defending-code-reference-harness
Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize
Defending Code Reference Harness is a set of Claude Code skills and autonomous pipeline tools for AI-powered vulnerability discovery, threat modeling, and security patching. Built from Anthropic's work with enterprise security teams, it provides interactive skills for threat modeling, scanning, triaging findings, and generating patches, plus reference implementations of autonomous scanning pipelines for C/C++ memory vulnerabilities and detection-and-response workflows. Developers can use the skills interactively in Claude Code or run fully autonomous scans with verification, deduplication, and patch generation.
Key Features
Use Cases
- 01Running interactive threat modeling and static vulnerability scans on application source code
- 02Autonomously discovering memory safety bugs in C/C++ libraries with execution-verified proof of concepts
- 03Triaging and deduplicating security findings across multiple scan runs against a threat model
- 04Generating and validating security patches with automated testing and fix verification
- 05Hunting attacker activity and scoping incident blast radius in application logs
- 06Customizing the scanning pipeline for different programming languages or vulnerability classes like SQL injection or XSS
Related Skills
View moresuperpowers
An agentic skills framework & software development methodology that works.
skills
Skills for Real Engineers. Straight from my .agents directory.
skills
Public repository for Agent Skills
ponytail
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
defending-code-reference-harness — FAQ
What is Defending Code Reference Harness?+
It's a collection of Claude Code skills and autonomous pipeline tools for AI-powered vulnerability discovery, threat modeling, and security remediation in source code. It includes both interactive skills you run step-by-step in Claude Code and fully autonomous scanning harnesses that execute complete security workflows.
How do I install and run the skills in Claude Code?+
Clone the repository, open it in Claude Code, and run /quickstart to get oriented. The interactive skills (/threat-model, /vuln-scan, /triage, /patch) are immediately available and only read/write files, so they're safe to run without sandboxing as long as you approve each tool use.
What are the prerequisites for autonomous scanning?+
You need Python 3, Docker, and an Anthropic API key (or access via Bedrock, Vertex, or Azure). Run the one-time setup script to install gVisor and build agent sandbox images. Autonomous pipelines require sandboxing because they execute target code.
Which AI clients does this work with?+
The interactive skills work with Claude Code. The autonomous pipelines use the Claude API directly (via Anthropic, Bedrock, Vertex, or Azure) and can be configured to use different Claude models via the --model flag.
Is this free to use?+
The reference harness code is open source, but you'll need access to Claude API credits. Anthropic also offers Claude Security as a managed commercial product for teams that prefer a hosted solution.
Can I customize this for languages other than C/C++?+
Yes, use the /customize skill to port the pipeline to your language and vulnerability class. You'll define what signals a finding (exceptions, DNS callbacks, etc.), what a proof of concept looks like, and how to build and run your target in a container.
How do I install defending-code-reference-harness?+
Open the source repository on GitHub and follow its README. defending-code-reference-harness is a skill — MCP Agents Market links you directly to the official repo.
Is defending-code-reference-harness free?+
defending-code-reference-harness is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.