Skip to main content
Which rules Guardian scans with depends on how it runs scans, and this differs by integration. Check which row applies to you before assuming your Policies are in effect.
If you use the recommended Claude Code remote plugin, your Policies do not apply.Guardian’s hooks run a fixed ruleset rather than reading your Policies configuration. If you have tuned your Policies and expect those rules to run in Claude Code, they will not, and Guardian may appear to miss findings that a CI or platform scan reports.If you require custom rules, see Semgrep’s #mcp Slack community for assistance.

What Guardian scans for

Guardian scans generated files using Semgrep Code, Supply Chain, and Secrets, so findings can cover:

Guardian does not replace CI scans

Guardian runs as your agent writes code; your CI and platform scans run on push, pull request, or a schedule and always enforce your Policies. Continue running Semgrep in CI. See Set up and deploy scans.