Gate pull requests with targeted diff-aware AI security review using Claude Code Security Review
Run a Claude Code powered security review pass on trusted pull requests so suspicious auth, secret, injection, and unsafe logic changes surface before merge.
Prerequisites
GitHub Actions, Claude API access, pull request workflows on trusted repositories
Installation
Requirements and caveats from upstream:
- ├── requirements.txt # Python dependencies
Basic usage or getting-started notes:
Add this to your repository's .github/workflows/security.yml:
yaml
name: Security Review
Source: https://github.com/anthropics/claude-code-security-review
Extracted from upstream docs: https://raw.githubusercontent.com/anthropics/claude-code-security-review/HEAD/README.md