Back
Anthropic Launches Free OSS Scanner for Finding Open-Source Vulnerabilities
SiTech AI Team2 min read

Anthropic Launches Free OSS Scanner for Finding Open-Source Vulnerabilities

Anthropic has introduced OSS Scanner, a free opt-in service that uses its strongest AI models, including Claude Mythos, to find security vulnerabilities in open-source software. Reports are fully model-generated with no human review.

Free AI Security Scans for Open-Source Projects

Anthropic has launched OSS Scanner, a free vulnerability-finding service for open-source software projects. Projects that sign up will receive thorough, periodic security scans powered by the company's strongest AI models at no cost, according to the company's announcement. The tool is designed to give open-source developers early warnings about potential security issues in their code.

Model-Generated Reports Without Human Review

Anthropic was transparent about the tradeoff. The outputs of the opt-in scanner will be fully model-generated, with no human review or triage. The company said this approach enables faster and more frequent scanning, but acknowledged that reports may be incorrect or invalid. Reports will be produced by Anthropic's strongest models, including Claude Mythos, which the company says gives open-source projects the largest defensive advantage available.

Built on Existing Efforts

Anthropic said the effort was inspired by OSS-Fuzz, the open-source software scanner created by Google and the OpenSSF, the Open Source Security Foundation, which has been available since 2016. The company also offers a paid product called Claude Security that can perform general-access code scanning and patching, while OSS Scanner delivers similar security audits at no cost.

Why It Matters

Google and Anthropic are not providing these tools purely out of altruism. Both companies rely heavily on open-source code projects that underpin much of the internet, and these projects are frequently maintained by unpaid volunteers. Vulnerabilities in such code can be extremely dangerous. A recent example is the XZ Utils backdoor, which could have given hackers administrative control over millions of systems around the world.

Sources: Engadget · The Decoder

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.