Anthropic Launches Free AI Tool to Find Security Bugs
Anthropic has launched OSS Scanner, a new opt-in service that uses its strongest AI models to search open-source projects for security vulnerabilities.
The company says participating projects will receive thorough, periodic security scans at no cost.
Powered by Claude Mythos
Anthropic says OSS Scanner will use its strongest models, including Claude Mythos, to analyze open-source code for possible security weaknesses.
The goal is to give maintainers earlier warnings about vulnerabilities before they can be exploited.
Projects must explicitly opt in to use the service.
No Human Review
There is an important limitation. Anthropic says OSS Scanner reports will be fully model-generated, with no human review or triage before they are sent to developers.
That allows Anthropic to perform scans more frequently and return results faster, but it also means some reported vulnerabilities may be incorrect or invalid.
Developers will therefore need to verify findings themselves before treating them as confirmed security issues.
AI Is Already Finding Major Bugs
AI-assisted vulnerability research is already being used to find serious problems in open-source software.
Recent examples include the “Copy Fail” vulnerability, which affected a large number of Linux distributions.
Tools like OSS Scanner could help maintainers identify similar problems earlier, especially in projects that lack dedicated security teams.
But AI Bug Reports Are Becoming a Problem
The rapid growth of AI-generated security research has also created a new problem for open-source maintainers.
Some projects are being flooded with low-quality or incorrect AI-generated vulnerability reports, increasing the amount of time developers must spend validating submissions.
Linux creator Linus Torvalds has previously criticized poor-quality AI-generated security reports, while Google has also faced problems with AI-generated submissions in its open-source vulnerability programs.
That makes accuracy particularly important for Anthropic’s new service.
OSS Scanner attempts to address the problem by using Anthropic’s strongest models, but the company is openly warning maintainers that its reports should not be treated as automatically verified findings.
For open-source projects willing to handle that additional validation work, the service could provide another free layer of security testing without requiring dedicated scanning infrastructure.
The post Anthropic Launches Free AI Tool to Find Security Bugs appeared first on ProPakistani.



