anthropics/defending-code-reference-harness
- Source
- GitHub
- First trending
- Category
- Security
- GitHub stars
- 7,492
- Main language
- Python
This page introduces an external open-source repository. It is not an HDATF product.

What it does
A reference implementation for finding and fixing code vulnerabilities with Claude, with Claude Code skills for threat modeling, scanning, triage and patching plus an autonomous scanning harness. The repository is not maintained.
How it helps ATF
Worth comparing with Harness, since it runs a staged loop of recon, finding, triage, reporting and patching. Its separate triage step after scanning could be a reference for how Harness checks a result with evidence before reporting it.
License
Custom license Custom or non-standard license. Read the license file before any reuse.
More in this category
- NVIDIA/SkillSpector
SkillSpector scans AI agent skills for Claude Code, Codex and MCP before installation. It looks for vulnerabilities, malicious patterns, prompt injection, data exfiltration and supply-chain risks in Git repos, URLs, zip files or directories. - mukul975/Anthropic-Cybersecurity-Skills
A community library of cybersecurity skills for AI agents, not affiliated with Anthropic, mapped to frameworks such as MITRE ATT&CK and NIST CSF 2.0. It includes offensive and dual-use techniques for authorized penetration testing, security research, defense and education. - simplex-chat/simplex-chat
SimpleX Chat is a messaging network with apps for iOS, Android and desktop that works without user identifiers of any kind, aiming to keep communication private by design. - HunxByts/GhostTrack
A Python command-line tool for information gathering. Its menus look up information about an IP address, a phone number or a username on social media. - astrid-runtime/book
The canonical reference book for Astrid, built with mdBook, covering the kernel, the capsule model, the host ABI, the bus and the security model. Appendices such as the capability catalog are generated from the Astrid source.
Only repositories in the ranked Trendshift lists are included, and the lists are used only to find candidates. We do not copy their ranks. Descriptions, licenses and star counts come from each GitHub repository. The notes are our own reading. We have not tested these projects, and a place on a trending list does not prove quality.