METAL for iPhone

Read AI news in the METAL app.

Download METAL and discover fresh AI stories every day.

Download on the App Store

For iPhone · Free download

Search for METAL AI Magazine in the App Store on your iPhone.

METAL

AI GlossaryㅋWords you meet while using AI

Claude Security

A code security scanner built by Anthropic that finds vulnerabilities in GitHub repositories and proposes fixes.

In plain words

Claude Security is a service that reviews software repositories on your behalf to spot security risks. It's less like an inspector checking a single brick for cracks, and more like one who traces how the wiring runs from room to room throughout the building. Rather than catching a typo in one file, it tracks how a value passed in from one part of the code gets used elsewhere to uncover problems.

When a scan finishes, each issue found comes packaged with what kind of risk it is, how likely it is to be a real problem, how severe it would be if triggered, and how to fix it. It doesn't apply the fix to the code automatically, though — a person has to review and approve it before any actual code changes begin.

Right now it's a beta service for customers on Anthropic's enterprise plan, and an admin has to turn the feature on and connect GitHub repository access in advance. Support is also limited to repositories hosted on GitHub.

How it shows up in the news

In articles, you'll see it used like "Claude Security started running a scan with Claude Mythos 5." Two things are easy to misunderstand here. First, this isn't a tool that automatically patches vulnerabilities — it finds problems and proposes fixes, and a person has to review and approve before anything is actually applied. Second, the model that detects vulnerabilities isn't the same as the one that fixes the code. Detection is done by Mythos 5, but the actual fix work runs on whatever Claude Code model the organization was already using.

Try it yourself

  1. An org admin turns on Claude Security and the Claude Code web feature, and grants the GitHub app access to the target repository.
  2. A user picks one of the connected repositories on the Claude Security webpage, narrowing the scope to a specific branch or folder if needed.
  3. Wait for the scan to finish. Since it traces data flow between files in the background, this can take some time.
  4. Check the risk rating and suggested fix attached to each item in the results list.
  5. Pick an item to fix, and in the fix session that opens, review and approve the suggested patch yourself.

See also

Stories using this term

Browse every entry