AIbaseUpdated

Anthropic launches OSS Scanner, using its most powerful AI models to scan the world's open-source software for vulnerabilities for free

On October 8, Anthropic announced the launch of OSS Scanner, an opt-in vulnerability detection service that will leverage its most powerful AI models (including Claude Mythos) to provide regular, free security scanning…

AI company Anthropic officially announced on October 8 local time the launch of a brand-new opt-in vulnerability detection service — OSS Scanner. The project aims to leverage Anthropic's most powerful AI models (including Claude Mythos) to provide comprehensive, regular free security scanning for open-source software worldwide.

For the application process, core maintainers of eligible foundational open-source projects simply need to submit a pull request (PR) to the OSS Scanner GitHub repository following the standard project template to complete their application. The overall review criteria are similar to Google's OSS-Fuzz, primarily targeting core open-source projects that have a significant impact on critical infrastructure and user security.

Looking back at the earlier technical exploration, over the past six months Anthropic used its latest models to conduct vulnerability scanning on multiple core software projects worldwide, cumulatively detecting more than 2.9万 (i.e., over 29,000) candidate vulnerabilities. However, limited by scarce manpower, it has so far only been able to complete manual review and severity assessment of approximately 6,000 of these vulnerabilities.

Regarding the vulnerability disclosure mechanism, Anthropic said it will continue to submit manually verified vulnerability reports through the existing coordinated vulnerability disclosure (CVD) process; at the same time, it has also opened an optional "fast track" for teams that want to obtain details as soon as a vulnerability report is produced.

The official introduction states that OSS Scanner's scan results are generated entirely automatically by large language models, without any manual review or triage process. Over the past several weeks, Anthropic has completed real-world validation of this automated detection process across dozens of open-source projects.

To validate an early version of the scanner, Anthropic commissioned a senior penetration testing expert responsible for CVD audits to manually review the 97 critical and high-severity vulnerabilities detected by the scanner across 48 projects. The results showed that 85 of them (88%) met the standard for entry into the CVD disclosure process; among the remaining 12 findings, 11 were genuine but were either known defects or overlapped with other results from this scan, and only 1 was ultimately judged to be a false positive.

Anthropic officially stated that while it cannot guarantee the scanner is absolutely perfect and error-free, it will continue to refine and optimize the entire detection system going forward by incorporating feedback from maintainers and as the underlying models continue to iterate.

Original source

AIbase

Content notes

Original publication and rights belong to the source.

Machine translation · Refer to the original