Anthropic released an open-source framework for autonomous vulnerability discovery and remediation using Claude. It automates the full cycle of recon, find, triage, report, and patch.
Anthropic released an open-source framework called 'Defending Code Reference Harness' for autonomous vulnerability discovery and remediation. It is a reference implementation that uses Claude to automatically find and fix security vulnerabilities in codebases.
Anthropic developed this framework based on learnings from partnering with security teams at several organizations since launching Claude Mythos Preview. It automates a five-step loop: recon, find, triage, report, and patch.
This framework demonstrates the potential of AI agents to actively discover and patch security vulnerabilities. Being open-source, it invites experimentation and improvement from the security community, and could set a new standard for AI-driven security automation.
The community noted that Anthropic's open-source vulnerability detection framework is not maintained, with criticism that it is actually a tool to drive purchases of commercial products. Additionally, execution costs could reach hundreds to thousands of dollars, and non-deterministic results led to it being called 'roulette-style,' with opinions that it may be less efficient than hiring existing security engineers. On the other hand, some cited the Mythos report, positively evaluating cost-effectiveness by claiming AI matches the productivity of 10 security engineers.