Skip to main content
Glama

seed_security_guidance

Write a claude-security-guidance.md file at your repo root to guard Claude Code as it generates code. Detects your Starter Series template and tailors the security rules to it.

Instructions

Generate a starter claude-security-guidance.md at the repo root, tailored to the detected Starter Series template. The file is consumed in-session by Anthropic's Claude Code Security Guidance Plugin (released 2026-05-26) as a guard while Claude writes code. Use force: true to overwrite an existing file.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pathNoPath to the repo (default: the MCP server's cwd). Use the absolute path of the project the user is working in.
forceNoOverwrite an existing claude-security-guidance.md. Default false (returns status='exists' instead).

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
statusYes
filePathYes
repoPathYes
bytesWrittenYes
relativePathYes
matchedStarterYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changedv0.5.3
    • removedOutput schema / properties / matchedStarter / anyOf
      Removed value: -[
      -  {
      -    "type": "string"
      -  },
      -  {
      -    "type": "null"
      -  }
      -]
    • addedOutput schema / properties / matchedStarter / type
      Added value: +[
      +  "string",
      +  "null"
      +]
  2. First observedv0.4.0

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden. It discloses that the tool writes a file at the repo root, that the generated content varies by detected template, and that force overwrites an existing file. It could say more about permissions or failure modes, but the schema covers the default 'exists' status.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded and only three sentences, with the core action first and the overwrite instruction last. The plugin release date is minor trivia that does not help an agent invoke the tool, preventing a perfect score.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a two-parameter write tool with full schema coverage and an output schema, the description supplies enough context: what file, where, why it exists, and how to overwrite. It is close to complete, though it omits any note on what happens when no Starter Series template is detected.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, and both parameters are fully documented there (path defaults to cwd, force defaults to false). The description only reiterates the force overwrite behavior already stated in the schema, so it adds little parameter meaning beyond the structured field.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource: 'Generate a starter `claude-security-guidance.md` at the repo root'. It also adds the tailoring condition (detected Starter Series template), which clearly separates it from the audit_* siblings that inspect rather than create.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear context for use: the file is consumed by the Claude Code Security Guidance Plugin and acts as a guard while Claude writes code, and explains that force: true should be used to overwrite. It does not name a when-not or a direct alternative, but no sibling offers the same seeding function.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.