
Anthropic has introduced OSS Scanner, a free service that will look for vulnerabilities in participating open-source projects. The company says reports will be generated by AI without human review.
The opt-in service is designed to scan code regularly. Anthropic said it will use its most capable models, including Claude Mythos.
Reports will not be triaged or reviewed by a person before they are sent. Some findings may therefore be mistaken or invalid, and maintainers will need to assess them themselves.
Anthropic said it tested the system with dozens of open-source projects and sent maintainers hundreds of bug reports. The company said some findings could be chained into unauthenticated remote-code-execution exploits. Each report, it said, includes a reproducer, an explanation of the vulnerability and a possible fix when available.
Maintainers of eligible projects can apply by submitting a pull request to the program’s repository. Anthropic said the service is intended for projects able to handle the findings independently. It also warned that reports may contain inaccuracies, including inflated severity ratings.