Anthropic Debuts Free AI Security Scanning for Open-Source Software

AI-generated image · US National Wire
The company is offering automated vulnerability reports via its OSS Scanner, though the lack of human oversight raises concerns about accuracy.
Anthropic has launched a new service called OSS Scanner designed to help open-source projects identify security vulnerabilities. According to reporting from The Verge, projects that opt into the service will receive periodic security scans at no cost, powered by the company's most capable models, including Claude Mythos.
While the service aims to provide a defensive advantage by alerting projects to security flaws more quickly, the reports are entirely model-generated. The Verge notes that because there is no human review or triage involved in the process, the resulting reports may be invalid or incorrect.
This move comes as AI-driven bug hunting becomes more prevalent. The Verge highlights that AI tools were instrumental in identifying the "Copy Fail" bug that affected nearly every Linux distribution in May. However, the surge in automated reporting has created challenges for some developers; The Verge reports that Google and Linus Torvalds have struggled to manage the high volume of AI-generated bug reports.

