Anthropic's OSS Scanner Hunts Open-Source Vulnerabilities With Claude Mythos
Anthropic opened OSS Scanner, a free opt-in service that runs its strongest models against critical open-source repos and emails raw, unreviewed vulnerability reports to maintainers.
- Anthropic launched OSS Scanner, a free opt-in AI vulnerability scanner for critical open-source projects.
- Reports are fully model-generated with no human review, bundling a reproducer, bisection, and candidate patch.
- Over 29,000 candidate vulnerabilities found in six months; 88% of 97 reviewed critical/high findings met CVD standard.
- Enrollment is via PR adding a project.yaml and Dockerfile to the GitHub repo.
- Scanner runs in an isolated VM with no internet access after the initial build phase.
- Eligibility follows OSS-Fuzz-style criteria, prioritizing projects critical to infrastructure and user security.
Anthropic has launched OSS Scanner, a free, opt-in service that scans selected critical open-source projects and emails potential vulnerabilities directly to maintainers. Reports can include an explanation, proof of concept, Git history analysis, and candidate patch. Anthropic performs no human review before delivery, moving validation and prioritization to participating projects.
During a six-month internal effort called Project Glasswing, Anthropic says its models generated more than 29,000 candidate vulnerabilities across major software projects. Its staff manually reviewed about 6,000. OSS Scanner expands that work by giving maintainers access to unreviewed findings without waiting for Anthropic’s security team to triage them.
Raw reports, complete with reproducers
After accepting a project, Anthropic builds it inside an isolated virtual machine, disables network access, and runs its security agents against the code. The pipeline uses Anthropic’s strongest models, including Claude Mythos, according to the company.
Inside each report
- A description of the suspected vulnerability and its severity
- A self-contained reproducer or proof of concept
- A Git bisection that identifies the introducing commit when possible
- A candidate patch when the model can produce one
Anthropic emails reports to the project’s primary security contact and can copy additional addresses. Maintainers may provide a public key to receive PGP-encrypted messages.
Because the reports are raw model output, maintainers must confirm exploitability, severity, and relevance to the project’s threat model. An optional
This story is for Pro members
You've reached the end of the free preview. Upgrade to AlphaSignal Pro to read the full article - and everything else behind the paywall.