vuln-scan
anthropics/defending-code-reference-harnessStatic source-code vulnerability scan. Reads a target directory (and THREAT_MODEL.md if present), spawns parallel review subagents per focus area, and writes…
Scores out of 100 · grade A
2026-08-22Works
40% of the score86/100
- Names 6 tools Claude Code does not ship: [object Object], [object Object], [object Object], [object Object].
Maintained
25% of the score86/100
- no commits in the last 12 weeks
- no license file
Adopted
20% of the score53/100
- 946 installs on skills.sh.
- 7,339 stars on the source repo.
Documented
15% of the score81/100
- 1,584 words with worked examples.
Install
npx skills add anthropics/defending-code-reference-harness/vuln-scanWhat the check found
| Finding | What it means |
|---|---|
| Unknown tools | It allow-lists tool names Claude Code does not ship, which usually means a typo. |
| No license | The repository ships no license file, so the reuse terms are unclear. |
What it says it does
Static source-code vulnerability scan. Reads a target directory (and THREAT_MODEL.md if present), spawns parallel review subagents per focus area, and writes VULN-FINDINGS.json + .md for /triage to consume. Read-only — no building, running, or network. For execution-verified crashes, use vuln-pipeline instead. Use when asked to "scan for vulns", "review this code for security issues", "find bugs in <dir>", or as the step between /threat-model and /triage.
Also in anthropics/defending-code-reference-harness
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| customizeanthropics/defending-code-reference-harness | No license | Skill | 917 installs | 15 days ago | |
| quickstartanthropics/defending-code-reference-harness | No license | Skill | 917 installs | 15 days ago | |
| verifyanthropics/defending-code-reference-harness | No license | Skill | 7.3k stars | 15 days ago | |
| threat-modelanthropics/defending-code-reference-harness | Unknown tools | Skill | 959 installs | 15 days ago | |
| dnr-huntanthropics/defending-code-reference-harness | Broken frontmatter | Skill | 7.3k stars | 15 days ago | |
| dnr-respondanthropics/defending-code-reference-harness | Broken frontmatter | Skill | 7.3k stars | 15 days ago |
Other security skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| release-openclaw-ciopenclaw/openclaw | No license | Security | 387k stars | today | |
| site-architecturecoreyhaines31/marketingskills | clean | Security | 94,902 installs | today | |
| cookbook-auditanthropics/claude-cookbooks | clean | Security | 52k stars | 2 days ago | |
| asocoreyhaines31/marketingskills | clean | Security | 46,665 installs | today | |
| openclaw-secret-scanning-maintaineropenclaw/openclaw | No license | Security | 387k stars | today | |
| graph-evolutiontrailofbits/skills | clean | Security | 2,860 installs | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=anthropics%2Fdefending-code-reference-harness)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
