# GPTsApp Plugins decision brief

## Security Guidance (claude-code)

Format: gptsapp-plugin-decision-brief/1.0.0
Plugin ID: gpa:plugin:6fe5b009a4324406ffc512ca1fd4a1d7f6c44b6b921604d5643cd6e7aaf35c44
Canonical: https://plugins.gptsapp.io/plugins/claude-code/anthropics/security-guidance
Source owner: anthropics
Declared author: Anthropic source repository
Repository: https://github.com/anthropics/claude-plugins-official
Package root: plugins/security-guidance
Package format: claude-plugin
Documented targets: Claude Code (claude-code)
Documented targets are source declarations, not tested compatibility. Other interfaces remain unknown.
Task scope: All recorded tasks
Recorded tasks: Review code (code-review); Configure workflows (workflow-rules); Review security (security-review)

Review the package's pattern warnings and model-backed code-review hooks before enabling them.

### Version and observation scope
Workflow-note version: Unknown
Workflow-note revision: Unknown
Workflow-note observation: 2026-09-07
Manifest version: Unknown
Manifest revision: Unknown
Manifest observation: Unknown
Component observation scope: observed-2026-09-07
A manifest observation does not revalidate older component or prerequisite notes.

### Installation and delivery
Package role: Unknown
Delivery boundary: Unknown
Access: Model-backed layers can send code and diffs to the configured model endpoint. Review data handling and usage costs.
License declaration: Consult the exact source terms; no hooks redistributed
A license declaration is not a directory redistribution or safety certification.
Official installation: https://code.claude.com/docs/en/discover-plugins
Installation note: Find security-guidance and review the hook layers and privacy section before installation.
Distribution: anthropic-official / security-guidance; path plugins/security-guidance; index revision 3deb821cb71ccfaaf2ffa9935e977df314ce5cd5; package revision 3deb821cb71ccfaaf2ffa9935e977df314ce5cd5
Distribution evidence: https://github.com/anthropics/claude-plugins-official/blob/3deb821cb71ccfaaf2ffa9935e977df314ce5cd5/.claude-plugin/marketplace.json

### Prerequisites by recorded task
- required: Claude Code CLI 2.1.144 or later, as stated by the observed README [Tasks: Review code; Configure workflows]
  Evidence: https://github.com/anthropics/claude-plugins-official/tree/main/plugins/security-guidance
- required: Python 3.8 or later and a working model-access path [Tasks: Review code; Configure workflows]
  Evidence: https://github.com/anthropics/claude-plugins-official/tree/main/plugins/security-guidance
The complete prerequisite inventory has not been established; unknown does not mean optional, free or unnecessary.

### Included components and observation limits
- Pattern, diff and commit-review hooks (Hooks): Three documented review layers; not a security certification; retained prior package observation, not revalidated by marketplace refresh
  Exact member count: Unknown.
Included Skill, Agent and Command files are not a request to install duplicate copies. File/configuration presence is not host activation.

### Source issues
No separately recorded issue. This is not a safety review.

### Independent runtime states
Package installed: Not observed
External connection: Not observed
Access authorized: Not observed
Task completed: Not observed
This brief includes no personal prerequisite answers, credentials or runtime checks. No winner, compatibility, safety or authorization verdict.

### Sources
- https://github.com/anthropics/claude-plugins-official/tree/main/plugins/security-guidance
- https://github.com/anthropics/claude-plugins-official/blob/3deb821cb71ccfaaf2ffa9935e977df314ce5cd5/.claude-plugin/marketplace.json
- https://github.com/anthropics/claude-plugins-official/tree/3deb821cb71ccfaaf2ffa9935e977df314ce5cd5/plugins/security-guidance
