Anthropic Sends Unverified Vulnerability Reports to Open Source
Anthropic launches OSS Scanner, delivering raw AI-generated vulnerability reports to open-source projects without human triage.
ImportanceMaterialEvidenceE3 inspectableWrite-upQuick
Anthropic launched OSS Scanner on October 8, a free vulnerability scanning service that sends fully model-generated reports directly to open-source maintainers without human review.
Over the prior six months, Anthropic discovered more than 29,000 candidate vulnerabilities but could only manually triage approximately 6,000 due to human capacity limits. On CyberGym, an academic vulnerability-discovery benchmark, LLM detection rates rose from under 20% to over 85% within a year, creating a backlog of high-quality but unverified reports.
Each OSS Scanner report includes a self-contained reproducer, vulnerability explanation, and candidate patch. In internal validation, Anthropic asked expert penetration testers to review 97 critical and high-severity findings across 48 projects; 85 (88%) met the bar for coordinated disclosure. PostgreSQL and wolfSSL maintainers confirmed most reports were valid, though some severity ratings were inflated.
The service is free and open to eligible projects via a GitHub application. Anthropic acknowledges reports may contain false positives and plans to refine the system based on maintainer feedback.