IT Home, October 9: On October 8 local time, Anthropic announced the official launch of OSS Scanner, an optional vulnerability detection service for open-source software. Open-source projects participating in this initiative will receive comprehensive, regular, and free security scans powered by Anthropic’s most advanced AI models, including Claude Mythos.
Core maintainers of eligible open-source projects can complete their application for integration by submitting a pull request (PR) to the OSS Scanner GitHub repository using the standard project template. The review criteria are similar to Google’s OSS-Fuzz, with priority given to foundational open-source projects that significantly impact critical infrastructure and user security.
According to reports, over the past six months, Anthropic used its latest models to perform vulnerability scans on core software projects worldwide, identifying over 29,000 candidate vulnerabilities. Due to limited human resources, Anthropic was only able to manually review and assess the severity of approximately 6,000 of these vulnerabilities.
Anthropic stated that it will continue to manually submit verified vulnerability reports through the existing Coordinated Vulnerability Disclosure (CVD) process; at the same time, it has established an optional "fast track" for teams wishing to receive details immediately after a vulnerability report is submitted.
IT Home learns that the OSS Scanner results are entirely generated by large models, with no human review or tiered investigation process included. Over the past several weeks, Anthropic has conducted real-world validation of this automated detection process across dozens of open-source projects.
To validate the early version of the OSS Scanner, Anthropic engaged senior penetration testing experts responsible for CVD audits to manually review 97 critical and high-severity vulnerabilities detected by the scanner across 48 projects.
Among these vulnerabilities, 85 (88%) met the criteria for inclusion in the CVD disclosure process. Of the remaining 12 findings, 11 were genuine but constituted known issues or duplicates of other scan results; only one was ultimately classified as an invalid report (false positive).
Anthropic states that the scanner cannot be guaranteed to be absolutely flawless, but it will be continuously refined and optimized based on feedback from maintenance personnel and as the underlying model evolves.
