Artificial intelligence company Anthropic officially announced the launch of a new optional vulnerability detection service called OSS Scanner on October 8th local time. This project aims to provide comprehensive, regular free security scans for global open source software using Anthropic's most powerful AI models, including Claude Mythos.
For application access, core maintainers of eligible foundational open source projects can simply submit a pull request (PR) to the OSS Scanner GitHub repository following a standard project template to complete the application. The overall review criteria are similar to Google's OSS-Fuzz, mainly targeting core open source projects that have significant impact on critical infrastructure and user safety.
Looking back at previous technical explorations, over the past six months, Anthropic has used the latest models to scan core software projects around the world, identifying more than 29,000 candidate vulnerabilities. However, due to limited human resources, only about 6,000 of these vulnerabilities have been manually reviewed and assessed so far.
Regarding the disclosure mechanism, Anthropic stated that it will continue to use its existing coordinated vulnerability disclosure (CVD) process to manually submit verified vulnerability reports; meanwhile, it also provides an optional "fast track" for teams wishing to obtain details immediately after the vulnerability report is generated.
According to the official introduction, the scan results of OSS Scanner are entirely generated by large models and do not include any manual verification or classification processes. In recent weeks, Anthropic has already tested this automated detection process in dozens of open source projects.
To validate an early version of the scanner, Anthropic commissioned senior penetration testing experts responsible for CVD audits to manually verify 97 high and critical severity vulnerabilities detected in 48 projects. The results showed that 85 (88%) met the standards for entering the CVD disclosure process; among the remaining 12 findings, 11 were real but considered known defects or duplicates of other results from this scan, and only one was determined to be a false positive.
Anthropic's official stated that although the scanner cannot guarantee absolute perfection, it will continue to refine and optimize the entire detection system based on feedback from maintainers and as the underlying models continue to evolve.
Join Now