2 min read
Add as a preferred source on Google

Anthropic Opens Free AI Vulnerability Scanner for Open-Source Projects

OSS Scanner uses Claude Mythos and other advanced models to produce periodic reports without human review, leaving maintainers responsible for validating and triaging the findings.

Magnifying glass over an exposed circuit board in morning light / TokenPost.ai
Magnifying glass over an exposed circuit board in morning light / TokenPost.ai

Anthropic launched OSS Scanner, a free, opt-in vulnerability scanner for eligible open-source projects, on Oct. 8, using advanced Claude models to speed access to security findings in software that supports infrastructure and users.

OSS Scanner generates periodic reports without prior human review or triage. Reports may contain an explanation of the vulnerability, a reproducer and a proposed patch when available, while maintainers remain responsible for validating and triaging the findings.

“The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage,” Anthropic said.

The service grew out of Project Glasswing, Anthropic’s effort to use Claude models to identify vulnerabilities in important software. The approach is designed to reduce delays from manual validation and give capable maintainers faster access to raw findings.

Its models identified more than 29,000 candidate vulnerabilities during the six months before the service’s launch. About 6,000 had undergone manual review, while nearly 5,000 unverified reports were sent directly to maintainers who requested all available findings.

The company also described testing involving 97 critical- or high-severity findings across 48 projects. Penetration testers determined that 85 findings, or 88%, met Anthropic’s standard for coordinated vulnerability disclosure. Of the other 12 findings, 11 were genuine but duplicated known issues or other scanner findings, while one was invalid.

“We can’t guarantee the scanner will be perfect,” Anthropic said.

Projects apply primarily by submitting a pull request that adds a configuration file to the OSS Scanner repository. Anthropic reviews applications individually and targets projects with a “critical impact on infrastructure and user security.”

OSS Scanner is separate from Claude Security, Anthropic’s commercial code-scanning and patching product for enterprises. Projects that cannot triage unreviewed findings will continue receiving human-verified disclosures through Anthropic’s coordinated-vulnerability-disclosure process.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…