How to run a security review on code written by Claude Code
Anthropic gives Claude Code two security reviews: the /security-review command, which analyzes your code from the terminal, and a GitHub Action that reviews each new pull request and comments inline with the concerns it finds.[1] The action runs on your GitHub Actions runners with an Anthropic API key, and for a pull request it analyzes only the changed files.[2]
IonWarp's Security Review checks pull requests on GitHub for authorization and trust-boundary changes, injection, exposed secrets and new attack surface. The planner adds it to the pull requests whose change needs it, next to Code Review, which runs on every one. On 13 benchmark pull requests with 18 known security issues, DeepSeek v4.1 Flash, the model it runs, scored an F1 of 62.5% at about 6 cents a review; the Qodo app scored 73.3%.[3]
IonWarp and Claude Code's two security reviews
Anthropic facts are from its public documentation, read on 2026-10-02; numbered notes link to the exact page.
IonWarp and Claude Code's two security reviews| Criterion | IonWarp | /security-review command | Security review GitHub Action |
|---|
| What it is | A security reviewer in a GitHub app; the planner adds it to the pull requests that need it | A Claude Code command that analyzes your codebase for potential security concerns[1] | A GitHub Action that uses Claude to analyze code changes for security vulnerabilities[2] |
|---|
| When it runs | When the planner finds a pull request's changes need it | When you run it in the terminal[1] | Automatically when a new pull request is opened[1] |
|---|
| What it posts | Findings with a severity, the attack path, a suggested fix and an AI fix prompt, tracked across pushes | Potential security concerns in your Claude Code session[1] | Inline comments on the pull request with concerns and recommended fixes[1] |
|---|
| Where it runs | IonWarp's hosted service — no CI minutes, no API key in your repository | Your Claude Code session, on a Pro or Max plan or an API Console account[1] | Your GitHub Actions runners, with an Anthropic API key[2] |
|---|