Anthropic’s bid to help open source projects detect security vulnerabilities with a new service called OSS Scanner. It says open source projects that opt in will benefit from “periodic, in-depth security scans performed by our most powerful models, at no cost.” This could mean that open source projects will be alerted to possible security issues sooner, but the trade-off is that OSS Scanner’s reports are not subject to human review:
The results of this opt-in vulnerability scanner will be entirely model-generated, without human review or sorting. This will allow for faster and more frequent analysis, but means it is possible for reports to be incorrect or invalid. These reports will be generated by our most powerful models (including Claude Mythos) to give open source projects the greatest defensive advantage.
OSS Scanner is far from the first tool to help with AI bug hunting. AI tools have helped detect major security flaws in open source software in recent months, such as the “Copy Fail” bug that affected almost all Linux distributions in May. At the same time, some open source projects are struggling to cope with the sudden onslaught of AI-generated bug reports, including Linus Torvalds and even Google.
Gn bussni

