Anthropic released Claude Code Security as a limited research preview for Enterprise and Team customers, with expedited free access for open-source maintainers. The tool reasons about data flow across a codebase, re-examines each finding in a multi-stage verification pass, assigns severity and confidence ratings, and proposes patches that are applied only with human approval.
Why it matters
It packages frontier-model vulnerability finding for defenders with explicit human approval gates, amid concerns about the same capability aiding attackers.
Key facts
As stated in the sources, with where to find them.
- Released as a limited research preview to Enterprise and Team customers, with expedited access for open-source maintainers.Opening and 'Getting started'
- Every finding goes through multi-stage verification where Claude tries to prove or disprove it; nothing is applied without human approval.Section 'How Claude Code Security works'
- Anthropic restates that Opus 4.6 found over 500 vulnerabilities in production open-source codebases.Section 'Using Claude for cybersecurity'
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Is AI shifting the balance between finding and fixing vulnerabilities?Discovery is ahead. AI finds real vulnerabilities faster than they are fixed, and simple checks overstate how often AI patches work.
- Can AI agents defend and oversee systems on their own?Not yet. Agents are weak on realistic defensive benchmarks and monitors can be evaded; assistants help analysts who stay in charge.
Sources
Related records
Feb 5, 2026
May 22, 2026
Apr 7, 2026
Mar 6, 2026
Oct 3, 2025
Oct 30, 2025