An AI-powered security review GitHub Action using Claude to analyze code changes for security vulnerabilities.
This GitHub Action integrates Claude Code into pull request workflows to perform automated security reviews of code changes. When a PR is opened, the action runs a Python-based audit pipeline that extracts the diff, sends changed files through Claude Code for semantic analysis, filters findings via a separate Claude API call to remove false positives, and posts inline review comments on the affected lines. The tool covers a broad range of vulnerability classes including SQL injection, XSS, hardcoded secrets, insecure deserialization, TOCTOU race conditions, and weak cryptography, and it works across any programming language. Configuration options include a custom false-positive filtering instructions file, a custom scan instructions file, selectable model (defaulting to claude-opus-4-1), and a per-commit execution toggle. A notable caveat in the documentation warns that the action is not hardened against prompt injection and should only run on PRs from trusted contributors. Security teams and DevOps engineers maintaining repositories on GitHub are the primary audience.
- ✓Open-source license (MIT)
- ✓Healthy fork ratio
- ✓Clear description
- ✓Trusted owner (anthropics)
- ✓Documented (README)
git clone https://github.com/anthropics/claude-code-security-reviewTools overview
What people ask about claude-code-security-review
What is anthropics/claude-code-security-review?
+
anthropics/claude-code-security-review is tools for the Claude AI ecosystem. An AI-powered security review GitHub Action using Claude to analyze code changes for security vulnerabilities. It has 5.7k GitHub stars and was last updated 5mo ago.
How do I install claude-code-security-review?
+
You can install claude-code-security-review by cloning the repository (https://github.com/anthropics/claude-code-security-review) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is anthropics/claude-code-security-review safe to use?
+
Our security agent has analyzed anthropics/claude-code-security-review and assigned a Trust Score of 100/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.
Who maintains anthropics/claude-code-security-review?
+
anthropics/claude-code-security-review is maintained by anthropics. The last recorded GitHub activity is from 5mo ago, with 77 open issues.
Are there alternatives to claude-code-security-review?
+
Yes. On ClaudeWave you can browse similar tools at /categories/tools, sorted by popularity or recent activity.
Deploy claude-code-security-review to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/anthropics-claude-code-security-review)<a href="https://claudewave.com/repo/anthropics-claude-code-security-review"><img src="https://claudewave.com/api/badge/anthropics-claude-code-security-review" alt="Featured on ClaudeWave: anthropics/claude-code-security-review" width="320" height="64" /></a>More Tools
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
An AI SKILL that provide design intelligence for building professional UI/UX multiple platforms
🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
The fastest, litest AI Gateway. Rust core with Python SDK. Call 100+ LLM APIs in OpenAI (or native) format with cost tracking, guardrails, load balancing, and logging [Bedrock, Azure, OpenAI, Anthropic, OpenAI, VertexAI, vLLM, Nvidia NIM]
AI agent skill that researches any topic across Reddit, X, YouTube, HN, Polymarket, and the web - then synthesizes a grounded summary