Anthropic's OSS Scanner Hunts Open-Source Vulnerabilities With Claude Mythos

Anthropic opened OSS Scanner, a free opt-in service that runs its strongest models against critical open-source repos and emails raw, unreviewed vulnerability reports to maintainers.

·
·
·
Anthropic's OSS Scanner Hunts Open-Source Vulnerabilities With Claude MythosPRO
Read2 min
TypeRepo
SubtopicRed Teaming
  • Anthropic launched OSS Scanner, a free opt-in AI vulnerability scanner for critical open-source projects.
  • Reports are fully model-generated with no human review, bundling a reproducer, bisection, and candidate patch.
  • Over 29,000 candidate vulnerabilities found in six months; 88% of 97 reviewed critical/high findings met CVD standard.
  • Enrollment is via PR adding a project.yaml and Dockerfile to the GitHub repo.
  • Scanner runs in an isolated VM with no internet access after the initial build phase.
  • Eligibility follows OSS-Fuzz-style criteria, prioritizing projects critical to infrastructure and user security.

Anthropic has launched OSS Scanner, a free, opt-in service that scans selected critical open-source projects and emails potential vulnerabilities directly to maintainers. Reports can include an explanation, proof of concept, Git history analysis, and candidate patch. Anthropic performs no human review before delivery, moving validation and prioritization to participating projects.

During a six-month internal effort called Project Glasswing, Anthropic says its models generated more than 29,000 candidate vulnerabilities across major software projects. Its staff manually reviewed about 6,000. OSS Scanner expands that work by giving maintainers access to unreviewed findings without waiting for Anthropic’s security team to triage them.

Raw reports, complete with reproducers

After accepting a project, Anthropic builds it inside an isolated virtual machine, disables network access, and runs its security agents against the code. The pipeline uses Anthropic’s strongest models, including Claude Mythos, according to the company.

Inside each report

  • A description of the suspected vulnerability and its severity
  • A self-contained reproducer or proof of concept
  • A Git bisection that identifies the introducing commit when possible
  • A candidate patch when the model can produce one

Anthropic emails reports to the project’s primary security contact and can copy additional addresses. Maintainers may provide a public key to receive PGP-encrypted messages.

Because the reports are raw model output, maintainers must confirm exploitability, severity, and relevance to the project’s threat model. An optional

Pro article

This story is for Pro members

You've reached the end of the free preview. Upgrade to AlphaSignal Pro to read the full article - and everything else behind the paywall.

Trending
  • No trending articles

Comments

avatar

Next Reads