Ross ROSS = Recommend OSS · open-source software intelligence for agents

anthropics/defending-code-reference-harness

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize observed · 2026-08-28

github.com/anthropics/defending-code-reference-harness · homepage · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

57/100

  • Activity 96
  • Release rhythm 35
  • Longevity 7

Flags: no_releases young no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 103
  • days_rel: n/a
  • days_push: 27
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

7368 stars · 594 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

A reference implementation from Anthropic for autonomous vulnerability discovery and remediation using Claude, including Claude Code skills for threat modeling, scanning, triage, and patching, plus an autonomous scanning harness configured for C/C++ memory vulnerabilities. It also includes detection-and-response skills for hunting attackers already present in logs.

Use cases

  • find memory safety vulnerabilities in C/C++ codebases with an LLM agent
  • build a threat model for my repository before scanning
  • triage and verify LLM-discovered vulnerability findings to reduce false positives
  • automatically generate patches for confirmed vulnerabilities
  • customize an autonomous vulnerability scanning pipeline for my language or vuln class
  • hunt for signs of an attacker already in my logs and propose a response

When to choose

  • you want an open-source, customizable reference pipeline for LLM-driven vulnerability discovery and remediation
  • you use Claude APIs (including Bedrock, Vertex, or Azure) and want to build your own security scanning workflow
  • you need skills for interactive threat modeling, scanning, triage, and patching in Claude Code
  • you want to learn Anthropic's best practices for securing source code with LLMs

When to avoid

  • you need a maintained, production-ready product with support - the repo explicitly is not maintained and accepts no contributions
  • you want a turnkey scanner that works on every codebase out of the box - the harness is a reference, not a product
  • you prefer a managed hosted solution - consider Anthropic's Claude Security product instead
  • you need a permissive license - the license is non-standard (NOASSERTION)

Facets

framework · maturity maintenance

security vulnerability-scanning agent-framework penetration-testing developer-tools security developer-tools artificial-intelligence python cli cross-platform vulnerability-discovery threat-modeling triage patching claude-code-skills llm-security memory-safety asan detection-and-response reference-implementation ai-agents docker

5 sources

Member repositories

RepositoryRoleHealth v2
anthropics/defending-code-reference-harnessmain57

For agents

markdown · JSON · MCP: product_card(name="anthropics/defending-code-reference-harness")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem