Agent skill

Security Guidance

by alirezarezvani in alirezarezvani/claude-skills

PreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills.

MITAuto-check passedSecurity

Install Security Guidance

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill security-guidance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills security-guidance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering/security-guidance/skills/security-guidance .claude/skills/security-guidance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-guidance
GitHub stars
28k
Token cost
~1.9k tokens
SKILL.md length
770 words
Files
2 (incl. references)
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

PreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills.

  • Works in 6 steps: Claude Code is about to run Edit, Write,… → PreToolUse hook fires → invokes… → The hook extracts file_path + content +… → …
  • You want a safety net during Claude Code sessions that touch security-sensitive code (auth
  • SKILL.md covers What It Catches, How It Works, Installation and Configuration, plus 8 more sections
  • Calls claude

What it does

Security Guidance is an agent skill from alirezarezvani/claude-skills. PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow injection, eval/new Function code injection) BEFORE the Edit/Write/MultiEdit operation completes. Session-state caching prevents duplicate warnings on the same file+rule combo. Stdlib only — no dependencies. Use when you want a safety net during Claude Code sessions that touch security-sensitive code (auth, payments, user input handling…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/pretooluse_hook_canon.md`).

It sits in Security, covering Web application vulnerabilities, Session handoff and CI/CD. It works with GitHub Actions and Python. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • You want a safety net during Claude Code sessions that touch security-sensitive code (auth
  • User input handling
  • — add security hook
  • Block unsafe code

Example prompts

  • “add security hook”
  • “block unsafe code”
  • “detect command injection before write”
  • “/security-guidance”

Requirements

  • Python 3
  • Node.js

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Claude Code is about to run Edit, Write, or MultiEdit
  2. PreToolUse hook fires → invokes security_reminder_hook.py with the tool input as JSON on stdin
  3. The hook extracts file_path + content + checks against the pattern table
  4. If a pattern matches AND this warning hasn't been shown for this file+rule in this session
  5. If a pattern matches BUT the warning was already shown this session
  6. If no pattern matches

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Guidance loads about 1.9k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 205 tokens; SKILL.md has 770 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~205
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 770 words, ~1,945 tokens.

Download SKILL.mdSave it as .claude/skills/security-guidance/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
security-guidance
description
PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow injection, eval/new Function code injection) BEFORE the Edit/Write/MultiEdit operation completes. Session-state caching prevents duplicate warnings on the same file+rule combo. Stdlib only — no dependencies. Use when you want a safety net during Claude Code sessions that touch security-sensitive code (auth, payments, user input handling, IaC). Disable with ENABLE_SECURITY_REMINDER=0 if you need to perform a verified-safe operation that would otherwise trip a pattern. Triggers — "add security hook", "block unsafe code", "detect command injection before write", "prevent SQL injection patterns", "security warning hook".

Security Guidance Hook

A PreToolUse hook that blocks 12 common security anti-patterns before Claude Code writes them.

This skill is a hook, not a slash command. Once installed, it runs automatically before every Edit, Write, or MultiEdit operation and warns + blocks if it detects a known dangerous pattern.

What It Catches

The hook scans both:

  • The file path being edited — flags GitHub Actions workflow files with risky ${{ }} patterns
  • The content being written — substring matches against 11 anti-patterns
PatternCategoryRisk
GitHub Actions workflow expressionsPath-basedWorkflow command injection via untrusted inputs
child_process.exec, exec(, execSync(SubstringNode.js command injection
new FunctionSubstringJS code injection
eval(SubstringJS code injection
dangerouslySetInnerHTMLSubstringReact XSS
document.writeSubstringDOM XSS
.innerHTML =SubstringDOM XSS
pickleSubstringPython deserialization RCE
os.system, from os import systemSubstringPython command injection
shell=True (subprocess)SubstringPython command injection
f-string SQL or .format SQLSubstringSQL injection
yaml.load(, yaml.unsafe_loadSubstringYAML deserialization RCE

How It Works

  1. Claude Code is about to run Edit, Write, or MultiEdit
  2. PreToolUse hook fires → invokes security_reminder_hook.py with the tool input as JSON on stdin
  3. The hook extracts file_path + content + checks against the pattern table
  4. If a pattern matches AND this warning hasn't been shown for this file+rule in this session:
    • Print the warning to stderr (Claude sees it)
    • Exit code 2 → blocks the tool call
    • Save the warning key to ~/.claude/security_warnings_state_<session>.json
  5. If a pattern matches BUT the warning was already shown this session:
    • Allow the tool call (exit code 0) — Claude already saw the warning once
  6. If no pattern matches:
    • Allow the tool call (exit code 0)

Installation

This plugin ships as a Claude Code plugin with hooks.json wiring:

bash
# In Claude Code:
/plugin marketplace add alirezarezvani/claude-skills
/plugin install security-guidance@claude-code-skills

Once installed, no further configuration needed — the hook runs automatically.

Configuration

Disable per-session via environment variable:

bash
ENABLE_SECURITY_REMINDER=0 claude
# Hook is bypassed for this session

Use sparingly — the hook is most useful exactly when you're tempted to disable it (because you're under deadline pressure to ship something you know is sketchy).

Per-File Override Pattern

If a specific file legitimately needs eval() or pickle (e.g., a sandboxed REPL, a deliberately unsafe parser for a fuzzer), document it in the file with a comment:

python
# SAFETY: pickle is the required serialization format for this internal tool.
# This file does NOT accept untrusted input. See SECURITY.md for boundary analysis.
import pickle

The hook will still warn on first edit per session. After acknowledging, subsequent edits in the same session are allowed (session-state caching).

Why The Patterns Are Substring-Based (Not AST-Based)

Trade-off: AST-based detection would be more precise (no false positives on string literals containing "eval("). Substring-based is:

  • Faster — runs in ms, doesn't parse the file
  • Cross-language — same hook works for JS/TS/Python/YAML/etc.
  • Conservative — false positives are easy to dismiss (one keystroke); false negatives are dangerous

For 90%+ of cases, substring detection is sufficient. If you need stricter detection, layer in a proper SAST tool (semgrep, CodeQL) as a CI step.

Show full SKILL.md (317 more words)Show less

State Files

The hook caches "warning shown" state in ~/.claude/security_warnings_state_<session_id>.json. These files:

  • Are auto-cleaned after 30 days (10% chance per hook invocation)
  • Are session-scoped (each Claude session gets its own)
  • Contain a JSON list of <file_path>-<rule_name> keys

You can safely delete ~/.claude/security_warnings_state_*.json files at any time — the hook regenerates them on next run.

Debug Log

The hook writes to ~/.claude/security-warnings-log.txt for debugging hook misfires:

bash
tail -f ~/.claude/security-warnings-log.txt
# Shows JSON decode errors, state-file save failures, etc.

(Upstream version wrote to /tmp/security-warnings-log.txt — we moved it to ~/.claude/ for persistence across reboots.)

Source + Attribution

This plugin is ported from David Dworken's MIT-licensed implementation in alirezarezvani/aeo-box.

Verbatim: the original 9 patterns (GitHub Actions, child_process.exec, new Function, eval, dangerouslySetInnerHTML, document.write, innerHTML, pickle, os.system) are preserved with their exact warning text.

Modifications:

  • Added 3 patterns: subprocess shell=True, SQL injection via f-string or .format, yaml.unsafe_load
  • Debug log moved from /tmp/security-warnings-log.txt → ~/.claude/security-warnings-log.txt
  • Restructured as a claude-skills plugin with attribution block in .claude-plugin/authoring-notes.json (originally in plugin.json; relocated when issue #954 showed Claude Code rejects manifests carrying extension keys)

Anti-Patterns

Disabling the hook by default

Defeats the purpose. If ENABLE_SECURITY_REMINDER=0 becomes your default, you've trained yourself to ignore the safety net. Use it only for specific verified-safe operations.

Modifying the pattern list without security review

Anyone can add a pattern. Removing one requires a security review — patterns exist because they map to real CVE classes.

Treating session-state as immutable security policy

The cache prevents nag-spam but is per-session. Don't rely on "I dismissed this once" as long-term policy — use the per-file documentation pattern instead (comment justifying the use).

  • engineering-team/skills/red-team — adversarial pen-testing
  • engineering-team/skills/threat-detection — threat modeling + detection design
  • engineering-team/skills/ai-security — AI-specific security (prompt injection, etc.)
  • engineering/ship-gate — pre-production audit (8-category, ~89 checks)
  • engineering/skill-security-auditor — security scan for skill packages

Trigger Phrases

  • "add security hook"
  • "block unsafe code before write"
  • "detect command injection"
  • "prevent SQL injection patterns"
  • "warn on eval / pickle / os.system"
  • "GitHub Actions security hook"

Version: 2.7.3 Source: Ported from alirezarezvani/aeo-box .claude/plugins/security-guidance/ (originally by David Dworken at Anthropic, MIT) License: MIT

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in engineering/security-guidance/skills/security-guidance of alirezarezvani/claude-skills.

  • SKILL.md
  • references/pretooluse_hook_canon.md

Open the folder on GitHubat commit 19392f7

Compare with similar skills

Security Guidance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Guidance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Guidance this skillalirezarezvani/claude-skills28k—~1.9kAutomated safety check: PassMIT
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT
Code Securitysemgrep/skills322—~1.2kAutomated safety check: PassCustom licence
Sast BanditAgentSecOps/SecOpsAgentKit2201 repos~2.6kAutomated safety check: PassCustom licence
Integrating Dast With Owasp Zap In Pipelinemukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Reproduce macOS Python FlavorsNuitka/Nuitka15k—~1.7kAutomated safety check: PassAGPL-3.0

Similar skills

  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Sast Bandit

    AgentSecOps/SecOpsAgentKit

    Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.

    220 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Integrating Dast With Owasp Zap In Pipeline

    mukul975/Anthropic-Cybersecurity-Skills

    Integrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration against running applications, ZAP finding interpretation…

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Reproduce macOS Nuitka issues across Python distributions and GitHub Actions Python packaging.

    15k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Gh

    bubbuild/bub

    GitHub CLI skill for interacting with GitHub via the gh command line tool.

    1.7k GitHub stars~798 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Categories

Questions about Security Guidance

What does Security Guidance do?

PreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills. Security Guidance is an agent skill from alirezarezvani/claude-skills. PreToolUse security-anti-pattern hook for Claude Code.

When should I use Security Guidance?

Security Guidance fits situations like: you want a safety net during Claude Code sessions that touch security-sensitive code (auth; user input handling; — add security hook; block unsafe code.

How do I install Security Guidance in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill security-guidance -a claude-code`. Or copy the skill folder (engineering/security-guidance/skills/security-guidance in alirezarezvani/claude-skills) into .claude/skills/security-guidance in your project. Claude Code loads it when a task matches its description.

How do I install Security Guidance in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill security-guidance -a codex`. Or copy the skill folder (engineering/security-guidance/skills/security-guidance in alirezarezvani/claude-skills) into .agents/skills/security-guidance in your project. Codex loads it when a task matches its description.

Can I use Security Guidance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill security-guidance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-guidance, .gemini/skills/security-guidance, .github/skills/security-guidance and .opencode/skills/security-guidance in your project.

What does Security Guidance need to run?

Going by SKILL.md and its folder, Security Guidance needs the command-line tools its instructions call (claude). Our summary lists: Python 3; Node.js.

Does Security Guidance access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Security Guidance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Guidance use?

Security Guidance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Guidance use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Security Guidance?

Skills that share tags, products or a category with Security Guidance: CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars), Code Security (semgrep/skills, 322 stars), Sast Bandit (AgentSecOps/SecOpsAgentKit, 220 stars) and Integrating Dast With Owasp Zap In Pipeline (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Guidance?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,891 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.