IT之家 AI

Anthropic Launches OSS Scanner: Using AI to Scan Open Source Software for Vulnerabilities Free of Charge

IT Home reported on October 9 that on October 8, local time, Anthropic announced the official launch of the open-source software optional access vulnerability detection service, OSS Scanner. The open-source software…

IT之家 On October 9, local time on October 8, Anthropic announced the official launch of the open-source software optional access vulnerability detection service, OSS Scanner. The open-source software included in this project will receive comprehensive, regular, free security scans by Anthropic’s most powerful AI model (including Claude Mythos).

As a core maintainer of an eligible open-source project, you only need to submit a pull request (PR) to the OSS Scanner GitHub repository using a standard project template to apply for access. Its review criteria are similar to Google’s OSS-Fuzz, with priority given to basic open-source projects that have a significant impact on critical infrastructure and user security.

According to the report, in the past six months, Anthropic used the latest models to conduct vulnerability scans on several core software projects worldwide. A total of over 29,000 potential vulnerabilities were identified. Due to limited personnel, Anthropic was only able to manually review and assess approximately 6,000 of these vulnerabilities.

Anthropic says it will continue to manually submit manually verified vulnerability reports through the existing Coordination Vulnerability Disclosure (CVD) process; at the same time, an optional “fast track” is also provided for teams that wish to obtain details as soon as vulnerability reports are released.

According to IT Home, the OSS Scanner scan results are entirely generated automatically by a large model, without any manual review or grading process. In the past few weeks, Anthropic has verified this automated detection process in dozens of open-source projects.

To verify the early version of the OSS Scanner, Anthropic assigned senior penetration testing experts responsible for CVD audits to manually review the 97 serious and high-risk vulnerabilities detected by the scanner in 48 projects.

Among these vulnerabilities, 85 (88%) met the criteria for entering the CVD disclosure process. Of the remaining 12 detected items, 11 actually exist but are known defects or overlap with other results from this scan; only 1 was ultimately determined to be an invalid report (false positive).

Anthropic said that it cannot guarantee that the scanner is absolutely perfect and error-free, but they will combine feedback from maintenance personnel, and as the underlying model continues to evolve, they will continuously refine and optimize the entire detection system.

Advertising statement: The text contains external link references (including but not limited to hyperlinks, QR codes, passwords, etc.) designed to provide more information, save selection time, and the results are for reference only. Articles on IT Home that include external links all include this statement.

Original source

IT之家 AI

Content notes

Original publication and rights belong to the source.

Machine translation · Refer to the original