Anthropic Launches Unreviewed AI Vulnerability Scanner, Claims 88% High-Severity Hit Rate
Anthropic released OSS Scanner, a free open-source vulnerability scanning service powered by its strongest models, self-reporting an 88% success rate for high-severity findings without human review.
ImportanceMaterialEvidenceE2 unreplicatedWrite-upQuick
Anthropic launched OSS Scanner on October 9, a free open-source vulnerability scanning service based on its strongest language models. The company claims that in early tests, 88% of critical and high-severity findings met the standards for Coordinated Vulnerability Disclosure (CVD).
Traditional open-source security relies on tools like Google's OSS-Fuzz or manual classification by human experts, creating a significant labor bottleneck. Anthropic noted that while its models discovered over 29,000 candidate vulnerabilities in the past six months, only about 6,000 could be manually reviewed. OSS Scanner aims to bypass this by removing the human review step, enabling faster and more frequent scans where maintainers receive raw model-generated reports directly.
The core feature is "zero human intervention." Reports are generated directly by models like Claude Mythos, including reproduction scripts and patch suggestions. Maintainers from projects such as PostgreSQL, OpenSSL, and wolfSSL reported that these findings were comparable to or better than some human reports, especially when accompanied by real exploit code. However, Anthropic acknowledged it cannot guarantee accuracy and warned that unverified reports could create noise.
The service is now opening to more projects, with eligible maintainers able to apply. This shifts the verification burden from the scanner to the recipient, making its actual utility dependent on the community's ability to process high-volume automated reports.