Claude Code Security Review: What Each Tool Catches (2026) - VibeDoctor 
← All Articles 🤖 AI Comparison & Trending High

Claude Code Security Review: What Each Tool Catches (2026)

Claude Code's security-guidance plugin, /security-review and Claude Security plugin compared: what each catches, what they miss, and what to add.

SEC-001 SEC-002 SEC-014 PKG-VERIFY

Quick Answer

Claude Code has three built-in ways to review code for security: the security-guidance plugin checks code while Claude writes it, the /security-review command makes one pass over the changes on your current branch, and the Claude Security plugin runs a multi-agent scan of a diff or a whole repository. All three read the source code in your checkout. None of them checks your dependencies against a live vulnerability database, confirms that imported packages exist, or looks at your deployed site, and Anthropic's own documentation says to keep running static analysis and dependency scanners alongside them.

Claude Code's Security Tools at a Glance

ToolWhen it runsWhat it coversAvailability
Security-guidance pluginAutomatically: on each edit, at the end of each turn, and on commits Claude makesCommon vulnerabilities in code Claude is writing, fixed in the same sessionAll plans
/security-reviewWhen you run itOne pass over the changes on your current branchBuilt into Claude Code
Claude Security pluginWhen you run /claude-securityMulti-agent scan of a diff or the whole repository, with independently reviewed findings and patches you apply yourselfPaid plans
Code ReviewOn pull requestsCorrectness and security review with full codebase contextTeam and Enterprise
Claude Security (managed)ContinuouslyHosted scanning of connected repositoriesEnterprise

Summarized from Anthropic's documentation for the security-guidance plugin and the Claude Security plugin, checked September 2026. Anthropic first announced Claude Code Security as a research preview in February 2026, noting that its team had used Claude Opus 4.6 to find more than 500 vulnerabilities in production open-source codebases.

What /security-review Checks

Anthropic's help center lists five categories: SQL injection, cross-site scripting, authentication and authorization flaws, insecure data handling, and dependency vulnerabilities. You run it with one line inside a Claude Code session:

/security-review

The same analysis runs on pull requests through Anthropic's open-source GitHub Action, anthropics/claude-code-security-review, which uses your own Claude API key. To tune it, copy the repository's security-review.md into .claude/commands/ and edit the instructions.

Read that prompt before relying on it. It limits Claude to read-only git and file tools, and it tells the model not to report whole classes of issues, including denial of service, rate limiting, and vulnerabilities in outdated third-party libraries, which it treats as handled elsewhere. That is a sensible choice for a fast diff review, and it is exactly why the command cannot be your dependency or abuse check.

The Bug These Tools Are Best At

Authorization bugs are where model-based review earns its keep, and they are common in agent-written APIs. This Next.js route authenticates the caller and still leaks every customer's invoices:

// BAD: any logged-in user can read any invoice by changing the id
export async function GET(req, { params }) {
  const session = await getSession(req);
  if (!session) return new Response('Unauthorized', { status: 401 });

  const invoice = await db.invoice.findUnique({ where: { id: params.id } });
  return Response.json(invoice);
}

// GOOD: the query is scoped to the caller, so other users' ids return nothing
export async function GET(req, { params }) {
  const session = await getSession(req);
  if (!session) return new Response('Unauthorized', { status: 401 });

  const invoice = await db.invoice.findFirst({
    where: { id: params.id, ownerId: session.user.id },
  });
  if (!invoice) return new Response('Not found', { status: 404 });
  return Response.json(invoice);
}

A regex-based scanner sees an authenticated route and moves on. A reviewer that understands the data model asks whose invoice this is. This class of bug, broken object level authorization, is the one behind the Lovable BOLA incident.

What Claude Code's Security Tools Miss

  • Dependencies and fresh CVEs. None of the three queries a vulnerability database. Anthropic's own documentation leaves supply-chain checks to the static analysis and dependency scanners in your CI, and the /security-review prompt skips outdated libraries outright. A CVE published last week against a package in your lockfile needs a scanner. If you are choosing one, see our comparison of Snyk alternatives.
  • Packages that do not exist. Agents sometimes import package names that were never published, which attackers then register. Only a lookup against the npm or PyPI registry proves a name is real. Background: hallucinated imports.
  • Secrets already in git history. /security-review reads your branch diff and a full plugin scan reads the working tree, so a key committed months ago and deleted since is invisible to both while it still sits in git history. GitGuardian's State of Secrets Sprawl 2025 counted 23.8 million new secrets on public GitHub in 2024, and 70% of those leaked in 2022 were still valid.
  • Your deployed site. Anthropic's docs say these reviews read the source code in your checkout, not a running site or deployed service. Missing security headers, an expiring SSL certificate or a publicly served .env file are properties of the deployment.
  • Repeatability and cost. Anthropic notes that scans are nondeterministic, so two scans of the same code can surface different findings, and a full Claude Security scan can take a while and use a large share of your plan's usage limits.

None of this makes the tools weak. It makes them one layer. Veracode's 2026 GenAI Code Security Report puts the average security pass rate of AI-generated code at 56%, so the other layers are not optional.

Add Deterministic Checks to the Agent Loop

The fix is to give the agent tools whose output does not depend on a model's judgment. You can wire Gitleaks, Trivy and Semgrep into Claude Code hooks or a pre-commit step, or connect a scanner as an MCP server so the agent calls it as a tool. VibeDoctor's Vibe Check (vibedoctor.io) works this way: you paste one line into Claude Code, Cursor or Codex, and the agent gets tools that check the files it just wrote for secrets, injection patterns, missing auth and hallucinated imports. The same account runs the full 149+ check scan of your repo and deployed URL, with file paths and line numbers. It is free to sign up, and the setup guide walks through the connection.

Then tell the agent when to use it. A short rule in CLAUDE.md (or .cursor/rules) does more than any prompt you remember to type:

## Security checks
- After changing auth, API routes, database queries or payments,
  run /security-review and a scanner check on the changed files.
- Fix every critical or high finding before saying the task is done.
- Never add a package without confirming it exists on the registry.

A Review Routine That Fits a Solo Founder

WhenWhat to runCatches
While Claude writesSecurity-guidance plugin (automatic)Common vulnerabilities in the code being written
Before each merge/security-review plus a secret, dependency and SAST scan of the changed filesAuthorization logic, keys, known CVEs, injection patterns
Weekly and before launchA Claude Security plugin scan or a full repo scan, plus a live URL scanOld code, headers, SSL, exposed files

The model-based reviews bring judgment, the scanners bring proof, and the live URL scan covers what neither can see. Skip any one of them and you are trusting the agent's word that the code is safe. For the full pre-launch list, see our vibe coding security checklist.

FAQ

Is /security-review free?

It is built into Claude Code, so it costs whatever that session costs on your plan or API usage. The GitHub Action version runs on your own Claude API key, so each pull request review is billed as API usage.

Does /security-review scan my whole codebase?

No. It covers the changes on your current branch. For the whole repository, run the Claude Security plugin on a paid plan, ask Claude to review a specific directory, or run a full scanner.

What is the difference between /security-review and the Claude Security plugin?

/security-review is a single pass over your branch diff. The Claude Security plugin runs a team of agents that maps your architecture, builds a threat model, independently reviews each finding, and can draft patches that you apply yourself. It takes longer, needs a paid plan, and uses more of your usage limits.

Can Cursor do the same security review?

The plugins and slash commands above run in Claude Code. In Cursor you can paste Anthropic's open-source review prompt into a chat, and any scanner exposed as an MCP server works there the same way it does in Claude Code.

Can I trust an AI to review AI-generated code?

Partly. A second model pass catches real bugs the first one wrote, especially authorization gaps. It does not replace tools that check facts, like whether a key is in your git history or a package exists. Use both, and read the critical findings yourself.

Diagnose your codebase - free

VibeDoctor checks for SEC-001, SEC-002, SEC-014, PKG-VERIFY and 148 other issues across 21 diagnostic areas - security, performance, code quality, and more.

SCAN MY APP →