HelpnetSecurity

Anthropic offers free AI security scans to open-source maintainers


Anthropic’s OSS Scanner is a new, free service that uses the company’s strongest AI models to find security vulnerabilities in open-source software. Maintainers who opt in receive periodic scans and reports explaining suspected flaws, how to reproduce them and, when available, how to fix them.

The service builds on Anthropic’s experience with Project Glasswing, which used Claude to find software vulnerabilities.

Anthropic says human validation has become a bottleneck in its vulnerability research. OSS Scanner sends AI-generated findings directly to project teams without human review, speeding up reporting while leaving maintainers responsible for checking findings and prioritizing fixes.

Early results and limitations

“Early AI reports about 18 months ago, before Project Glasswing, were appalling. The reports we received from Anthropic, raw model output included, were as good and sometimes better than what we get from people. Particularly when a report comes with a real exploit attached, that’s basically job done for an engineer as you can verify it right away,” said Anton Arapov, OpenSSL Corporation.

Penetration testers assessed 97 high and critical severity findings across 48 projects from an early version of the scanner. Anthropic said 85 met its coordinated disclosure criteria, 11 were genuine but duplicated known issues or other findings, and one was invalid.

“We can’t guarantee the scanner will be perfect,” Anthropic said. The company acknowledged that reports can overstate severity or misunderstand a project’s security assumptions.

What maintainers can expect

Enrolled projects receive an initial scan and a bundle of reports by email. Subsequent scans look for newly introduced vulnerabilities and issues missed in earlier checks. Their frequency will depend on factors including demand and how widely a project is used.

Maintainers can provide guidance on what to test, which inputs to treat as potentially malicious, how to rate severity and what kind of proposed patches would be useful.

The company says the service is intended for teams that can already keep up with verified high and critical severity reports and have capacity to investigate more findings.

Eligibility and disclosure

Core maintainers can apply through the OSS Scanner GitHub repository. Applications are assessed individually, with eligibility focused on established projects important to infrastructure and user security.

Unvalidated findings do not carry a mandatory 90-day disclosure deadline. If Anthropic later validates a report through its existing coordinated disclosure program, a 90-day period may begin when maintainers are notified of that validation.

Projects can pause automated reports or opt out and return to receiving only reports under company’s standard disclosure process.



Source link