A beam of light scanning a wall of dark server-rack bricks and illuminating hairline cracks in three of them
News

Anthropic Will Scan Your Open-Source Project for Vulnerabilities — Free, and With No Human in the Loop

Born out of Project Glasswing's 29,000-candidate vulnerability pile, the free opt-in service is Anthropic's answer to a triage bottleneck it admits it cannot staff — and a statement about where AI security work is heading.

AI SafetyCybersecurityAnthropicOpen SourceClaude

Anthropic has opened its vulnerability-hunting machine to everyone who maintains an open-source project. The company announced OSS Scanner this week, a free opt-in service that runs Anthropic’s strongest models — including Claude Mythos — over participating projects and delivers vulnerability reports directly to maintainers: reproducer, root-cause explanation, bisection of when the bug was introduced, and a candidate patch where one exists.

The catch is stated in the same breath as the offer: the reports are “fully model-generated, without human review or triage.” Faster and more frequent scanning, Anthropic writes, means “it is possible reports will be incorrect or invalid.” As Engadget notes, the paid Claude Security product keeps a human-verified pipeline for enterprises; the open-source ecosystem gets the raw model output.

Why Anthropic is delegating its own backlog to software

The service is really an overflow valve for Project Glasswing, Anthropic’s vulnerability-discovery programme. Over the past six months its models surfaced more than 29,000 candidate vulnerabilities across major open-source projects — and humans managed to triage only about 6,000 of them. Anthropic’s own framing is that it is bottlenecked on human review capacity, not model capability. On the CyberGym benchmark, LLMs went from finding under 20% of vulnerabilities at the start of last year to over 85% this year.

Maintainers, remarkably, asked for the raw feed. Nearly 5,000 unvalidated reports have already gone out after recipients requested bulk submissions with proposed patches — on the theory that a report with a reproducer attached costs an engineer minutes to verify and exploits can be developed in minutes once a bug is public.

The early numbers justify the confidence, mostly. Independent penetration testers validated an early version against 97 critical and high-severity findings across 48 projects: 85 (88%) met Anthropic’s coordinated-disclosure bar, 11 of the remainder were real but duplicated known issues, and exactly one was a false positive. Maintainer quotes in the announcement are close to glowing — curl’s Daniel Stenberg credited the scanner with finding “one of the worst curl vulnerabilities reported in the last few years,” and wolfSSL’s Todd Ouska reported 72 of 74 reports valid, five becoming CVEs. Best-AI.org’s coverage tallies the same figures.

The trade nobody has priced yet

Here’s the uncomfortable part, and Anthropic deserves credit for printing it: the defence layer of the internet’s shared software infrastructure is being handed to models that also sit in the hands of anyone willing to pay API rates. OSS Scanner is framed as a defensive gift, modelled on Google’s OSS-Fuzz. It is also a demonstration that frontier AI has crossed the threshold where one company can find tens of thousands of real vulnerabilities at industrial scale. The same capability, pointed by a different motive, is the supply-chain nightmare scenario security researchers have been warning about — a point this site has covered from AI labs’ own hacking disclosures to the low-skill-attacker effect. Anthropic publishing a 88%-valid raw-output pipeline is, among other things, a progress report on how far that capability has come.

The economics deserve a second look, too. Anthropic says this is about open-source defensive posture; it is also product strategy. Every raw report teaches maintainers that Anthropic’s models find things fuzzers miss, at a price point — free — Google’s OSS-Fuzz has held for a decade. The paid Claude Security product sits one tier up for enterprises that want the human-verified version. Giving away model-generated triage builds the customer base for selling it. That isn’t sinister; it’s the same land-grant logic behind every free developer tier. But the open-source ecosystem should notice that the free tier’s quality signal and the paid tier’s sales pitch are now the same artefact.

For maintainers, the practical calculus is straightforward. A raw report with a reproducer and candidate patch is nearly costless to check and occasionally gold — and maintainers can still enrol via a PR to the anthropics/oss-scanner repo. New Zealand sits at the end of every one of these supply chains: government, banks and cloud services here run on the same OpenSSL-class libraries, as NZ’s own cyber agency has been warning. Whatever raises the patch rate on unmaintained internet plumbing benefits everyone downstream — including the 88% of reports that turn out to be real.

The deeper shift is cultural. Vulnerability disclosure has always been a human-to-human courtesy — a researcher emailing a maintainer, arguing about severity. We’re now entering an era where the researcher is a model and the first contact is a machine-generated report that may arrive faster than the maintainer can triage. Open source just got the defensive version of that world. The offensive version is already somebody else’s roadmap.

Sources: Anthropic, Engadget, Best-AI.org

Sources: Anthropic, Engadget, Best-AI.org