secure-coding
3 resources across 2 kinds
Frameworks & agents
- Open ↗Security Guidance (Claude Code plugin)cloud costlicence
Claude Code plugin that hooks Edit/Write, end-of-turn, and git commit to flag ~25 dangerous code patterns and run LLM diff reviews for injection, XSS, SSRF, IDOR, and hardcoded secrets in generated code.
- Open ↗Semgrep Agent Skillslicence
Agent-Skills pack for AI coding agents, generated largely from open-source Semgrep rules: secure-coding guidance across 15+ languages, OWASP LLM Top 10 (2025) guidance, and Semgrep scanning plus custom-rule authoring.
Benchmarks
- Open ↗jev-sec-benchcloud costhosted
MIT-licensed Go benchmark that scores TypeSafe's hosted Jev model on 662 labelled messages (263 injections) and 200 matched vulnerable/secure code pairs; needs a TypeSafe API key, and the documented runner is not in the tree.