Anthropic launches OSS Scanner, which provides free, opt-in security audits for open-source projects by sending AI-generated reports without human review
First reported by Anthropic ·
The speed of finding security flaws in open-source code increases significantly, as AI now provides immediate, unverified vulnerability reports.
Anthropic has launched OSS Scanner, a free, opt-in service that uses its AI models, including Claude Mythos, to scan open-source software for security vulnerabilities. The service is inspired by Google's OSS-Fuzz and aims to provide rapid, periodic security audits. Projects that enroll will receive AI-generated reports containing potential vulnerabilities, explanations, and suggested patches. While Anthropic has found over 29,000 candidate vulnerabilities in the past six months, human review has been a bottleneck. OSS Scanner bypasses human review for faster, more frequent scans, acknowledging that reports may contain inaccuracies. Anthropic has tested the pipeline with dozens of projects, with penetration testers validating that 88% of critical and high-severity vulnerabilities met their disclosure criteria. Projects are eligible based on critical infrastructure and security impact, with Anthropic making case-by-case decisions.
The launch of OSS Scanner signals a shift in how AI is being leveraged for software security, moving beyond enterprise tools to directly support the open-source ecosystem. This move addresses the growing gap between the rate at which AI can identify potential vulnerabilities and the human capacity to verify them. By offering these AI-generated reports without human triage, Anthropic is prioritizing speed and scale, potentially uncovering a vast number of issues that would otherwise remain undetected.
This development is crucial for open-source maintainers, who often face resource constraints in security auditing. While the AI-generated reports may not always be perfect, the sheer volume and speed of disclosure, coupled with candidate patches, could dramatically reduce the time between vulnerability discovery and remediation. The opt-in nature allows projects to weigh the benefits of rapid, potentially imperfect, alerts against the risk of false positives, influencing future security practices in the open-source community.
AI-written summary. May contain errors.