TLDRocket
Sign in

Anthropic OSS Scanner offers opt-in vulnerability finding

Anthropic ● Covered by 5 sources

Anthropic is offering an opt-in scanner that hunts open-source bugs for free. It uses its strongest models, so maintainers get faster reports — and some may be wrong.

Based on reporting by Anthropic — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Anthropic is opening a new front in open-source security: OSS Scanner, an opt-in service that uses its strongest models to look for vulnerabilities and send the findings to project maintainers at no cost. The pitch is simple. Let the models do the hunting, and let maintainers decide how much of the firehose they want to drink.

The company says this grew out of Project Glasswing, where Claude was used to find bugs in software. Over the last six months, Anthropic says it found more than 29,000 candidate vulnerabilities across some of the world’s most important open-source projects. Human reviewers have only been able to triage about 6,000 of them, which is exactly the bottleneck you’d expect once the machine starts moving faster than the people.

That pressure is pushing a new workflow. Anthropic says it has already sent nearly 5,000 reports directly to maintainers who asked for everything, even the unverified material, because they wanted speed over waiting for full review. The company will still use its existing coordinated vulnerability disclosure process for human-verified findings, especially when projects don’t have the staff to sort through reports themselves. But OSS Scanner is the fast lane: fully model-generated, no human review, and therefore more likely to include false alarms.

Anthropic says it tested the pipeline with dozens of projects over the last several weeks. Those early disclosures included hundreds of bug reports, and the company says some could be chained into unauthenticated remote code execution. It also says each report comes with a self-contained reproducer, an explanation, and sometimes a candidate patch. To back up the system, Anthropic asked outside penetration testers to review 97 critical and high-severity scanner findings across 48 projects; 85 met the company’s bar, 11 were real but duplicates, and one was invalid.

The project is inspired by Google’s OSS-Fuzz, but the delivery is different. Anthropic is betting that open-source maintainers would rather get a fast, possibly messy signal than wait for the perfect one. Core maintainers of eligible projects can apply through a GitHub repo, and Anthropic says it will decide eligibility case by case for software with critical infrastructure and user-security impact.

My take — AI-written commentary, not fact-checked reporting

This is the right kind of AI security product: blunt, useful, and slightly alarming. The industry has spent years pretending bug-finding should be elegant; in practice, it’s often just about getting decent reports in front of tired maintainers before attackers do. The open-source world doesn’t need more applause. It needs fewer excuses and better triage.

Read more about this at: Anthropic

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.