# Security Guidance Setup

> Security companion — sets up and integrates the official Anthropic security-guidance plugin (anthropics/claude-code, free, ships in the claude-plugins-official marketplace) into idea-to-deploy. security-guidance is a shift-left, always-on reviewer of Claude-generated code: instant regex pattern warnings on every Edit/Write, an LLM diff review on Stop that feeds high-severity findings back before you see the response, and an agentic commit/push reviewer that traces cross-file data flow (IDOR, auth bypass, SSRF). Use when the user asks about the security-guidance plugin, realtime/shift-left security review as code is written, automatic vulnerability catching on edit or commit, or wiring continuous security review into the lifecycle. Distinct from /security-audit (on-demand deep audit report) — security-guidance is the continuous layer that complements it. Detects install, prints the verified CLI commands, and maps the plugin onto the lifecycle; does NOT vendor upstream code.

## Facts
- Page: https://tashan.sh/capability/skill-hih-diman-security-guidance-setup
- tashan id: skill:HiH-DimaN/security-guidance-setup
- Source: https://github.com/HiH-DimaN/idea-to-deploy
- Type: skill
- Category: security
- tashan score: not scored (catalogued only — too little public evidence)
- Adoption: 9.0
- Upkeep: 62.0
- Freshness: 94.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- License: MIT
- Official: no

## Install

```sh
cp -r security-guidance-setup ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-14 by tashan (https://tashan.sh) from public evidence. Scorer s5.
