Anthropic Launches OSS Scanner to Let Claude Find Vulnerabilities Before Hackers Do


anthropic fable 5 suspended
Image credit: Anthropic

Anthropic is taking its AI-powered cybersecurity push ine notch up with OSS Scanner, a new opt-in service that uses its strongest Claude models to regularly scan open-source software for security vulnerabilities. The service is available to eligible projects at no cost and is designed to get vulnerability reports to maintainers much faster.

Anthropic’s AI scanner can find vulnerability before attackers do

Anthropic says its latest models have become dramatically better at finding security flaws. On the CyberGym benchmark, AI models went from finding fewer than 20% of vulnerabilities at the beginning of last year to more than 85% this year.

The company says it has already discovered more than 29,000 candidate vulnerabilities while scanning important open-source projects over the past six months. However, its human teams have only been able to manually review around 6,000 of them, creating a major bottleneck.

OSS Scanner is designed to remove that bottleneck. Unlike Anthropic’s existing coordinated vulnerability disclosure process, reports from OSS Scanner are fully generated by AI without human review or triage. That means maintainers receive findings faster, but Anthropic warns that some reports can still be incorrect.

The reports include a reproducer, an explanation of the vulnerability, and a proposed patch when one is available. Anthropic says early testing uncovered hundreds of bugs, including vulnerabilities that could be chained into unauthenticated remote code execution attacks.

Anthropic also tested 97 critical and high-severity findings across 48 projects with expert penetration testers. 85 findings, or 88%, met the company’s bar for its coordinated disclosure process, while only one was judged to be a false positive.

Open-source maintainers can opt in

Eligible core maintainers can enroll by submitting a pull request to Anthropic’s OSS Scanner GitHub repository. Projects must generally have a critical impact on infrastructure or user security, with eligibility decided case by case.

Anthropic says the service is aimed at projects capable of handling additional vulnerability reports. Projects that need human-verified findings can continue using the company’s existing disclosure process. The launch is part of Anthropic’s Cyber Mission, which also includes a new program aimed at helping defend critical infrastructure such as power grids, water systems and transportation networks.

More about the topics: AI, anthropic, Claude

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages