Claude Security plugin
Run a multi-agent vulnerability scan of a repository or a diff from inside Claude Code, then turn chosen findings into reviewed patches you apply yourself.
The Claude Security plugin brings a security research team into your Claude Code session. A set of agents maps the architecture, builds a threat model, hunts for vulnerabilities, and has every candidate finding checked by independent verifier agents before it reaches the report. You can scan a whole repository or just a set of changes, and then ask for patches for the findings you care about. Patches are never applied for you.
It runs locally, on whatever models your session can use, and every scan counts towards your normal usage. That also means it can reach code a hosted service cannot, such as repositories on GitLab, Bitbucket or a locked-down internal network. Anthropic also sells a managed Claude Security product on the Enterprise plan that monitors connected repositories continuously; this page is about the plugin.
Where it sits relative to other tools:
- Security guidance checks code as Claude writes it.
/security-reviewis a single quick pass over your branch.- Code Review reviews pull requests.
- This plugin is the on-demand deep scan.
What you need
- A way to run dynamic workflows: a paid plan, Anthropic API access, or a third-party provider. On Pro, switch them on via the Dynamic workflows row in
/config. - Python 3.9+ on your
PATHaspython3(python3 --versionto check). Only the standard library is used, so nothing gets installed. - Linux, macOS or Windows.
- Git for change scans and for patching. A full scan works in any directory, versioned or not.
Models and providers
The plugin makes no model calls of its own; everything runs inside your session, so there is no separate key to configure.
- The agents that hunt, verify, write patches and review patches use your session's model. Set it with
/modelbefore scanning. A few supporting steps, such as mapping the repository, use thesonnetalias. - It runs on paid plans, the Anthropic API, or third-party providers: Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry.
- On third-party providers
sonnetmay resolve to a version your account cannot use. Pin versions, includingANTHROPIC_DEFAULT_SONNET_MODEL. See model configuration. - Automatic model fallback re-runs requests flagged by a model's safeguards. On Bedrock, Agent Platform and Foundry, depending on setup, you may get a refusal instead.
Installing
In VS Code or the desktop app, use the normal plugin installer (see installing plugins). In a terminal, start claude and run:
/plugin install claude-security@claude-plugins-official
Choose an installation scope in the details screen that opens.
Marketplace "claude-plugins-official" not found: run/plugin marketplace add anthropics/claude-plugins-officialand try again.- "Plugin not found": check the name.
Run /reload-plugins to apply.: do so to activate it in the current session.
To remove it later, use the /plugin menu or run claude plugin uninstall claude-security from your shell.
Running a full scan
The plugin adds a single command, /claude-security, which opens a menu with three jobs: Scan codebase, scan a set of changes, and Suggest patches.
- Run
/claude-securityand choose Scan codebase. - Pick the scope. The plugin reads the repository first and offers the whole thing or focused areas, each with a file count and relative cost. If you are unsure, answer "I don't know" and it picks a default suited to the repo's size.
- Confirm. Scans can take a while, use a lot of tokens, and need Claude Code left open. Nothing starts until you agree.
- Watch progress. Each stage is announced as it starts;
/workflowsshows the detail. - Read the report in the timestamped results folder (see below).
You can skip the menu by passing arguments or plain language:
/claude-security scan the payments service only
Scan commit 9f3e2a1 for security issues
Tip: Run scans in auto mode. Otherwise you will be approving each agent step by hand.
Scanning just your changes
If your branch has commits its base lacks, the menu offers to scan only that diff, which is a good pre-merge check. You can also pick one of your open pull requests, or name a single commit.
Only committed changes are scanned. Commit or stash work in progress, or run a full scan, which reads the working tree. Change scans require git. Listing your open PRs is the only step that touches the network, and it is only offered when the session can already run gh and gh is signed in.
Big repositories
Rather than scanning a huge monorepo end to end, pick one of the focused scopes offered (the API layer, the auth code and so on). The run sizes itself to that area, and the report's coverage section says what was and was not examined. Scan another area whenever you like.
The results folder
Each scan creates CLAUDE-SECURITY-<timestamp>/ in your repository:
| File | Contents |
|---|---|
CLAUDE-SECURITY-RESULTS.md | The readable report. Each finding has an ID (F1, F2...), impact, exploit scenario, severity, confidence and recommendation |
CLAUDE-SECURITY-RESULTS.jsonl | The same findings, one JSON object per line |
CLAUDE-SECURITY-RESULTS.sarif | A SARIF 2.1.0 log, with CWE classifications, for GitHub code scanning or any SARIF-aware tool |
CLAUDE-SECURITY-REVISION-<commit>.json | A stamp recording the commit scanned, effort level, whether uncommitted changes were included, and how thoroughly findings were verified. Unversioned scans stamp UNVERSIONED |
That folder is the only thing a scan adds to your checkout, and it contains its own .gitignore so a careless git add . will not commit it. To keep a report for audit, delete that .gitignore and commit the folder.
Only findings that survive independent verification make it into the report, which keeps it short. Scans are nondeterministic: two runs on identical code can find different things. I schedule them regularly rather than treating one clean run as proof, and use the revision stamp to tie each report to the exact code it covered.
Getting patches
Choose Suggest patches from the menu, or say something like "fix finding F2", then select the findings to address.
- Patches are built against committed code, and the report must still match it. Findings whose code has changed since the scan are skipped with a note, and you are offered a fresh scan.
- Each patch is drafted in a scratch copy of the repo; your files are untouched.
- A separate reviewer agent checks every patch, running your tests where they exist and reading the diff independently. A patch is only written if the reviewer can vouch that it fixes that one finding, introduces nothing new, and otherwise leaves behaviour unchanged. If it cannot vouch for all three, you get an explanation instead of a patch.
You apply them
Patches land in the report's patches/ folder as F<n>.patch, each with an explanatory note. Apply from your shell:
git switch -c fix/sec-F2
git apply CLAUDE-SECURITY-20261008-1412/patches/F2.patch
or ask Claude to apply one and open a pull request. If the patched code had no tests, the note says so. Give each patch its own PR so it can be reviewed and tested in isolation.
Where it fits in your stack
| Stage | Tool | Covers |
|---|---|---|
| While Claude writes | Security guidance | Common vulnerabilities in Claude's own edits |
| On demand, quick | /security-review | One pass over the current branch |
| On demand, deep | Claude Security plugin | Multi-agent scan of a repo or diff, verified findings, reviewed patches |
| Pull requests | Code Review (Team and Enterprise) | Correctness and security review with full codebase context |
| Managed | Claude Security product (Enterprise) | Hosted, continuous scanning of connected repos |
| CI | Your SAST and dependency tools | Deterministic rules, supply chain, policy |
The plugin complements, rather than replaces, deterministic scanners. It reasons about code the way a human researcher would, which tends to surface logic flaws those tools cannot see.
Troubleshooting
A Python warning when the menu opens. python3 is missing or older than 3.9. Install Python 3 or put a newer python3 first on your PATH, then start a new session.
"Safeguards flagged this message" on a Fable model. Fable's cybersecurity classifiers flag some requests; Claude Code reruns them on an Opus model via automatic fallback. This is expected and the scan should still finish.