A small update to an invoice page can look ready: the page loads and the download works. Except changing the invoice number lets a customer download someone else’s bill. A very efficient feature, for the wrong person.
Anthropic’s Claude Code Security Reviewer looks for flaws like this. It uses GitHub Actions to review pull requests—proposed code changes. Claude checks changed files in context, filters likely false alarms and comments beside suspicious lines with explanations and possible fixes.
How to set it up
1. Choose a GitHub repository where you can manage settings and enable Actions. You need a funded Anthropic API key enabled for Claude API and Claude Code usage. API usage is billed separately; GitHub Actions quotas or charges also apply.
2. In the repository, open Settings → Secrets and variables → Actions → New repository secret. Name it CLAUDE_API_KEY, paste your API key as the value and click Add secret. GitHub’s secret setup guide shows these steps.
3. Copy the workflow from Anthropic’s Quick Start into
.github/workflows/security.yml in your repository. Save and commit it. The example includes permission to post review comments and references your saved secret.4. Open a trusted pull request from a branch in that repository. Check the run in the Actions tab, then review any comments on the changed lines. Confirm each finding before applying a fix.
Anthropic recommends trusted pull requests only: malicious instructions in submitted code can manipulate the reviewer.
In the invoice example, finding the document is only half the job; checking who may read it is the other half. This puts that security question beside the code, while the team can still change it.