On October 9th, according to news from the IT community, on October 8th local time, Anthropic officially launched an optional vulnerability detection service OSS Scanner for open-source software. Open-source projects that join this initiative will receive comprehensive and free regular security scans provided by Anthropic's most powerful AI models (including Claude Mythos).
Eligible core maintainers of open-source projects only need to submit a pull request to the OSS Scanner GitHub repository ( PR ) following the standard project template to complete the application for integration. The review criteria are similar to Google's OSS-Fuzz, with priority given to fundamental open-source projects that have a significant impact on critical infrastructure and user security.
According to the introduction, over the past six months, Anthropic has used the latest models to conduct vulnerability scans on multiple core software projects around the world, detecting more than 29,000 potential vulnerabilities. Due to limited manpower, Anthropic was only able to manually review and assess about 6,000 of these vulnerabilities.
As mentioned by Anthropic, they will continue to submit manually verified vulnerability reports through the existing coordination and vulnerability disclosure process (CVD). At the same time, an optional "fast track" has also been established for teams that wish to obtain detailed information as soon as possible after the vulnerability reports are produced.
IT has learned that the scanning results of OSS Scanner are entirely generated automatically by large models, without any manual review or grading process. In the past few weeks, Anthropic has completed practical tests of this automated detection process in dozens of open-source projects.
To verify an early version of OSS Scanner, Anthropic entrusted senior penetration testing experts responsible for auditing CVD to manually review 97 severe and high-risk vulnerabilities detected by the scanner in 48 projects.
Among these vulnerabilities, 85 (accounting for 88%) met the criteria to enter the CVD disclosure process. Of the remaining 12 detected items, 11 indeed existed but were either known defects or overlapped with other results from this scan; ultimately, only 1 case was determined to be an invalid report (false positive).
As mentioned by Anthropic, it is not possible to guarantee that this scanner is absolutely perfect and error-free, but in the future, we will continue to refine and optimize the entire detection system based on the feedback from maintenance personnel and with the continuous iteration of the underlying models.












