# Security

> Security scanning, auditing, and compliance validation with 4 specialized agents, plus fail-closed hooks: PII/secrets guard, HMAC-chained tamper-evident audit (CloudWatch dual-write), token-budget circuit breaker

## Facts
- Page: https://tashan.sh/capability/plugin-aws-solutions-library-samples-guidance-for-claude-code-with-amazon-bedrock-security
- tashan id: plugin:aws-solutions-library-samples/guidance-for-claude-code-with-amazon-bedrock/security
- Source: https://github.com/aws-solutions-library-samples/guidance-for-claude-code-with-amazon-bedrock
- Type: plugin
- Category: security
- tashan score: 45.0 / 100
- Adoption: 7.0
- Upkeep: 100.0
- Freshness: 100.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- License: MIT-0
- Official: no

## Install

```sh
/plugin marketplace add aws-solutions-library-samples/guidance-for-claude-code-with-amazon-bedrock
/plugin install security@aws-claude-code-plugins
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-23 by tashan (https://tashan.sh) from public evidence. Scorer s5.
