The instances of AI models “going rogue” and getting into places they shouldn’t be have proven that the bots are really good at finding vulnerabilities in systems. So it shouldn’t come as a surprise that some companies have decided to leverage these capabilities. Anthropic has recently announced OSS Scanner, a free opt-in service that checks open source projects for vulnerabilities.
Inspired by Google’s OSS-Fuzz, the service serves to provide coders with early warnings regarding potential security risks or issues. The tool uses the company’s strongest language models, including Claude Mythos, and the scanner’s outputs are fully generated with these models without human review or triage. This allows for faster and more frequent scanning.

However, the lack of human involvement means that there is a possibility that the reports will be incorrect or invalid. As we’ve seen time and time again, AI models have a tendency to make things up or “hallucinate”. According to the company, it checked the findings of an early version of OSS Scanner and found that 88% of its findings met the standards for its coordinated vulnerability disclosure (CVD) process. And out of the remaining results, only one was a false positive. While this indicates that the scanner is fairly reliable, it’s not perfect. Anthropic does acknowledge this, and has assured that it will continue to refine the system based on feedback.
Beyond that, the company will keep manually disclosing human-verified vulnerability reports through its CVD process. As mentioned on the launch page, OSS Scanner is meant to be an option for developers who want to receive reports as soon as they become available. Additionally, Claude Security remains available as a paid option, offering general-access code scanning and patching for enterprises. Those interested in OSS Scanner can head over to the official website for further instructions on how to enroll their projects. Worth noting that only some projects may be eligible for the service.
(Source: Anthropic)

