Anthropic opens free AI vulnerability scans to open-source projects
Maintainers can opt in to periodic model-generated security reports, but the findings arrive without human review.
Security findings without a review queue
Anthropic launched OSS Scanner on October 8, offering open-source projects free, periodic vulnerability scans using its strongest models. Maintainers must opt in. The company says each report can include a proof of concept, an explanation of the flaw and a proposed fix when one is available. Reports are sent without human review, a deliberate way to deliver findings faster than Anthropic’s existing coordinated-disclosure process. The company says that process will continue for projects that lack the capacity to triage a stream of raw model findings.
A useful tool with a triage cost
Anthropic says its earlier Project Glasswing work produced more candidate vulnerabilities than its staff could manually validate. OSS Scanner shifts some of that review work to participating maintainers. The company expects a high true-positive rate, but warns that reports may contain inaccurate findings or severity ratings; its expectation is not an independent measurement of the new service in general use. The scanner is one part of the newly announced Anthropic Cyber Mission, which also begins a separate program pairing models and engineers with critical-infrastructure defenders. Neither launch establishes that software or infrastructure is now secure by default.