Awesome Claude Code Security banner
efij efij

Awesome Claude Code Security

Security community

Description

A awesome curated list of security resources, hardening tools, threat research, and governance frameworks specifically for Claude Code

Installation

This entry records only its repository, not the path inside it, so there is no exact command to give. Open the source below and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

README

Awesome Claude Code Security

[![Awesome](https://awesome.re/badge-flat2.svg)](https://awesome.re) [![Track Awesome List](https://www.trackawesomelist.com/badge.svg)](https://www.trackawesomelist.com/awesome-claude-code-security) [![License: CC BY 4.0](https://img.shields.io/badge/License-CC%20BY%204.0-lightgrey.svg)](https://creativecommons.org/licenses/by/4.0/) [![PRs Welcome](https://img.shields.io/badge/PRs-welcome-brightgreen.svg)](CONTRIBUTING.md) [![Last Commit](https://img.shields.io/github/last-commit/anthropics/claude-code.svg?label=upstream%20activity)](https://github.com/anthropics/claude-code)

**A curated collection of security resources, hardening tools, threat research, and governance frameworks for [Claude Code](https://code.claude.com) and the AI coding agent ecosystem.**

*For security engineers, AppSec teams, platform engineers, and anyone deploying Claude Code in production.*

[Official Docs](#-official-security-documentation) · [Hardening](#-hardening-and-permissions) · [MCP Security](#-mcp-security) · [Tools](#-security-tools-and-scanners) · [Enterprise](#-enterprise-governance-and-policy) · [Research](#-research-talks-and-writeups)


**Why this list?** Claude Code runs shell commands, edits files, calls APIs, and installs MCP servers — all with your user privileges. One malicious `.claude/settings.json`, a poisoned MCP tool, or a prompt injection hidden in a README can lead to RCE, credential theft, or silent data exfiltration. This list exists to help you harden, govern, and monitor every surface.


Contents