← Back to the feed

Anthropic launches free AI security scans for open-source projects

The Verge ·

Anthropic has launched OSS Scanner, a free service that offers open-source projects periodic security scans using its strongest AI models. The aim is to help developers spot vulnerabilities sooner, which matters as AI tools are increasingly used to find flaws in widely used software.

Projects must opt in, and the reports are generated entirely by AI, with no human review or triage, so some may be incorrect or invalid. Anthropic says the scans will use models including Claude Mythos; similar AI-assisted research has helped uncover serious flaws, while developers such as Linus Torvalds and Google have also faced a growing volume of AI-generated bug reports.

  • Anthropic is offering free, periodic AI security scans to open-source projects.
  • OSS Scanner reports will have no human review and may be invalid.
  • AI bug reports can help find flaws but add pressure on developers.

New here? Start with this

Open-source software is code that anyone can inspect, use or contribute to. It often underpins websites, apps and other tools, so a flaw in a widely used project can affect many people.

Anthropic is an AI company whose Claude models can analyse code for possible security weaknesses. Its scanner is intended to help project maintainers find flaws, but projects must choose to take part and the reports are produced without human review, so they may include mistakes.

AI tools are increasingly being used both to uncover vulnerabilities and to generate bug reports, adding to the work developers must assess. The key question is how useful automated scans can be in finding real problems while keeping inaccurate reports manageable.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

Free, opt-in scans could help open-source maintainers find serious vulnerabilities earlier, especially in widely used projects that may lack dedicated security teams. Using capable AI models to examine code at scale could make security checks more accessible as AI-assisted discovery becomes increasingly common.

The case against

Reports generated without human review may include false or invalid findings, adding work for maintainers who already face a growing volume of AI-generated bug reports. Even a free service can impose real costs if teams must spend time validating its results, so they may reasonably prefer more selective, human-triaged reporting.

AI Business Markets Technology

Read the full article at the source →