AI News Feed
Market watch
Products & Applications

Anthropic Offers Free OSS Scanner for Open-Source Vulnerabilities

Anthropic offers free vulnerability scans to open-source projects via OSS Scanner, using AI reports without human review.

Anthropic described the service as opt-in. "Projects that join will receive thorough, periodic security scans by our strongest models at no cost," the company announced, according to Engadget. The company said outputs from the scanner will be fully model-generated, without human review or triage. That design is meant to allow faster and more frequent scanning, but Anthropic acknowledged that reports may be incorrect or invalid. The reports will be produced by its strongest models, including Claude Mythos, to give open-source projects what it called the largest defensive advantage.

Anthropic said it was inspired by OSS-Fuzz, a scanner created by Google and the Open Source Security Foundation. OSS-Fuzz has been available since 2016. Anthropic already has a paid product, Claude Security, that can perform general-access code scanning and patching. OSS Scanner performs similar security audits at no cost, according to Engadget.

Engadget reported that Google and Anthropic are not necessarily offering these products out of altruism. Both companies rely heavily on open-source code projects that underpin the internet, often run by unpaid workers. Security vulnerabilities in that code are highly dangerous. The report cited the XZ Utils backdoor as a recent example, saying it could have handed hackers administrative control over millions of systems around the world.

Engadget noted that AI models have recently demonstrated that they are excellent at finding and exploiting vulnerabilities. The new scanner could give open-source coders early alerts about potential security issues for free. The tradeoff is that its reports will not be reviewed by humans, so the information may need independent verification.