Anthropic launches free, opt-in OSS Scanner for open-source vulnerability scans with no human review
Overview
Anthropic has launched OSS Scanner, a free, opt-in service in which its strongest models, including Claude Mythos, periodically scan enrolled open-source projects for security vulnerabilities. Core maintainers of eligible projects can enroll by submitting a pull request to the company's GitHub repository. Eligibility mirrors OSS-Fuzz's criteria, requiring a "critical impact on infrastructure and user security," decided case by case. Anthropic says the reports are fully model-generated, with no human review or triage. The company says this allows faster and more frequent scanning, but that some reports may be incorrect or invalid. Each report is said to include a proof-of-concept, an explanation, and a suggested fix. In a pilot, 85 of 97 checked critical and high-severity findings met Anthropic's disclosure bar, according to the company's own report.
AI-generated from articles · Updated 8m ago
Article timeline
Follow the coverage from different perspectives.
- The Verge · AIAnthropic launches free OSS Scanner for open-source security vulnerability reports
Anthropic has launched OSS Scanner, a free opt-in service that gives open-source projects periodic security scans by its strongest models, including Claude Mythos. The reports are fully model-generated without human review or triage, so they may be incorrect or invalid.
- AnthropicAnthropic launches OSS Scanner to find open-source software vulnerabilities
Anthropic is launching OSS Scanner, a service that uses its frontier models to periodically scan opted-in open-source projects for vulnerabilities at no cost. Its reports provide a proof-of-concept, an explanation, and a suggested fix.
- Anthropic ResearchAnthropic launches OSS Scanner, a free AI vulnerability scanner for open-source projects
Anthropic is launching OSS Scanner, an opt-in service that runs periodic security scans of enrolled open-source projects using its strongest models at no cost. Its outputs are fully model-generated without human review, so some reports may be incorrect or invalid, though a pilot found 85 of 97 checked critical and high-severity findings met Anthropic's disclosure bar. Core maintainers of eligible projects can enroll through a GitHub pull request.
- Anthropic NewsroomPickAnthropic launches Cyber Mission with infrastructure defense and free OSS Scanner
Anthropic has launched the Anthropic Cyber Mission, which starts with the Critical Infrastructure Defense Program for operational technology and OSS Scanner for open-source projects. The defense program brings frontier Claude models, on-site engineers and threat research to trusted providers such as Accenture, CrowdStrike and Palo Alto Networks. OSS Scanner gives enrolled open-source projects periodic free scans from its strongest models, with reports sent without human review and an expected true-positive rate above 90%.
Heat trend
Not enough continuous observations to show a trend yet.