Updated
Updated · The Verge · Oct 8
Anthropic Launches Free AI Security Scans for Open-Source Projects With 0 Human Review
Updated
Updated · The Verge · Oct 8

Anthropic Launches Free AI Security Scans for Open-Source Projects With 0 Human Review

3 articles · Updated · The Verge · Oct 8

Summary

  • Anthropic has opened an opt-in service called OSS Scanner that gives open-source projects free, periodic vulnerability scans generated by its strongest models, including Claude Mythos.
  • 0 human reviewers check the reports before they are sent, a trade-off Anthropic says enables faster, more frequent scanning but can also produce incorrect or invalid findings.
  • AI bug-hunting tools have recently helped uncover major flaws, including May’s “Copy Fail” bug that affected nearly every Linux distribution.
  • Open-source maintainers are also facing a flood of AI-generated bug reports, with projects tied to Linus Torvalds and Google among those struggling to keep up.

Insights

Will Anthropic's AI scanner prevent the next major cyberattack, or simply bury open-source developers under an avalanche of false alarms?
As AI uncovers critical software flaws faster than humans, who is responsible when automated bug reports overwhelm the developers trying to fix them?