Security Guidance · alirezarezvani
PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow injection, eval/new Function code injection) BEFORE the Edit/Write/MultiEdit operation completes. Session-state caching prevents duplicate warnings on the same file+rule combo. Stdlib only — no dependencies. Use when you want a safety net during Claude Code sessions that touch security-sensitive code (auth, payments, user input handling, IaC). Disable with ENABLESECURITYREMINDER=0 if you need to perform a verified-safe operation that would otherwise trip a pattern. Triggers — "add security hook", "block unsafe code", "detect command injection before write", "prevent SQL injection patterns", "security warning hook".
Works with: Claude Code, Cursor, Codex CLI
Category: Dev Tools & CI — see all ranked ›
Work: Agent configuration · Security review
Who it is for: Agent operator · Security engineer
- Adoption: 1 repos
- Health: active
- GitHub stars: 23,181
- Contributors: 30
- License: MIT
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
source ↗ · skill:alirezarezvani/security-guidance
Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›