AI

Anthropic launches OSS Scanner for open-source security

The free service scans opted-in open-source projects using Anthropic's strongest models, but reports are model-generated with no human review.

Anthropic has launched OSS Scanner, a free service that provides periodic security vulnerability scans for open-source projects that opt in, according to The Verge.

The company said the scans are generated by its strongest models, including Mythos. Projects must sign up to receive the reports.

Anthropic cautioned that the reports are fully model-generated, without human review or triage. As a result, the findings could be incorrect or invalid.

The launch comes as maintainers of some open-source projects, including work involving Linus Torvalds and Google, have struggled to keep up with a surge in AI-generated bug reports. In May, the "Copy Fail" bug affected nearly every Linux distribution after being discovered with the help of AI tools.

Quick answers

What is Anthropic's OSS Scanner?

It is a free service that runs periodic security vulnerability scans on open-source projects that opt in, with reports generated by Anthropic's models.

Are the OSS Scanner reports reviewed by humans?

No. Anthropic said the reports are fully model-generated without human review or triage, so they could be incorrect or invalid.

Which models generate the scans?

Anthropic said the scans are produced by its strongest models, including Mythos.

Source