ANTHROPIC LAUNCHES FREE AI SECURITY SCANS FOR OPEN SOURCE CODE
Anthropic has launched a free service called OSS Scanner, offering open-source software projects periodic security scans aimed at finding vulnerabilities. The company said projects that opt in "will receive thorough, periodic security scans by our strongest models at no cost," including a model it calls Claude Mythos. Anthropic said the reports generated by the scanner are "fully model-generated, without human review or triage," which it said allows for faster and more frequent scanning but also means some reports may be incorrect or invalid. The company said the aim is to give open-source projects "the largest defensive advantage" against security flaws. Anthropic already sells a separate paid product, Claude Security, which performs broader code scanning and patching, but said OSS Scanner carries out similar audits free of charge.
Anthropic said OSS Scanner was inspired by OSS-Fuzz, an open-source scanning tool built by Google and the Open Source Security Foundation that has been available since 2016. Both reports noted that AI tools have already been credited with uncovering significant vulnerabilities in open-source software in recent months, citing a flaw known as "Copy Fail" that affected nearly every Linux distribution in May. One report noted that major open-source projects, including those overseen by Linus Torvalds and by Google, have struggled to keep pace with a rise in AI-generated bug reports. The reports also pointed to past incidents such as the XZ Utils backdoor as examples of the risks posed by vulnerabilities in widely used open-source code.
Anthropic and Google both rely heavily on open-source software that underpins much of the internet, much of it maintained by unpaid contributors, which one report said gives both companies a commercial interest in strengthening its security alongside any broader public benefit. Anthropic has not said how many projects have joined OSS Scanner so far or set out further plans for the service.