Read as article
Anthropic's OSS Scanner Sends Unreviewed AI Bug Reports
By @sharedot · · 8 pages
- Programming
- Open Source
- Security
- AI
Anthropic launched OSS Scanner, sending open-source maintainers free, fully model-generated vulnerability reports with no human review or triage.
Anthropic ships OSS Scanner for open source
Anthropic on Thursday unveiled OSS Scanner, an opt-in service that gives eligible open-source projects free, periodic security scans from its strongest models, including Claude Mythos. The company says the service is informed by its Project Glasswing vulnerability research, and that outputs are fully model-generated with no human review or triage, enabling faster and more frequent scanning. Each report includes a self-contained reproducer, an explanation of the flaw, when it may have been introduced, and a candidate patch when available. The offering sits under the company's broader Cyber Mission alongside a Critical Infrastructure Defense Program.
The break with convention: no human triage, no forced 90-day clock
What sets OSS Scanner apart from typical vulnerability programs is that findings go straight to maintainers as raw model output — Anthropic says maintainers themselves asked to receive unreviewed issues sooner. If Anthropic later validates a report through its existing coordinated disclosure program, a 90-day period can begin from notification of that human validation, and the company says it may eventually impose disclosure periods on some high-severity reports.
The evidence from a 48-project test
Penetration testers who review Anthropic's disclosures examined 97 critical and high-severity findings across 48 projects from an early version of the scanner: 85 met the company's coordinated disclosure bar, 11 were real but duplicated known issues or other findings, and just one was a false positive — an 88% pass rate reported by multiple outlets including Help Net Security and Incrypted. Anthropic also acknowledges maintainers have flagged inflated severity ratings and misread threat models. According to The Times of India, wolfSSL's Todd Ouska reported that of 74 reports, all but two were valid and five became CVEs.
How maintainers enroll
Core maintainers apply by opening a pull request on the OSS Scanner GitHub repository with a YAML configuration that lists the git repository to clone, a primary contact email, and a Dockerfile that pre-installs dependencies and builds the project so an offline agent can audit it without internet access. Optional fields include CC'd emails, a GPG key for encrypted reports, a threat_model.md file, and a disabled flag to opt out. Anthropic says enrollment follows criteria similar to Google's OSS-Fuzz, targeting established projects with critical impact on infrastructure and user security; Tech My Money reports contact addresses appear in public configuration, so a security alias is recommended.
The stakes: report floods are already overwhelming maintainers
The AI-report deluge is a live pain point — TechRadar reported from the Open Source Summit that IBM expects roughly 66,000 unique vulnerability disclosures in 2026, that curl ended its HackerOne program over poorly researched and AI-generated submissions, and that Linus Torvalds called AI bug hunters' duplicates a problem for the Linux security mailing list. Free scanning can add work before it removes it.
What comes next
Anthropic forecasts that in two years AI will favor defense — catching bugs before they ship and enabling fundamentally secure software — while conceding attackers hold the upper hand until then, according to The Register's coverage of the announcement. The parallel Critical Infrastructure Defense Program pairs Claude models and on-site engineers with partners including CrowdStrike, Palo Alto Networks, Deloitte and Rockwell Automation. Related efforts include a Cyber Verification Program for vetted security professionals and Claude for OSS, which gives free Claude Max 20x subscriptions for fixing vulnerabilities. As of writing, The Hacker News counted 116 pull requests already submitted to the enrollment repository.
Sources
- thehackernews.com › Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects
- timesofindia.indiatimes.com › Anthropic launches free AI-powered security scanner for open-source software projects
- theregister.com › AI company moves to defend critical infrastructure and open-source projects from AI
- techmymoney.com › OSS Scanner: Free Checks for Eligible Open-Source Projects
- helpnetsecurity.com › Anthropic offers free AI security scans to open-source maintainers
- incrypted.com › Anthropic Launches a Free Vulnerability Scanner for Open-Source Software
- techradar.com › In open source cybersecurity, AI is kind of a problem — but it can also be a solution
- the-decoder.com › Anthropic launches a free AI scanner for open-source projects