Anthropic Launches OSS Scanner to Provide Free AI-Powered Vulnerability Detection for Open Source Software

icon币界网
Share
AI summary iconSummary
Anthropic has launched OSS Scanner, a free AI-powered tool for detecting open source vulnerabilities. The service uses models such as Claude and Mythos to scan eligible projects. Developers can apply via a GitHub pull request. Over 29,000 potential issues were identified within six months, with 6,000 manually reviewed. The tool automatically generates results, and 88% of high-severity issues met disclosure criteria. This initiative aligns with the growing trend of AI integration in cryptocurrency news.
CoinDesk reports:

IT Home, October 9: On October 8 local time, Anthropic announced the official launch of OSS Scanner, an optional vulnerability detection service for open-source software. Open-source projects participating in this initiative will receive comprehensive, regular, and free security scans powered by Anthropic’s most advanced AI models, including Claude Mythos.

Core maintainers of eligible open-source projects can complete their application for integration by submitting a pull request (PR) to the OSS Scanner GitHub repository using the standard project template. The review criteria are similar to Google’s OSS-Fuzz, with priority given to foundational open-source projects that significantly impact critical infrastructure and user security.

According to reports, over the past six months, Anthropic used its latest models to perform vulnerability scans on core software projects worldwide, identifying over 29,000 candidate vulnerabilities. Due to limited human resources, Anthropic was only able to manually review and assess the severity of approximately 6,000 of these vulnerabilities.

Anthropic stated that it will continue to manually submit verified vulnerability reports through the existing Coordinated Vulnerability Disclosure (CVD) process; at the same time, it has established an optional "fast track" for teams wishing to receive details immediately after a vulnerability report is submitted.

IT Home learns that the OSS Scanner results are entirely generated by large models, with no human review or tiered investigation process included. Over the past several weeks, Anthropic has conducted real-world validation of this automated detection process across dozens of open-source projects.

To validate the early version of the OSS Scanner, Anthropic engaged senior penetration testing experts responsible for CVD audits to manually review 97 critical and high-severity vulnerabilities detected by the scanner across 48 projects.

Among these vulnerabilities, 85 (88%) met the criteria for inclusion in the CVD disclosure process. Of the remaining 12 findings, 11 were genuine but constituted known issues or duplicates of other scan results; only one was ultimately classified as an invalid report (false positive).

Anthropic states that the scanner cannot be guaranteed to be absolutely flawless, but it will be continuously refined and optimized based on feedback from maintenance personnel and as the underlying model evolves.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.