Anthropic Opens Free AI Security Scanner to Open Source Maintainers
Anthropic is putting an unreviewed automated scanner in front of infrastructure-critical projects and letting maintainer feedback, not its own validation numbers, set the terms for how far it spreads.
Reporting from 1 source: GIGAZINE.
Anthropic opened OSS Scanner, a free vulnerability-finding service that runs its models against open source code with no human review. In initial validation, experts checked 97 findings across 48 projects; 85 met Coordinated Vulnerability Disclosure criteria, 11 were known or duplicate issues, and one was a false positive. PostgreSQL and OpenSSL took part. Maintainers of eligible projects apply by pull request.
Anthropic's OSS Scanner is narrower than its Claude Security product and aimed only at open source projects that carry weight for infrastructure and user security. Acceptance is decided case by case, and a project's key maintainers apply by pull request against the scanner's repository.
Reports can include reproduction steps, a description of the flaw, binary search for when a bug entered the code, and proposed patches. The tradeoff Anthropic names is that no human reviews the scans, so findings can be wrong or not valid.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.