Skip to content

Secure Claude Code 1.2.0: Malicious Plugin Guard Expansion

Choose a tag to compare

@github-actions github-actions released this 26 Mar 09:59
· 42 commits to main since this release

Secure Claude Code 1.2.0 expands plugin threat coverage beyond install-source checks into post-install plugin behavior, sideloaded extension paths, and trust-boundary tampering.

New malicious-plugin guard packs

  • plugin-hook-origin-guard
    • blocks plugin hook commands that execute from temp, download, scratch, or other paths outside the plugin trust boundary
  • plugin-exec-chain-guard
    • blocks dangerous download-and-execute or inline interpreter chains embedded inside plugin hook and command definitions
  • plugin-surface-expansion-guard
    • blocks plugins that widen their operational surface onto sensitive lifecycle events or broad mutation-plus-shell hook coverage
  • sideloaded-extension-guard
    • blocks sideloaded local plugin and extension installs from .vsix, archive, unpacked, temp, and download paths
  • plugin-trust-boundary-tamper-guard
    • blocks plugins that try to weaken CLAUDE.md, .mcp.json, plugin hook config, or Secure Claude Code control surfaces after install

Why this matters

Secure Claude Code already covered malicious plugin entry paths through install-source and manifest checks. This release closes the next important gap: what a plugin tries to do after it has been accepted.

That means better protection against:

  • malicious plugin hook origins
  • plugin-packaged payload execution chains
  • broad plugin lifecycle interception
  • sideloaded extension bypasses
  • plugin persistence and policy tampering

Included in this release

  • updated balanced and strict profiles
  • updated generated hooks/hooks.json for the plugin path
  • updated README.md, GUARDS.md, and SIGNATURES.md
  • expanded smoke coverage for the new malicious-plugin signatures

Verification

  • claude plugin validate .
  • bash tests/smoke.sh
  • bash scripts/package-release.sh efij/secure-claude-code 1.2.0
  • GitHub Actions CI: green on main and v1.2.0

Secure Claude Code remains a local-first modular security layer for Claude Code, Claude cowork workflows, MCP tools, malicious plugins, secrets, prompt injection fallout, exfiltration paths, and risky agent actions.