Secure Claude Code 1.2.0: Malicious Plugin Guard Expansion
Secure Claude Code 1.2.0 expands plugin threat coverage beyond install-source checks into post-install plugin behavior, sideloaded extension paths, and trust-boundary tampering.
New malicious-plugin guard packs
plugin-hook-origin-guard- blocks plugin hook commands that execute from temp, download, scratch, or other paths outside the plugin trust boundary
plugin-exec-chain-guard- blocks dangerous download-and-execute or inline interpreter chains embedded inside plugin hook and command definitions
plugin-surface-expansion-guard- blocks plugins that widen their operational surface onto sensitive lifecycle events or broad mutation-plus-shell hook coverage
sideloaded-extension-guard- blocks sideloaded local plugin and extension installs from
.vsix, archive, unpacked, temp, and download paths
- blocks sideloaded local plugin and extension installs from
plugin-trust-boundary-tamper-guard- blocks plugins that try to weaken
CLAUDE.md,.mcp.json, plugin hook config, or Secure Claude Code control surfaces after install
- blocks plugins that try to weaken
Why this matters
Secure Claude Code already covered malicious plugin entry paths through install-source and manifest checks. This release closes the next important gap: what a plugin tries to do after it has been accepted.
That means better protection against:
- malicious plugin hook origins
- plugin-packaged payload execution chains
- broad plugin lifecycle interception
- sideloaded extension bypasses
- plugin persistence and policy tampering
Included in this release
- updated
balancedandstrictprofiles - updated generated
hooks/hooks.jsonfor the plugin path - updated
README.md,GUARDS.md, andSIGNATURES.md - expanded smoke coverage for the new malicious-plugin signatures
Verification
claude plugin validate .bash tests/smoke.shbash scripts/package-release.sh efij/secure-claude-code 1.2.0- GitHub Actions CI: green on
mainandv1.2.0
Secure Claude Code remains a local-first modular security layer for Claude Code, Claude cowork workflows, MCP tools, malicious plugins, secrets, prompt injection fallout, exfiltration paths, and risky agent actions.