OSSanthropics/claude-code-security-review — Official Security Review GitHub ActionGitHub·high signalXBlueskyLinkedInCopy linkLaunched alongside Claude Code Security. Performs context-aware security analysis on PR diffs. Detects 10+ vulnerability categories. Diff-aware, false-positive filtering, custom scanning instructions. 3K stars on launch day.SourceSource pageGitHub↳ Follow the threadPolicy dependency / Stack layerClaude Code adds omitClaudeMd so subagents can run without inherited CLAUDE.md, and a sha256 plugin-install accept flagGitHubStack layer / Threat patternAlibaba's open-code-review v1.12.1 adds OpenCode 2.x native-tool support and a git binary safety checkGitHubStack layer / Threat patternClaude Code lowers the medium dynamic-workflow guideline from 15 agents to 10, and defaults Pro plans to smallClaude Code ChangelogStack layer / Threat patternTip: Anthropic's own CI proves `claude plugin test` is not in a released build yetGitHubStack layer / Threat patternClaude Code Mods are shipping, built on a middleware-style function-hook model with a side-effect-tracking $ objectGitHub (anthropics/claude-code) via Boris ChernyStack layer / Threat patternArchestra platform 1.4.0-beta.8 switches to native Claude Code sign-in for personal subscriptions and exposes durable runtime health metricsGitHubStack layer / Threat patternPattern: Claude Code has shipped Bash permission-bypass fixes in five consecutive releasesClaude Code ChangelogStack layer / Threat patternTip: gap-trap's "Proven Red" gate runs every new test against the old code and fails when it passesGitHub