Close Menu
NCIJ Network |NCIJ Network |
    What's Hot

    If you’ve heard online that London is dystopian and dangerous – read this. It just isn’t | Sadiq Khan

    July 23, 2026

    Modi vows ‘stringent punishment’ for exam fraud fuelling India’s youth-led ‘Cockroach’ protests

    July 23, 2026

    Stühlerücken in der Union: Wer folgt auf Thorsten Frei? – POLITICO

    July 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • If you’ve heard online that London is dystopian and dangerous – read this. It just isn’t | Sadiq Khan
    • Modi vows ‘stringent punishment’ for exam fraud fuelling India’s youth-led ‘Cockroach’ protests
    • Stühlerücken in der Union: Wer folgt auf Thorsten Frei? – POLITICO
    • Ann Widdecombe: Family announces public memorial later this year
    • Business rates to be cut by 20% for pubs, clubs and music venues in England | Business rates
    • ServiceNow bets $40 million on Indian banking software specialist to expand its financial services push
    • Anthropic Releases Claude Security Plugin for Claude Code in Beta: A Multi-Agent Vulnerability Scanner That Runs in Your Terminal
    • Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network |NCIJ Network |
    Thursday, July 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network |NCIJ Network |
    Home»Artificial Intelligence

    Anthropic Releases Claude Security Plugin for Claude Code in Beta: A Multi-Agent Vulnerability Scanner That Runs in Your Terminal

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 23, 2026 Artificial Intelligence No Comments8 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Anthropic has released the Claude Security plugin for Claude Code in beta. The plugin runs a multi-agent vulnerability scan of a repository from inside an existing Claude Code session, then turns the findings you select into patch files that you review and apply yourself. Anthropic emphasized the tool’s versatility upon announcement, highlighting its capability to either run a comprehensive scan across the full codebase or inspect changes from the terminal right before a commit.

    What plugin adds

    The plugin adds a single command, /claude-security, which opens a menu of three jobs, per the official documentation:

    • Scan codebase — the whole repository or a scoped subset of it
    • Scan changes — a branch’s diff, a pull request’s diff, or a single commit
    • Suggest patches — turn a report’s findings into .patch files

    Installation is two commands from the official Anthropic marketplace:

    /plugin install claude-security@claude-plugins-official
    /reload-plugins

    If the marketplace is not found, run /plugin marketplace add anthropics/claude-plugins-official first. The plugin source is public in the claude-plugins-official repository, currently at version 0.10.0.

    How the scan pipeline is structured

    The scan is implemented as a dynamic workflow — a JavaScript orchestration script that fans work out across subagents. The script declares six phases:

    1. Inventory: partition the repository into components. Every top-level directory must be either scanned or explicitly skipped with a reason.
    2. Threat model: one modeler per component, producing entry points, sinks, trust boundaries, and files a researcher must read in full.
    3. Research: one researcher per component × category cell.
    4. Sweep: gap-fill over what the matrix did not cover.
    5. Panel: three-lens adversarial verification, one voter per lens.
    6. Adversarial: max effort only: re-panel marginal keeps, then red-team every survivor.

    Research runs against four fixed categories: injection-and-input, auth-and-access, memory-and-unsafe, and crypto-and-secrets. The memory-and-unsafe lens is dropped for components written entirely in memory-safe languages, so a pure Python or TypeScript component gets three lenses instead of four.

    The operational scale of a run is dictated by four distinct effort tiers: low, medium, high, and max. Depending on the selected tier, specific thresholds are enforced: the maximum number of components is capped at 12 for low and medium tiers, expanding to 24 for high and max tiers; matrix cells are assigned 1 researcher, which increases to 2 at the high and max levels; and the number of gap-fill sweeps scales from 0 at low, to 1 at medium, up to 2 for high and max. When dealing with a limited scope or a small diff, the process condenses into a single-researcher configuration instead of deploying the entire matrix. This ensures the evaluation remains strictly proportionate to the target while maintaining the identical verification standard.

    The system employs model-tiered agents: the orchestrator runs on Opus, while the repository cartographer and read-only code explorer run on Sonnet. Furthermore, the session model is inherited by researchers and verifiers, and scan agents are restricted exclusively to read-only tools.

    How a finding earns its place in the report

    This is the part worth understanding closely. A candidate finding does not go into the report because a researcher found it. It goes in only after surviving a panel.

    Each candidate is handed to three independent verifiers, one per lens: REACHABILITY, IMPACT, and DEFENSES. Each returns a structured verdict of TRUE_POSITIVE or FALSE_POSITIVE with one or two lines naming the decisive file:line. The keep quorum is 2 of 3. If fewer than three voters return, the candidate is not keepable at all.

    The panel result also caps the finding’s stated confidence. A unanimous 3/3 panel allows a confidence ceiling of high; a 2/3 quorum caps it at medium. A finding cannot claim more confidence than its verification earned.

    Critically, the tally is computed in Python by the report renderer, not asserted by the model that produced the findings. The revision stamp’s verification.status is set to verified only when the vote record proves the panel ran for every finding in the report; otherwise it is unverified with a stated reason. That makes the report’s own account of its rigor something you can check rather than something you take on trust.

    Anthropic Beta Claude Code MultiAgent Plugin Releases Runs Scanner Security Terminal Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Validating Distributed LLM Serving Benchmarks with NVIDIA srt-slurm, SLURM Recipes, Parameter Sweeps, and Pareto Analysis

    Cursor Releases Cursor Router: A Request-Level Classifier Delivering Frontier Coding Quality at 30–50% Lower Cost

    AI, security operations and the new race against time

    Research-Grade EdgeBench Analysis: AI Agent Benchmarking, Leaderboard Analytics, Scaling Laws, and Evaluation Metrics

    Google Releases Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber: A Cheaper, More Token-Efficient Flash Tier Built for Agentic Workloads

    Poolside Releases Laguna S 2.1, an Open-Weight Agentic Coding Model Punching Above Its Weight Class on SWE-Bench Multilingual

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    If you’ve heard online that London is dystopian and dangerous – read this. It just isn’t | Sadiq Khan

    July 23, 2026

    Modi vows ‘stringent punishment’ for exam fraud fuelling India’s youth-led ‘Cockroach’ protests

    July 23, 2026

    Stühlerücken in der Union: Wer folgt auf Thorsten Frei? – POLITICO

    July 23, 2026

    Ann Widdecombe: Family announces public memorial later this year

    July 23, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    If you’ve heard online that London is dystopian and dangerous – read this. It just isn’t | Sadiq Khan

    July 23, 2026

    Modi vows ‘stringent punishment’ for exam fraud fuelling India’s youth-led ‘Cockroach’ protests

    July 23, 2026

    Stühlerücken in der Union: Wer folgt auf Thorsten Frei? – POLITICO

    July 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.