Anthropic Launches Free AI Tool to Scan Open-Source Code for Vulnerabilities
· Technology · Engadget, Bloomberg
Anthropic has introduced a free vulnerability-finding service called OSS Scanner for open-source software projects. The service provides thorough, periodic security scans using Anthropic's strongest AI models, including Claude Mythos, at no cost to participating projects. Outputs from the scanner are fully model-generated without human review or triage, which may result in incorrect or invalid reports. Anthropic notes the tool was inspired by Google's OSS-Fuzz, which has been available since 2016, and contrasts it with their existing paid product, Claude Security. The company acknowledges that both it and Google benefit from open-source code that underpins the internet, often maintained by unpaid workers, citing the XZ Utils backdoor as a recent example of dangerous vulnerabilities in such code.
Why it matters
Open-source developers gain access to advanced AI-powered security scanning at no cost, potentially improving the security of widely used software. However, the lack of human review raises concerns about the reliability of vulnerability reports, which could lead to wasted effort or missed threats.
Read the original report — Engadget
Join us on Telegram
Breaking news the moment it lands. At 10,000 members we ship the Android app.