- Anthropic has launched OSS Scanner, a free, opt-in vulnerability-finding service for open-source software.
- The service uses Anthropic’s most powerful models, including Claude Mythos, and generates reports without human review.
- Penetration testers found that 85 of 97 critical and high-risk findings across 48 projects met coordinated vulnerability disclosure quality requirements.
Anthropic has launched OSS Scanner, a free service designed to find vulnerabilities in open-source software. The opt-in program will allow eligible projects to receive periodic checks using the company’s most powerful models, including Claude Mythos, expanding access to security audits for open-source developers.
Anthropic built the service using experience gained from deploying artificial intelligence to find vulnerabilities through Project Glasswing. Unlike its enterprise product, Claude Security, OSS Scanner focuses on supporting open-source developers and will provide audits at no cost, the company said.
Models identified more than 29,000 potential vulnerabilities
Anthropic said it used its latest models over the past six months to review some of the most important software projects. The models identified more than 29,000 potential vulnerabilities, but specialists were able to verify and prioritize only about 6,000 manually.
Open-source developers have increasingly asked to receive all identified issues, including findings that specialists have not yet reviewed, according to the company. By the time Anthropic announced OSS Scanner, it had sent project maintainers nearly 5,000 such reports, along with suggested fixes.
OSS Scanner is intended to accelerate that process by generating reports automatically and without human review, allowing projects to be scanned more frequently. Anthropic cautioned that the results may contain false positives, duplicate findings or inaccurate severity assessments.
Before the launch, Anthropic tested the scanner on dozens of open-source projects. The initial results produced hundreds of bug reports, including several cases in which vulnerabilities could be chained to enable unauthenticated remote code execution, or RCE.
Penetration testers reviewed high-risk findings
For further validation, penetration testers analyzed 97 critical and high-risk findings across 48 projects. Of those, 85 findings, or 88%, met the quality requirements of the coordinated vulnerability disclosure process.
Another 11 findings were genuine bugs but duplicated previously known issues or other scan results. Only one finding was a false positive.
Some project maintainers nevertheless said the scanner may overstate severity ratings or misinterpret a project’s threat model. Anthropic said it would continue improving the system based on developer feedback and advances in its models.
Scanner reports will include code that reproduces the bug, an explanation of the vulnerability, information about when it may have entered the code and, when available, a proposed fix.
How projects can apply
Maintainers of eligible projects can apply by creating a request in the service’s GitHub repository and following its standard template and additional instructions.
Anthropic will select projects individually, using criteria similar to those employed by OSS-Fuzz. The principal requirement is that a project have a significant effect on infrastructure and user security.
Separately, Broadcom will provide Anthropic with as much as $42 billion to fund AI infrastructure, according to an earlier report.
Source: Incrypted
