Anthropic's official security plugin: instant pattern warnings on edits for known-dangerous calls (unsafe deserialisation, raw innerHTML, hard-coded secrets) and a post-turn review that sends the diff to a fast model and feeds high-severity findings back to Claude to fix before you see the response.
License: Apache-2.0 · Created by Anthropic · The project lists support for Claude Code
Free
What you get
Anthropic's official security plugin: instant pattern warnings on edits for known-dangerous calls (unsafe deserialisation, raw innerHTML, hard-coded secrets) and a post-turn review that sends the diff to a fast model and feeds high-severity findings back to Claude to fix before you see the response.
Pairs with the built-in /security-review command.
Install the Security Guidance (Anthropic) skill
A community skill: it installs from its own repository and your agent runs the project's instructions locally with your own model. SkillGild lists it and credits the author; nothing runs on SkillGild.
With the SkillGild CLI (needs git). It clones anthropics/claude-plugins-official and copies the skill folder into the right place for your agent; use --agent codex, cursor or gemini-cli for other clients.
Install from the official marketplace; Claude Code adds it automatically
Or copy the folder yourself from anthropics/claude-plugins-official (folder plugins/security-guidance) into ~/.claude/skills/security-guidance/ for Claude Code, ~/.agents/skills/ for Codex, ~/.cursor/skills/ for Cursor or ~/.gemini/skills/ for Gemini CLI, then start a new session.
Try asking
Requests that trigger this skill once it is installed in your agent.
Review this PR for security issues before I merge
Check the upload handler for path traversal
Run /security-review on the pending changes
Questions
How do I install the Security Guidance (Anthropic) skill in Claude Code?
Run skillgild install security-guidance --agent claude-code: the SkillGild CLI clones anthropics/claude-plugins-official and copies the skill folder into ~/.claude/skills/security-guidance. You can also use the project's own commands shown above, or copy the folder yourself. Use --agent codex, cursor or gemini-cli for other clients.
Is Security Guidance (Anthropic) free and open source?
Yes. The upstream repository is published under the Apache-2.0 license by Anthropic. SkillGild lists and credits it and installs it from source; it does not host or run it.
Which agents does Security Guidance (Anthropic) work with?
The project lists Claude Code. It is a plain Agent Skills folder (SKILL.md plus supporting files), so any client that reads that format can load it.
Does Security Guidance (Anthropic) run on SkillGild?
No. Security Guidance (Anthropic) is a community skill: your agent runs its instructions locally with your own model, and SkillGild lists, credits and installs it. Hosted SkillGild skills are marked differently and run through the SkillGild MCP server.
Related guides
Setup steps and worked examples for this kind of skill.
Publication-quality figures for ML papers: picks the chart type for your results, writes the matplotlib or seaborn code and checks its colors for contrast. Use it to compare methods, baselines or ablations in a chart, to check whether text and figure colors meet a contrast ratio, or to plan an architecture diagram from your method section.
Karpathy's observations on how LLMs fail at coding, codified into four rules the agent follows: think before coding (state assumptions, ask instead of guessing), simplicity first, surgical changes, and goal-driven execution.
Builds an animation from scratch the way a design engineer would: it chooses the curve, duration and properties, keeps motion off the main thread where it matters, and explains the choice.
Translates Apple's interface and motion principles into web code: spring curves, gesture physics, translucent materials and typography, as explained in Apple's WWDC design sessions.
Turn the project you just built into a short, shareable launch video with one command. Your agent reads the project code, so no live URL or screenshots are needed.
Anthropic's canvas-design skill guides Claude to produce finished visual artefacts (posters, covers, social graphics) by composing on an HTML canvas with deliberate typography, grid and colour decisions rather than defaulting to a template.
Anthropic's financial-services marketplace: a core financial-analysis plugin (comps, DCF, LBO, three-statement models in Excel, deck QC) plus vertical bundles for investment banking, equity research, private equity, fund administration, operations and financial advisors, 11 named agents and connectors to Daloopa, Morningstar, S&P Global, FactSet, PitchBook and more.
A universal SEO skill for Claude Code: 26 sub-skills and 19 specialist sub-agents covering technical audits, content quality, schema, E-E-A-T, local and e-commerce SEO, hreflang, backlinks, sitemaps, images, generative-engine optimisation and agent readiness (llms.txt, WebMCP).
Seventy-plus skills for equity investors and traders: market-breadth analysis, VCP and CAN SLIM screeners, breakout trade planning, risk-based position sizing, earnings-reaction scoring, technical charting, economic calendars, a value-dividend screener and a portfolio manager with Alpaca.
A large community collection: 380+ skills, 30+ agents and 70+ commands for Claude Code, Codex, Gemini CLI, Cursor and other agents, organised by job (engineering, marketing, product, compliance, C-level advisory, research, finance, operations, daily productivity).