‹ The Index

Claude Security Linter

plugin

A pre-tool-use hook plugin that automatically scans code for security vulnerabilities before Claude writes it to disk. Detects eval() usage, Function constructor abuse, hardcoded API keys and secrets, Bearer tokens, AWS credentials, innerHTML/outerHTML XSS vectors, inline private keys, and GitHub personal access tokens. Uses a two-tier severity system: errors block the write with detailed remediation guidance, while warnings allow the write but inject advisory context. Runs as pure Node.js wi...

Works with: Claude Code (native)
native: this artifact type is that client's own format

Category: Security — see all ranked ›

Install (Claude Code):

/plugin marketplace add anthropics/claude-plugins-community
/plugin install claude-security-linter@claude-community
Looking for a replacement? npx tashan-cli doctor is free and tells you everything above about your whole config. tashan Pro names the replacement — which one, and how it measures. $6/mo.

Security audit

Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.

What changed recently

You are reading this because you came looking. tashan Pro gives tashan doctor the history behind it, so a run over your own config says which of YOURS moved.

You searched for one. Check the rest of your stack:

npx tashan-cli doctor

Reads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.

tashan Pro$6/mo

We recorded 1 change to Claude Security Linter in the last 45 days. Pro tells you on the day — for the servers in your own config, not the ones you thought to look up.

Start a 7-day trial › Everything measured on this page stays free.

Show your score

Measured this well? Put the live badge in your README — it updates as the score does.

tashan badge for Claude Security Linter
[![tashan](https://tashan.sh/badge/plugin-its-animay-claude-security-linter-claude-security-linter.svg)](https://tashan.sh/capability/plugin-its-animay-claude-security-linter-claude-security-linter.html)

source ↗  ·  plugin:its-animay/claude-security-linter/claude-security-linter

Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.

Measured 2026-09-13  ·  scorer s5  ·  how  ·  something wrong here?