Claude Security: scanning code with judgment, not just rules, and why that doesn't take you out of the loop
cybersecurity AI
Every new vulnerability scanner promises the same thing: fewer false positives, more context, less noise for the security team. Anthropic just launched the public beta of Claude Security with that same promise, but it’s worth looking closely at what it actually does differently from a traditional SAST tool, and above all, what part of the work still stays on your plate even when the tool is good.
What Claude Security is
Claude Security is a tool built for security teams that automates two stages usually kept separate: finding vulnerabilities and proposing how to fix them. Instead of matching known patterns like a classic rule-based scanner does, it analyzes code by understanding context and tracing how data moves across different files in the same repository.
That difference isn’t cosmetic. Traditional scanners are good at catching what they already know (an unsafe function, a typical injection pattern) but miss vulnerabilities that depend on how several components interact with each other. That kind of logic bug, the one that only shows up when two modules combine in a specific way, is exactly the blind spot of rule-based tools.
How the workflow works
The process has three concrete steps:
- Scan: goes through the repository understanding the code’s context, not just searching for strings or functions flagged as risky.
- Adversarial validation: every finding goes through a review where the system itself challenges its own result before reporting it, with the stated goal of reducing false positives.
- Proposed patch: for each confirmed finding, it suggests a targeted fix that respects the code’s existing structure, ready for a human to review.
The tool targets vulnerabilities like memory corruption, injections, authentication bypasses, and logic errors that depend on context and multiple components, exactly the kind of finding a pattern-based scanner tends to miss.
What doesn’t change: the human stays in the loop
Here’s the part that matters most to me as an analyst: no patch gets applied on its own. Human review and approval is mandatory before any fix reaches the code. That’s the right design decision, and it’s also a signal that Anthropic isn’t selling this as a replacement for the security team’s judgment, but as a way to get faster to the point where that judgment is actually needed.
The tool integrates with the usual workflow (GitHub, Slack, Jira, CSV or Markdown export) and today is available as a Claude Code plugin in beta, with scans enabled for Enterprise customers.
The practical rule
Claiming a scanner “understands context” is an easy promise to make in a product page and a hard one to hold up against real code, with legacy dependencies, inconsistent conventions, and accumulated technical debt. Before trusting the false-positive reduction any new tool promises, this one included, run it against your own codebase and compare the findings against what you already know is there. The real guarantee isn’t the AI doing the analysis, it’s that the final patch goes through a human before it touches production. That part doesn’t get automated, and it shouldn’t.
Have you already tried it on one of your own repos? I’d like to compare notes on how well it separates signal from noise in practice, reach out on LinkedIn.
Sources: Claude Security, Anthropic on how it works, the public beta, and the human approval workflow.