Skip to content

Claude Security plugin

Run a multi-agent vulnerability scan of a repository or a diff from inside Claude Code, then turn chosen findings into reviewed patches you apply yourself.

The Claude Security plugin brings a security research team into your Claude Code session. A set of agents maps the architecture, builds a threat model, hunts for vulnerabilities, and has every candidate finding checked by independent verifier agents before it reaches the report. You can scan a whole repository or just a set of changes, and then ask for patches for the findings you care about. Patches are never applied for you.

It runs locally, on whatever models your session can use, and every scan counts towards your normal usage. That also means it can reach code a hosted service cannot, such as repositories on GitLab, Bitbucket or a locked-down internal network. Anthropic also sells a managed Claude Security product on the Enterprise plan that monitors connected repositories continuously; this page is about the plugin.

Where it sits relative to other tools:

  • Security guidance checks code as Claude writes it.
  • /security-review is a single quick pass over your branch.
  • Code Review reviews pull requests.
  • This plugin is the on-demand deep scan.

What you need

  • A way to run dynamic workflows: a paid plan, Anthropic API access, or a third-party provider. On Pro, switch them on via the Dynamic workflows row in /config.
  • Python 3.9+ on your PATH as python3 (python3 --version to check). Only the standard library is used, so nothing gets installed.
  • Linux, macOS or Windows.
  • Git for change scans and for patching. A full scan works in any directory, versioned or not.

Models and providers

The plugin makes no model calls of its own; everything runs inside your session, so there is no separate key to configure.

  • The agents that hunt, verify, write patches and review patches use your session's model. Set it with /model before scanning. A few supporting steps, such as mapping the repository, use the sonnet alias.
  • It runs on paid plans, the Anthropic API, or third-party providers: Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry.
  • On third-party providers sonnet may resolve to a version your account cannot use. Pin versions, including ANTHROPIC_DEFAULT_SONNET_MODEL. See model configuration.
  • Automatic model fallback re-runs requests flagged by a model's safeguards. On Bedrock, Agent Platform and Foundry, depending on setup, you may get a refusal instead.

Installing

In VS Code or the desktop app, use the normal plugin installer (see installing plugins). In a terminal, start claude and run:

/plugin install claude-security@claude-plugins-official

Choose an installation scope in the details screen that opens.

  • Marketplace "claude-plugins-official" not found: run /plugin marketplace add anthropics/claude-plugins-official and try again.
  • "Plugin not found": check the name.
  • Run /reload-plugins to apply.: do so to activate it in the current session.

To remove it later, use the /plugin menu or run claude plugin uninstall claude-security from your shell.

Running a full scan

The plugin adds a single command, /claude-security, which opens a menu with three jobs: Scan codebase, scan a set of changes, and Suggest patches.

  1. Run /claude-security and choose Scan codebase.
  2. Pick the scope. The plugin reads the repository first and offers the whole thing or focused areas, each with a file count and relative cost. If you are unsure, answer "I don't know" and it picks a default suited to the repo's size.
  3. Confirm. Scans can take a while, use a lot of tokens, and need Claude Code left open. Nothing starts until you agree.
  4. Watch progress. Each stage is announced as it starts; /workflows shows the detail.
  5. Read the report in the timestamped results folder (see below).

You can skip the menu by passing arguments or plain language:

/claude-security scan the payments service only
Scan commit 9f3e2a1 for security issues

Tip: Run scans in auto mode. Otherwise you will be approving each agent step by hand.

Scanning just your changes

If your branch has commits its base lacks, the menu offers to scan only that diff, which is a good pre-merge check. You can also pick one of your open pull requests, or name a single commit.

Only committed changes are scanned. Commit or stash work in progress, or run a full scan, which reads the working tree. Change scans require git. Listing your open PRs is the only step that touches the network, and it is only offered when the session can already run gh and gh is signed in.

Big repositories

Rather than scanning a huge monorepo end to end, pick one of the focused scopes offered (the API layer, the auth code and so on). The run sizes itself to that area, and the report's coverage section says what was and was not examined. Scan another area whenever you like.

The results folder

Each scan creates CLAUDE-SECURITY-<timestamp>/ in your repository:

FileContents
CLAUDE-SECURITY-RESULTS.mdThe readable report. Each finding has an ID (F1, F2...), impact, exploit scenario, severity, confidence and recommendation
CLAUDE-SECURITY-RESULTS.jsonlThe same findings, one JSON object per line
CLAUDE-SECURITY-RESULTS.sarifA SARIF 2.1.0 log, with CWE classifications, for GitHub code scanning or any SARIF-aware tool
CLAUDE-SECURITY-REVISION-<commit>.jsonA stamp recording the commit scanned, effort level, whether uncommitted changes were included, and how thoroughly findings were verified. Unversioned scans stamp UNVERSIONED

That folder is the only thing a scan adds to your checkout, and it contains its own .gitignore so a careless git add . will not commit it. To keep a report for audit, delete that .gitignore and commit the folder.

Only findings that survive independent verification make it into the report, which keeps it short. Scans are nondeterministic: two runs on identical code can find different things. I schedule them regularly rather than treating one clean run as proof, and use the revision stamp to tie each report to the exact code it covered.

Getting patches

Choose Suggest patches from the menu, or say something like "fix finding F2", then select the findings to address.

  • Patches are built against committed code, and the report must still match it. Findings whose code has changed since the scan are skipped with a note, and you are offered a fresh scan.
  • Each patch is drafted in a scratch copy of the repo; your files are untouched.
  • A separate reviewer agent checks every patch, running your tests where they exist and reading the diff independently. A patch is only written if the reviewer can vouch that it fixes that one finding, introduces nothing new, and otherwise leaves behaviour unchanged. If it cannot vouch for all three, you get an explanation instead of a patch.

You apply them

Patches land in the report's patches/ folder as F<n>.patch, each with an explanatory note. Apply from your shell:

git switch -c fix/sec-F2
git apply CLAUDE-SECURITY-20261008-1412/patches/F2.patch

or ask Claude to apply one and open a pull request. If the patched code had no tests, the note says so. Give each patch its own PR so it can be reviewed and tested in isolation.

Where it fits in your stack

StageToolCovers
While Claude writesSecurity guidanceCommon vulnerabilities in Claude's own edits
On demand, quick/security-reviewOne pass over the current branch
On demand, deepClaude Security pluginMulti-agent scan of a repo or diff, verified findings, reviewed patches
Pull requestsCode Review (Team and Enterprise)Correctness and security review with full codebase context
ManagedClaude Security product (Enterprise)Hosted, continuous scanning of connected repos
CIYour SAST and dependency toolsDeterministic rules, supply chain, policy

The plugin complements, rather than replaces, deterministic scanners. It reasons about code the way a human researcher would, which tends to surface logic flaws those tools cannot see.

Troubleshooting

A Python warning when the menu opens. python3 is missing or older than 3.9. Install Python 3 or put a newer python3 first on your PATH, then start a new session.

"Safeguards flagged this message" on a Fable model. Fable's cybersecurity classifiers flag some requests; Claude Code reruns them on an Opus model via automatic fallback. This is expected and the scan should still finish.