Most people still treat AI coding agents like magic - paste code, get output, hope nothing breaks in prod.
But the real risk isn’t bad code. It’s the quiet security holes that appear when agents edit files, run commands, and access your entire project without guardrails.
ClaudeDevs just dropped something that actually addresses this:
- New official “security-guidance” plugin for Claude Code
- It gives the agent real-time context about security best practices while it works
- Instead of retroactively finding vulnerabilities, the agent gets warned during generation itself
- Works directly inside your existing Claude Code workflow.. no extra tools needed
- Released as an official plugin, not some random community script
This is the difference between “it works on my machine” and “this won’t get me hacked in 3 months.”
If you’re already using Claude Code for real projects, this plugin should be one of the first things you install.
ClaudeDevs (@ClaudeDevs)
We’ve shipped a security-guidance plugin for Claude Code that helps identify and fix vulnerabilities as you’re writing code.
Available for all Claude Code users. Install from the plugin marketplace (/plugins).
Video
— https://nitter.net/ClaudeDevs/status/2059385239781384341#m