I use models for static analysis everyday. You have to give them targeted prompts and use “traditional sast” to pinpoint the code to ~10KBs of hotspots to get good results. Granted a small code base in my scope is 100MBs of code so YMMV. I am still long tree-sitter.
Introducing Claude Code Security, now in limited research preview. It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss. Learn more: anthropic.com/news/claude-co…

Feb 21, 2026 · 12:47 AM UTC

4
1
34
4,844
Sort replies: Relevant Recent Liked
Replying to @CryptoGangsta
Loved your blog posts

ALT Excited Lets Go GIF

1
1
275
Replying to @CryptoGangsta
Yeah I’ve had the most results from combining traditional tooling with AI instead of only using AI.
1
186