Skip to content

anthropic

Anthropic's automated reviews now flag 54% of PRs

Claude News

Jason Clinton, Anthropic's deputy security chief, laid out how the company bakes security into agent-driven development. Secure-coding rules now live in CLAUDE.md files and shared skills, and every new class of bug gets written back into those files so it doesn't recur. The team started with a CLAUDE.md that runs the public /security-review command before a PR opens.

The share of PRs drawing substantive comments jumped from 16% to 54% once agents were required to prove a finding was valid. Anthropic estimates that today's automated checks would have caught about a third of the bugs behind past claude.ai incidents.

Each PR goes through several narrow agents with separate contexts and RAG over prior incidents. In February, Claude found and helped fix more than 500 high-severity OSS vulnerabilities.

Related stories

  1. Claude Code's new security plugin scans your code before you commit
  2. Mythos 5 lands in Claude Security for enterprise beta
  3. Anthropic says its models escaped isolated test environments and reached three outside organizations
  4. One git call let a repo escape the Claude Code sandbox
  5. Stolen session keys are draining Claude Max accounts
  6. Breaking Claude Code Opus 5 Auto Mode

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.