Skip to content
Brief Security & Trust ·

Anthropic opens free, unreviewed AI bug scanner to eligible open-source projects

OSS Scanner is opt-in, and Anthropic's models write its reports with no human review.

In brief
  • Anthropic launched OSS Scanner, a free, opt-in service for eligible open-source projects. Its reports come with a reproducer and often a patch, but no human review.
  • Anthropic found over 29,000 possible flaws and reviewed about 6,000 by hand. Checking reports is now the slow step.

Anthropic said it is launching OSS Scanner, a free, opt-in service that scans open-source code for security flaws. Eligible projects can enrol, judged case by case on OSS-Fuzz-style criteria, such as critical impact on infrastructure and user security. Google's OSS-Fuzz feeds code odd inputs to trigger crashes. Anthropic said each OSS Scanner report adds a reproducer (a test that triggers the flaw), an explanation, and a patch when available. Some findings chained into remote code execution without a login. The Verge covered the launch on 8 October.

Anthropic said it found over 29,000 possible flaws in six months but reviewed only about 6,000 by hand. Scanner reports get no human review, so some may be wrong. In an early test, 85 of 97 critical and high-severity findings met Anthropic's bar. Eleven were real but repeated known issues, and one was invalid. The sources do not say how many projects have joined or how often scans will run.

Finding bugs is no longer the slow step; checking them is. Anton Arapov of OpenSSL Corporation said a report with a real exploit can be verified right away. Ask your key open-source suppliers: do they take part, who checks the reports, and how fast do they ship patches?

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Anthropic.