Anthropic is bragging that while its Claude Code Security can sniff out vulnerabilities, but it is looking like the dull bit of proving them and fixing them still trips everyone up.
To put numbers on the hype, Anthropic pointed to its red team using Claude Opus 4.6 to find “over 500 vulnerabilities in production open-source codebases.”
That sounds punchy until you ask how many of those reports turned into something maintainers could ship.
Stealth startup, founder Guy Azari pointed out that “Out of the 500 vulnerabilities that Anthropic reported, only two to three vulnerabilities were fixed. If they haven’t fixed them, it means that you haven’t done anything right.”
Azari flagged the lack of Common Vulnerabilities and Exposures assignments as a sign that the process is stuck in the halfway house between “interesting” and “actionable”. He said security teams have never been short of reports, but AI just finds more.
Azari said: “We used to get the reports all day long. When AI was introduced, it just multiplied by 100x or 200x and added a lot of noise because AI assumes these are vulnerabilities, but there wasn’t a unit that could actually show the real value or impact. And if it’s not there, you’re probably not gonna fix it.”
He claimed that in 2025 the National Vulnerability Database had a backlog of roughly 30,000 CVE entries waiting for analysis, with nearly two-thirds missing a severity score. Open-source maintainers are already drowning, and Azari pointed out that curl shut down its bug bounty to deter ropey reports.
Azari said: “The maintainers of curl closed their programme two months ago or something like that because they just got too many false positives and they couldn’t deal with the load. So, potentially, what Claude did was not helpful, as it brought them more issues. But these issues are not validated; they are not concrete. It’s not a fix. It’s more like magnifying the collapse.”







