Claude Code's /security-review command reads the changes on your current branch and looks for common vulnerabilities: injection, cross-site scripting, authentication and authorisation flaws, insecure data handling and risky dependencies. It is a worthwhile first pass. It reads source code only, so it cannot see the running app, its hosting, secrets held elsewhere or what the business meant each user to be able to reach.
That gap matters most when the app was built by someone who is not a developer and is about to hold company data or face customers. This post explains what Anthropic's review does, how to run it, where it stops, and where a person, such as an engineer carrying out a vibe code audit, has to take over. Everything here about the tool comes from Anthropic's own documentation, read on 8 Oct 2026. Claude Code changes often, so check the current docs before relying on any detail. If Claude Code itself is new to you, start with our explainer on Claude Code for business.
What does Claude Code's security review do?
Anthropic announced /security-review on 6 Aug 2025, alongside a GitHub Action that runs the same kind of review on pull requests. The announcement lists what it looks for: SQL injection risks, cross-site scripting, authentication and authorisation flaws, insecure data handling and vulnerabilities in dependencies. Once it has reported, you can ask Claude to implement a fix for each issue.
The current Claude Code commands reference describes it more precisely. It analyses the diff between your branch and the default branch on origin, identifies risks such as injection, problems with authentication or authorisation, and data exposure, and needs an origin remote to work. Anthropic's help centre article on automated security reviews (dated 16 Mar 2026) adds that these reviews should sit alongside your existing security practice and manual code review rather than replace them.
Anthropic has also described where the tooling helped its own teams. The announcement says the GitHub Action caught a remote code execution vulnerability, exploitable through DNS rebinding, in an internal tool, and a server-side request forgery flaw in a proxy built to manage internal credentials. Both were fixed. That is a vendor's own account, but it shows the kind of flaw a review of the code can catch before it ships.
How do you run it?
- Update Claude Code to the latest version and open it in the project directory.
- Check the project is a git repository with a remote called
origin, usually on GitHub. Without one, the review has nothing to compare against and fails. - Do the work on a branch, so the changes you want checked differ from the default branch.
- Type
/security-review. Claude explains each issue it finds. - Ask Claude to fix the issues you agree with, then read those fixes before you commit them.
For pull requests, Anthropic publishes an open-source GitHub Action, claude-code-security-review, which reviews the changed files and posts inline comments. Its README warns that it is not hardened against prompt injection and should only be used on trusted pull requests, and it recommends requiring maintainer approval before workflows run for external contributors. Organisations on Anthropic's Team and Enterprise plans can also use Code Review, a managed pull request review that is currently a research preview.
Where does /security-review sit among Anthropic's other review tools?
Anthropic's documentation presents several review tools as layers, each working at a different stage. A team that uses only one of them has a narrower safety net than it may assume.
| Tool | When it runs | What it covers | Availability |
|---|---|---|---|
| Security guidance plugin | Automatically, while Claude writes code | A pattern check on each edit, a background review of each turn's changes, and a deeper review when Claude commits or pushes | All plans |
/security-review | When you ask | One pass over the changes on the current branch | All Claude Code users |
Claude Security plugin (/claude-security) | When you ask | A deeper scan of a whole repository or a set of changes, with each finding checked independently and patches you apply yourself | A paid plan, Anthropic API access or a third-party provider such as Amazon Bedrock |
| Code Review | On pull requests | Correctness and security review with full codebase context | Team and Enterprise plans, research preview |
| Your own CI scanners | On every build | Static analysis, dependency and supply-chain checks, and policy enforcement | Whatever you configure |
Two details from the docs matter for anyone deciding whether an app is ready. None of the security guidance plugin's layers blocks a write or a commit: findings go back to Claude as instructions, and Anthropic says the review model can miss issues. The Claude Security plugin's page also notes that scans are nondeterministic, so two scans of the same code can surface different findings. These tools improve the odds of catching a flaw, but the decision to publish stays with you.
What can't Claude Code's security review see?
Anthropic is direct about the main limit. Its documentation says that whether you ask Claude to review existing code or run the Claude Security plugin, the review reads the source code in your checkout, "not a running site or deployed service". /security-review works on the same source, limited to your branch's changes. In practice that leaves several things outside its view.
The running app and how it is deployed
Many problems in AI-built apps sit in configuration rather than in code: database access rules set in a hosting dashboard, a storage bucket left public, settings that differ between test and live, or no backups at all. If those settings are not in the repository, the review cannot read them.
What a stranger can reach without logging in
One of the gaps we find most often in AI-built apps is a database that anyone can read once they find its address, even though the login screen looks secure. Confirming whether an anonymous visitor can fetch data that way means testing the live service. A review of source code can point to code that looks risky, but it cannot confirm what the deployed app actually hands out.
Code outside the diff
/security-review covers only the changes on your current branch. If a colleague has committed everything straight to the main branch, or built the whole app before anyone thought to check it, there may be little or nothing in that diff. For code that already exists, Anthropic suggests asking Claude to review a specific file or directory, or running the Claude Security plugin across the repository. Both still read source only.
Secrets that are not in today's changes
An API key committed months ago stays in the repository's history even after someone deletes it from the current files. Keys held in a hosting dashboard, a shared document or on the builder's laptop are not in the checkout at all. A review of the diff will not tell you which keys exist, who can see them or whether any need rotating.
What the business intended
A review can see whether a route checks the user's role. It cannot know that a sales manager should see their own team's pipeline but not payroll, or that a client should see only their own invoices. That intent comes from the business, and somebody has to write it down before anyone, human or AI, can check the app against it.
Who owns the code and accounts
Whether the code, hosting and domain sit in company accounts or in one person's personal accounts never shows up in a code review, yet it decides what happens when the builder leaves or loses access.
Why does a person still have to sign off?
Anthropic's security documentation for Claude Code states that you are responsible for reviewing proposed code and commands for safety before approving them. Its review tools follow the same pattern: they report and suggest, and a person decides. Code Review findings do not approve or block a pull request, and patches from the Claude Security plugin are never applied automatically.
That is a sensible design, and it means someone in your business has to make the call. For an internal calculator with no personal data, the builder running /security-review and fixing what it finds may be a reasonable level of care. For anything holding customer or staff records, taking payments or sold to other businesses, the person accepting the risk should have someone technical check the parts the tool cannot see. Our risk guide for apps your team built with AI sets out how the level of checking should rise with what the app holds.
If you are the manager who has just found out about a colleague's app, our guide to what to do when a colleague built a tool with AI covers the first questions to ask. Apps like this are also worth recording as part of any wider review of the shadow AI already happening in your business. Whether Claude itself is safe to use with company data is a separate question, covered in is Claude safe for business.
How does a vibe code audit complement Claude Code's review?
We treat /security-review as a useful input. If the builder has run it and fixed what it found, our engineers start from a cleaner codebase and spend their time where the tool cannot reach.
A Safe to Ship review of an AI-built app covers six areas: who can see your data (in the database as well as on the screen), exposed keys and passwords, vulnerable code and libraries, connections to your other systems, backups and recovery, and who owns the code, hosting and accounts. You get a written report graded by severity, a walk-through with the engineers who did the review and a keep, fix or rebuild recommendation. After any fixes, our CTO signs off the reviewed version. That sign-off covers the version we reviewed on the date we reviewed it. It is not a guarantee against every attack.
If your team will keep building, the longer-term answer is to run checks on every change. Our Ready to Build setup configures the AI coding tool with security rules, puts the code in a GitHub organisation the business owns, adds AI pull request review with dependency and secret scanning, moves keys into a secrets manager and separates test and live environments, then trains up to two people to work with it. Our guide on how to set up Claude Code safely for a business team covers the settings in more detail.
How SpotDev can help
If an app built with Claude Code, Cursor or Codex is about to hold customer data or go in front of customers, our engineers can review it, fix what isn't safe and have our CTO sign off the version you use. Safe to Ship audits start from £1,500, priced by the app's risk tier. Request a quote for a vibe code audit and tell us what the app does and who uses it.
Frequently asked questions
What does Claude Code's /security-review check?
It analyses the changes on your current branch, compared with the default branch on origin, for common vulnerabilities. Anthropic lists SQL injection, cross-site scripting, authentication and authorisation flaws, insecure data handling and vulnerable dependencies. Claude explains each issue it finds, and you can then ask it to implement fixes. The command needs a git repository with an origin remote.
Can Claude Code's security review check a live website or deployed app?
No. Anthropic's documentation says its reviews work on the source code in your local copy of the repository and do not test a running site or deployed service. Hosting settings, database access rules configured outside the repository, secrets held elsewhere and what an anonymous visitor can reach on the live app all need checking separately.
Is /security-review enough before publishing an app built with AI?
For a low-risk internal tool with no personal data, running it and fixing what it finds may be a reasonable level of care. For apps holding customer or staff records, taking payments or sold to other businesses, it is a first pass. Anthropic says automated reviews should sit alongside manual code review, and someone still has to check configuration, access rules and ownership.
Does /security-review work if all the code is on the main branch?
It reviews the difference between your current branch and the default branch on origin, so if everything has been committed straight to main there may be little to review. For existing code, Anthropic suggests asking Claude to review specific files or directories, or using the Claude Security plugin for a deeper scan of the whole repository.
Is the claude-code-security-review GitHub Action safe to run on every pull request?
Anthropic's README says the action is not hardened against prompt injection and should only be used on trusted pull requests. It recommends requiring maintainer approval before workflows run for external contributors. For a public repository, or any repository that accepts outside contributions, turn that setting on before adding the action.
How is a vibe code audit different from Claude Code's review?
A vibe code audit is carried out by our engineers across six areas, including who can see your data in the database, exposed keys, connections to other systems, backups and ownership of code and accounts. It looks at how the app is configured and hosted as well as its source code, and ends with a severity-graded report and, after fixes, a CTO sign-off of the reviewed version.
Sources
- Anthropic, Automate security reviews with Claude Code, 6 Aug 2025
- Anthropic, Claude Code docs: Commands (the /security-review entry), accessed 8 Oct 2026
- Anthropic, Claude Code docs: Catch security issues as Claude writes code, accessed 8 Oct 2026
- Anthropic, Claude Code docs: Security, accessed 8 Oct 2026
- Anthropic, Claude Code docs: Scan your codebase for vulnerabilities, accessed 8 Oct 2026
- Anthropic, Claude Code docs: Code Review, accessed 8 Oct 2026
- Anthropic Help Centre, Automated Security Reviews in Claude Code, 16 Mar 2026
- Anthropic, claude-code-security-review (GitHub repository README), accessed 8 Oct 2026
Get new articles by email
Practical guides from the SpotDev team, when we publish them.
By submitting this form, you consent to us sending you emails with our latest content. Privacy Policy



