agent-launcher-orchest…
Use when a user wants to build, launch, grade, or schedule a Claude Managed Agent (CMA) in their own Anthropic account — "build me an agent", "launch this as a…
PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow injection, eval/new Function code injection) BEFORE the Edit/Write/MultiEdit operation completes.
$ npx -y skills add alirezarezvani/claude-skills --skill security-guidance --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/security-guidanceContext preview
The summary Claude sees to decide when to auto-load this skill.
PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow injection, eval/new Function code injection) BEFORE the Edit/Write/MultiEdit operation completes.
name: security-guidance description: PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow injection, eval/new Function code injection) BEFORE the Edit/Write/MultiEdit operation completes. Session-state caching prevents duplicate warnings on the same file+rule combo. Stdlib only — no dependencies. Use when you want a safety net during Claude Code sessions that touch security-sensitive code (auth, payments, user input handling, IaC). Disable with ENABLE_SECURITY_REMINDER=0 if you need to perform a verified-safe operation that would otherwise trip a pattern. Triggers — "add security hook", "block unsafe code", "detect command injection before write", "prevent SQL injection patterns", "security warning hook".
**A PreToolUse hook that blocks 12 common security anti-patterns before Claude Code writes them.**
This skill is a **hook**, not a slash command. Once installed, it runs automatically before every `Edit`, `Write`, or `MultiEdit` operation and warns + blocks if it detects a known dangerous pattern.
The hook scans both:
| Pattern | Category | Risk | |---|---|---| | GitHub Actions workflow expressions | Path-based | Workflow command injection via untrusted inputs | | `child_process.exec`, `exec(`, `execSync(` | Substring | Node.js command injection | | `new Function` | Substring | JS code injection | | `eval(` | Substring | JS code injection | | `dangerouslySetInnerHTML` | Substring | React XSS | | `document.write` | Substring | DOM XSS | | `.innerHTML =` | Substring | DOM XSS | | `pickle` | Substring | Python deserialization RCE | | `os.system`, `from os import system` | Substring | Python command injection | | `shell=True` (subprocess) | Substring | Python command injection | | f-string SQL or `.format` SQL | Substring | SQL injection | | `yaml.load(`, `yaml.unsafe_load` | Substring | YAML deserialization RCE |
1. Claude Code is about to run `Edit`, `Write`, or `MultiEdit` 2. PreToolUse hook fires → invokes `security_reminder_hook.py` with the tool input as JSON on stdin 3. The hook extracts file_path + content + checks against the pattern table 4. If a pattern matches AND this warning hasn't been shown for this file+rule in this session:
5. If a pattern matches BUT the warning was already shown this session:
6. If no pattern matches:
This plugin ships as a Claude Code plugin with `hooks.json` wiring:
# In Claude Code: /plugin marketplace add alirezarezvani/claude-skills /plugin install security-guidance@claude-code-skills
Once installed, no further configuration needed — the hook runs automatically.
Disable per-session via environment variable:
ENABLE_SECURITY_REMINDER=0 claude # Hook is bypassed for this session
Use sparingly — the hook is most useful exactly when you're tempted to disable it (because you're under deadline pressure to ship something you know is sketchy).
If a specific file legitimately needs `eval()` or `pickle` (e.g., a sandboxed REPL, a deliberately unsafe parser for a fuzzer), document it in the file with a comment:
# SAFETY: pickle is the required serialization format for this internal tool. # This file does NOT accept untrusted input. See SECURITY.md for boundary analysis. import pickle
The hook will still warn on first edit per session. After acknowledging, subsequent edits in the same session are allowed (session-state caching).
Trade-off: AST-based detection would be more precise (no false positives on string literals containing "eval("). Substring-based is:
For 90%+ of cases, substring detection is sufficient. If you need stricter detection, layer in a proper SAST tool (semgrep, CodeQL) as a CI step.
The hook caches "warning shown" state in `~/.claude/security_warnings_state_<session_id>.json`. These files:
You can safely delete `~/.claude/security_warnings_state_*.json` files at any time — the hook regenerates them on next run.
The hook writes to `~/.claude/security-warnings-log.txt` for debugging hook misfires:
tail -f ~/.claude/security-warnings-log.txt # Shows JSON decode errors, state-file save failures, etc.
(Upstream version wrote to `/tmp/security-warnings-log.txt` — we moved it to `~/.claude/` for persistence across reboots.)
This plugin is ported from David Dworken's MIT-licensed implementation in [`alirezarezvani/aeo-box`](https://github.com/alirezarezvani/aeo-box/tree/main/.claude/plugins/security-guidance).
**Verbatim:** the original 9 patterns (GitHub Actions, child_process.exec, new Function, eval, dangerouslySetInnerHTML, document.write, innerHTML, pickle, os.system) are preserved with their exact warning text.
**Modifications:**
388 production-ready Claude Code skills, plugins, and agent skills for 13 AI coding tools. The most comprehensive open-source library of Claude Code skills and agent plugins — also works with OpenAI Codex, Gemini CLI, Cursor, and 9 more coding agents.
Repo: alirezarezvani/claude-skills
Use when a user wants to build, launch, grade, or schedule a Claude Managed Agent (CMA) in their own Anthropic account — "build me an agent", "launch this as a…
Phase 3 of building a Claude Managed Agent — the bounded grade→iterate loop. Define a CMA outcome (a required markdown rubric graded by an isolated grader),…
Phase 1 of building a Claude Managed Agent — interview the founder about the one job the agent should do, then produce a build sheet (CMA primitives table +…
Phase 4 of building a Claude Managed Agent — make it run without you. Turn a graded agent into a recurring scheduled deployment (POSIX-cron), an event-driven…
Phase 2 of building a Claude Managed Agent — turn a validated build sheet into exact API payloads and a resumable BYOK curl launch script, then launch…
Close out a launched Claude Managed Agent — recap every primitive the founder now owns, regenerate the single-file overview page, and suggest the next 1-2…