Blog
4 min read

Claude Code Security Review: /security-review, the Security Plugins, and When to Use Each

Claude Code has several layers of security checking: the /security-review command for your branch, a security-guidance plugin that reviews code as Claude writes it, a Claude Security plugin for deep scans, and Code Review on pull requests. What each catches and how to use them on an AI-built app.

AI-written code has the same security bugs as human-written code — sometimes more, because it's written fast and reviewed lightly. Claude Code can check for them. There are four tools, and they work at different stages.

The quick answer

Before you merge a branch, run:

/security-review

That's the one to remember. The rest add depth.

1. /security-review — one pass over your branch

/security-review analyses the changes on your current branch compared with your repository's default branch, looking for risks such as:

  • Injection — SQL injection, command injection (SQL injection explained)
  • Authentication and authorisation mistakes — missing checks, users reaching other users' data (IDOR explained)
  • Data exposure — secrets in code, sensitive fields returned by an API
  • Unsafe handling of input — XSS, unsafe deserialisation (XSS explained)

It reports what it found and why it matters, and you can ask Claude to fix the issues in the same session.

It needs an origin remote to know what your default branch is. If it fails with an "ambiguous argument" error, your repo probably has no remote set up yet. (git remote add origin)

2. The security-guidance plugin — checks code as it's written

This plugin makes Claude review its own changes for common vulnerabilities while it works, and fix what it finds before the code reaches a pull request. Once installed, there's nothing to invoke.

/plugin install security-guidance@claude-plugins-official

It needs Python 3.7+ on your PATH and works best inside a Git repository. To turn it on for everyone on a project, add it to the checked-in .claude/settings.json:

{
  "enabledPlugins": {
    "security-guidance@claude-plugins-official": true
  }
}

(Claude Code plugins explained)

3. The Claude Security plugin — a deep scan

For a thorough look at a whole codebase, the Claude Security plugin runs a multi-agent scan: agents map the architecture, build a threat model, hunt for vulnerabilities, and independently double-check each finding before writing a report. You can then turn chosen findings into patches.

/plugin install claude-security@claude-plugins-official

It can scan the whole repository or just a set of changes. It's heavier than /security-review — it uses more of your plan's usage — and needs a paid plan or API access, plus Python 3.9+.

4. Code Review — on every pull request

Code Review runs automated, multi-agent reviews on pull requests in GitHub, catching logic errors and security problems before merge. Locally, /code-review checks your current diff for correctness bugs.

How they fit together

Stage Tool Best for
While Claude writes security-guidance plugin Catching common mistakes immediately
Before you merge /security-review A quick check of a branch
Periodically Claude Security plugin A deep audit of the whole app
On pull requests Code Review Every change, automatically

None replaces your other tools — dependency scanning (npm audit, Dependabot) and secret scanning (GitHub secret scanning) catch different problems.

What automated review won't catch

Treat a clean report as "no obvious problems", not "secure". Automated review is weaker at:

  • Business logic — "a free user can call the paid endpoint" only looks wrong if you know the rules
  • Configuration outside the code — an open database port, a public storage bucket, a missing firewall
  • Things that depend on how it's deployed — HTTPS, headers, who can reach the admin panel

For an AI-built app, pair the tools with a human pass through a checklist. (Security checklist for vibe-coded apps, OWASP Top 10)

A good routine

  1. Install the security-guidance plugin once.
  2. Run /security-review before merging anything that touches login, payments, uploads or user data.
  3. Run a deep scan before launch and every few months after.
  4. Fix, then re-run to confirm.

EasySpawn runs your app on its own isolated server with HTTPS, a firewall and daily backups set up for you, so the infrastructure side of security isn't left to chance. See how it works or join the waitlist.

Related: A Security Checklist for Vibe-Coded Apps · How to Review a Pull Request Written by an AI Agent · The OWASP Top 10 Explained · Prompt Injection in Coding Agents

Keep reading