Anthropic OSS Scanner offers opt-in vulnerability finding
Anthropic ● Covered by 5 sources
Anthropic is offering an opt-in scanner that hunts open-source bugs for free. It uses its strongest models, so maintainers get faster reports — and some may be wrong.
Based on reporting by Anthropic — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Anthropic is opening a new front in open-source security: OSS Scanner, an opt-in service that uses its strongest models to look for vulnerabilities and send the findings to project maintainers at no cost. The pitch is simple. Let the models do the hunting, and let maintainers decide how much of the firehose they want to drink.
The company says this grew out of Project Glasswing, where Claude was used to find bugs in software. Over the last six months, Anthropic says it found more than 29,000 candidate vulnerabilities across some of the world’s most important open-source projects. Human reviewers have only been able to triage about 6,000 of them, which is exactly the bottleneck you’d expect once the machine starts moving faster than the people.
That pressure is pushing a new workflow. Anthropic says it has already sent nearly 5,000 reports directly to maintainers who asked for everything, even the unverified material, because they wanted speed over waiting for full review. The company will still use its existing coordinated vulnerability disclosure process for human-verified findings, especially when projects don’t have the staff to sort through reports themselves. But OSS Scanner is the fast lane: fully model-generated, no human review, and therefore more likely to include false alarms.
Anthropic says it tested the pipeline with dozens of projects over the last several weeks. Those early disclosures included hundreds of bug reports, and the company says some could be chained into unauthenticated remote code execution. It also says each report comes with a self-contained reproducer, an explanation, and sometimes a candidate patch. To back up the system, Anthropic asked outside penetration testers to review 97 critical and high-severity scanner findings across 48 projects; 85 met the company’s bar, 11 were real but duplicates, and one was invalid.
The project is inspired by Google’s OSS-Fuzz, but the delivery is different. Anthropic is betting that open-source maintainers would rather get a fast, possibly messy signal than wait for the perfect one. Core maintainers of eligible projects can apply through a GitHub repo, and Anthropic says it will decide eligibility case by case for software with critical infrastructure and user-security impact.
My take — AI-written commentary, not fact-checked reporting
This is the right kind of AI security product: blunt, useful, and slightly alarming. The industry has spent years pretending bug-finding should be elegant; in practice, it’s often just about getting decent reports in front of tired maintainers before attackers do. The open-source world doesn’t need more applause. It needs fewer excuses and better triage.
Read more about this at: Anthropic
Related stories
Google Open-Sources Mantis: A Modular Skills Toolkit That Lets Coding Agents Find, Reproduce and Patch Vulnerabilities
MarkTechPost · 4 weeks ago ·
51
Cisco Foundation AI Releases Antares: 350M and 1B Open-Weight Models That Localize Known Vulnerabilities Inside Real Codebases
MarkTechPost · 2 months ago ·
25
Anthropic brings Mythos 5 to its Claude Security vulnerability scanner
The New Stack · 1 month ago ·
31