Vulnerability scanning and patch generation with researcher agents and adversarial validation
The vulnerability detection and patching capabilities behind Claude Security, packaged for Claude Code. Scans run inside your session on your machine, against any repository you can clone.
Scan Codebase maps your repository's architecture, threat-models every component, fans research agents across the code, and verifies what they find. Each finding comes back with a severity, a CWE category, potential impact, reproduction steps, and a suggested path to remediation.
How it works: Install the plugin, run /claude-security, and choose an option.
In beta. Scans use the Claude access you already have. Learn more here.