ProductHot

Anthropic's Free OSS Scanner Hunts Open-Source Bugs

Anthropic is handing open-source maintainers a free bug-hunting service run by its strongest models. No human checks the reports first, which is both the appeal and the catch.

Evan BrooksEvan Brooks
Heat: 700
Anthropic's Free OSS Scanner Hunts Open-Source Bugs

Anthropic is handing open-source maintainers a free bug-hunting service run by its strongest models. No human checks the reports first, which is both the appeal and the catch.

Anthropic's OSS Scanner Brings Free AI Vulnerability Scanning to Open Source

Anthropic launched OSS Scanner on October 8, an opt-in service that scans open-source projects for security bugs and sends maintainers the findings at no cost. There's no human review in the loop: the reports come straight from Anthropic's most capable models. For open-source maintainers who are often one person deep on security, it's the kind of offer that's hard to ignore.

The service grows out of Project Glasswing, Anthropic's internal push to use Claude to find vulnerabilities. The company says that work found more bugs than it could handle, which is why it's now sharing the firehose instead of filtering it first. As a free security tool aimed at open source security, it hands projects the kind of scanning they'd otherwise pay for.

Why AI Vulnerability Scanning Took Off So Fast

The case for OSS Scanner rests on a number that's moved fast in a short time. On CyberGym, an academic vulnerability-finding benchmark, language models went from catching under 20% of bugs at the start of last year to over 85% this year. That's the jump that turned AI bug hunting from a curiosity into a tool maintainers actually want.

Anthropic says the quality crossed a line. Maintainers used to get "slop" from AI, a flood of low-value, wrong reports that wasted their time. More and more, they're getting high-quality bug reports instead. Some of them arrive with a working exploit attached, which lets an engineer verify the issue on the spot rather than taking a claim on faith.

The timing is the point. Anthropic notes that exploits can now be developed in minutes. If attackers can move that fast, projects that find and fix bugs quickly gain a real edge. Scanning speed becomes a race, and the model side of the race keeps getting faster.

Inside Project Glasswing: 29,000 Bugs and a Human Bottleneck

The reason Anthropic is handing over raw output is that its own team couldn't keep up.

Over the last six months, the company used its latest models to scan some of the world's most important software projects. That work turned up more than 29,000 candidate vulnerabilities. Anthropic could only manually review and triage about 6,000 of them. The rest sat in a queue, waiting on human capacity that wasn't there.

Maintainers started asking for the whole pile. Anthropic says it has sent nearly 5,000 reports directly to maintainers after they asked to receive everything, even the unverified ones. When people on the receiving end are saying "send it all, we'll sort it," the bottleneck stops being a reason to hold back.

That's the logic behind the free, unreviewed scanner. Instead of being the filter, Anthropic becomes the sender.

How the Free OSS Scanner Works and What the Reports Include

Joining is opt-in, and that word matters. Projects choose whether to receive scans, rather than having Anthropic scan them uninvited.

Once a project signs up, it gets thorough, periodic scans from Anthropic's strongest models. Each report aims to be self-contained: an explanation of the bug, a reproducer you can run, a bisection showing when the bug was introduced where possible, and a candidate fix when the model can write one. Anthropic modeled the idea on Google's OSS-Fuzz, which scans open-source software with fuzzers, but swaps the fuzzer for a language model.

The no-human-review design is deliberate and comes with a warning attached. Because nothing is validated before it's sent, some reports will be wrong. Anthropic says so plainly. Open-source maintainers who've gotten the early reports tend to say the signal is high anyway. In one test, Anthropic asked expert penetration testers to check 97 critical and high-severity findings across 48 projects. Of those, 85 met the bar, 11 turned out to be real but duplicates of known issues, and one was a genuine false positive.

Early users gave it a warm review. Noah Misch, a PostgreSQL developer, said an unusually high share of the scanner's findings caught real defects, and that several reports came with fixes usable almost as-is. Anton Arapov of OpenSSL Corporation said the reports, raw output included, were as good as or better than what humans send. Todd Ouska of wolfSSL said that of 74 reports his project received, all but two were valid and five became CVEs.

What OSS Scanner Means for Open-Source Maintainers

The offer is aimed at projects, not enterprises. Anthropic already sells Claude Security, a code scanning and patching product for companies. OSS Scanner is the free counterpart for the open-source world.

If you maintain a project, the trade-off is straightforward. You get frequent, detailed security reports for free, with reproducers and patches that can slot into your existing review process. The cost is triage time, since you're no longer shielded by a human filter.

The most useful habits here are familiar ones. Treat each report as a lead, not a verdict: verify the reproducer, check the severity yourself, and watch for inflated ratings or findings that miss your project's threat model. Anthropic says early maintainers flagged exactly those issues. Enrolling is opt-in, so the call on whether the noise is worth the signal sits with each project.

Share This Story

Mentioned products

Sources

Related AI News

Google Cloud's Gemini Agent Takes on Work Tasks
Product

Google Cloud's Gemini Agent Takes on Work Tasks

Google's Gemini just got a promotion from answering questions to finishing work. Businesses get it first, and the model picker reaches outside Google on day one.

Heat: 820
Anthropic's New Usage Policy Bans Model Abuse
Business & Industry

Anthropic's New Usage Policy Bans Model Abuse

Anthropic rewrote its rules for the first time in a year. The headline change protects the model itself, and the election section got a more careful rewrite than most people expected.

Heat: 780
Anthropic Opens Claude Cyber Access in Three Tiers
Business & Industry

Anthropic Opens Claude Cyber Access in Three Tiers

Anthropic is handing its strongest security tools to the defenders who need them, with conditions attached. The company folded two older programs into one three-tier system, and every tier now requires data retention.

Heat: 1,200
Anthropic's $100M Plan to Train 10,000 AI Engineers
Business & Industry

Anthropic's $100M Plan to Train 10,000 AI Engineers

Anthropic is spending $100 million to build a specific kind of engineer, one who can move AI from a slide deck into a working system. The catch: you can't apply, and the first badges won't exist until 2027.

Heat: 1,050