anthropics/defending-code-reference-harness
Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize observed · 2026-08-28
Health v2 · maintenance only
57/100
- Activity 96
- Release rhythm 35
- Longevity 7
Flags: no_releases young no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 103
- days_rel: n/a
- days_push: 27
- n_releases_24m: 0
Adoption not part of the score
7368 stars · 594 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
A reference implementation from Anthropic for autonomous vulnerability discovery and remediation using Claude, including Claude Code skills for threat modeling, scanning, triage, and patching, plus an autonomous scanning harness configured for C/C++ memory vulnerabilities. It also includes detection-and-response skills for hunting attackers already present in logs.
Use cases
- find memory safety vulnerabilities in C/C++ codebases with an LLM agent
- build a threat model for my repository before scanning
- triage and verify LLM-discovered vulnerability findings to reduce false positives
- automatically generate patches for confirmed vulnerabilities
- customize an autonomous vulnerability scanning pipeline for my language or vuln class
- hunt for signs of an attacker already in my logs and propose a response
When to choose
- you want an open-source, customizable reference pipeline for LLM-driven vulnerability discovery and remediation
- you use Claude APIs (including Bedrock, Vertex, or Azure) and want to build your own security scanning workflow
- you need skills for interactive threat modeling, scanning, triage, and patching in Claude Code
- you want to learn Anthropic's best practices for securing source code with LLMs
When to avoid
- you need a maintained, production-ready product with support - the repo explicitly is not maintained and accepts no contributions
- you want a turnkey scanner that works on every codebase out of the box - the harness is a reference, not a product
- you prefer a managed hosted solution - consider Anthropic's Claude Security product instead
- you need a permissive license - the license is non-standard (NOASSERTION)
Facets
framework · maturity maintenance
security vulnerability-scanning agent-framework penetration-testing developer-tools security developer-tools artificial-intelligence python cli cross-platform vulnerability-discovery threat-modeling triage patching claude-code-skills llm-security memory-safety asan detection-and-response reference-implementation ai-agents docker
5 sources
- readme: https://github.com/anthropics/defending-code-reference-harness · fetched 2026-08-28 · 989bec13ca56
- homepage: https://claude.com/blog/using-llms-to-secure-source-code · fetched 2026-08-29 · aa0c99625569
- site_page: https://platform.claude.com/docs · fetched 2026-08-29 · 42493d4b28e3
- site_page: http://claude.com/pricing · fetched 2026-08-29 · 71972a93716a
- site_page: https://claude.com/pricing · fetched 2026-08-29 · 54ae70c3efc4
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| anthropics/defending-code-reference-harness | main | 57 |
For agents
markdown · JSON · MCP: product_card(name="anthropics/defending-code-reference-harness")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem