Anthropic's security plugin reviews what Claude Code wrote, not code Claude runs
Anthropic shipped a security-guidance plugin for Claude Code that reviews code after it's written. The problem? Real-world agent exploits happen before code hits a file. A practical breakdown of what the plugin gets right, what it misses, and why pre-action authorization still matters.