New vulnerability-finding service
Anthropic has introduced a free security scanning service called OSS Scanner designed to help open-source projects locate security vulnerabilities. Participating open-source projects that choose to opt in will receive thorough and periodic security scans provided at no cost.
According to Anthropic, the service utilizes its strongest models, including Claude Mythos, to give open-source software the largest defensive advantage possible and alert projects to potential security issues sooner.
Automated reports without human review
A key characteristic of the OSS Scanner is that its output is entirely model-generated. The service operates without human review or triage.
While this approach allows for faster and more frequent scanning, Anthropic notes that it also means reports could potentially be incorrect or invalid.
Context in open-source AI bug hunting
The introduction of OSS Scanner follows a broader trend of artificial intelligence tools being used to identify major security flaws in open-source software. Recent examples include the “Copy Fail” bug that affected nearly every Linux distribution.
At the same time, the influx of automated bug reports has created challenges for some open-source projects and maintainers, with figures such as Linus Torvalds noting difficulties in keeping up, and Google pausing an open-source bug bounty program due to automated submissions.

