Anthropic launched OSS Scanner on October 8, offering eligible open-source maintainers free, recurring AI security scans with findings sent without human review. Teams can get suspected flaws sooner, but they take on the work of checking whether the reports are right. In an earlier Mythos scan, curl lead developer Daniel Stenberg said his security team spent hours checking five claimed vulnerabilities and confirmed only one. He said the report helped improve curl, while noting that AI tools can offer patches that usually aren't a complete fix.
The service grew out of a bottleneck: Anthropic says its models found more than 29,000 candidate vulnerabilities over six months, while people reviewed roughly 6,000. Those figures alone don't establish accuracy: they don't say how many of the reviewed candidates were confirmed. Some maintainers asked for the unchecked findings too, prompting the company to offer a standing opt-in service. Reports explain the suspected bug, include an example demonstrating how it could be exploited, and offer a proposed fix when available.
Core maintainers apply through a pull request, a proposed change, in Anthropic’s enrollment repository. They add projects/<project>/project.yaml with a repository address and contact email, plus a Dockerfile containing instructions to install dependencies and build the project. The audit runs without internet access after setup; contact addresses in the enrollment file are public, so Anthropic recommends an address suitable for publication.
Acceptance is case by case, prioritizing established projects important to infrastructure and user security. Anthropic checks that applicants are core maintainers and says the service is intended for teams able to handle additional findings. These automated reports don't start a 90-day public-disclosure countdown, although that clock can begin if Anthropic later validates a finding through its human review program and notifies the maintainer.
Anthropic hasn't committed to a fixed scan interval, and teams can pause automated reports. The question to watch is how many unchecked OSS Scanner reports become verified fixes.
Sources
- 1.Launching an opt-in vulnerability-finding service for open-source software · Anthropic
- 2.anthropics/oss-scanner · Anthropic via GitHub
- 3.OSS Scanner · Anthropic Frontier Red Team
- 4.Introducing the Anthropic Cyber Mission · Anthropic
- 5.Mythos finds a curl vulnerability · Daniel Stenberg
Reported by the WattsUpNext desk from the sources linked below. Spot an error? Tell us at corrections@wattsupnext.com.
The WattsUpNext Brief
Get stories like this in your inbox.
One email each weekday, only the topics you choose. Real news, sourced, no fluff. Unsubscribe in one click.




