Anthropic has launched a new service called OSS Scanner to help open-source projects identify security vulnerabilities. Projects that opt-in will receive "thorough, periodic security scans by our strongest models at no cost." This service aims to alert projects to potential security issues earlier, though the reports are generated solely by AI models, including Claude Mythos, and do not undergo human review. This means reports may occasionally be incorrect or invalid, but Anthropic believes it offers a significant defensive advantage.
OSS Scanner is not the first AI tool to assist in finding security flaws in open-source software. AI has recently helped uncover major vulnerabilities, such as the "Copy Fail" bug affecting Linux distros. However, the influx of AI-generated bug reports has become overwhelming for some open-source projects, including those led by Linus Torvalds and even Google, which has paused its open-source bug bounty program due to a surge in AI-generated submissions.




