Contacts
Follow us:
Contact us
Close

CONTACTS

Krikis, MB, Company code: 305601196, Klaipėda, Lithuania

info@krikis.lt

Anthropic introduces free AI security scans for open source projects

Anthropic introduces free AI security scans for open source projects

Anthropic introduces free AI security scans for open source projects

Anthropic PBC has announced a new service – OSS Scanner – that gives open source projects the ability to receive periodic, in-depth security scans using the company’s most powerful AI models, at no upfront cost. The initiative is part of the broader Anthropic Cyber Mission, which aims to protect both critical infrastructure and the open source ecosystem from the growing threat landscape driven by AI.

The service is designed to automate vulnerability detection and provide direct, fully documented notifications to project maintainers. According to SiliconANGLE, OSS Scanner operates as a live service that any eligible project can purchase by submitting a pull request to Anthropic’s GitHub repository. The evaluation is based on the project’s impact on infrastructure and user security, and projects that don’t have the resources to process raw data will still receive human-verified notifications through the existing disclosure process.

How does OSS Scanner work?

Secure server room with bright acids

OSS Scanner relies on trusted AI models, including Claude Mythos, to scan codebases and generate a „reproducer“ – a self-contained test that can reproduce the vulnerability. Each report also includes a potential fix and a „bisection“ analysis of the code history, which indicates when the bug was introduced. This information, according to SiliconANGLE, allows maintainers to understand the problem more quickly and take action without additional human verification.

Early testing showed that out of 97 critical and high-risk findings, 85 were confirmed as suitable for disclosure, while the rest were mostly repeats of already known vulnerabilities. WolfSSL Inc. confirmed that out of 74 reports received, 72 were correct, and five of them became CVEs. This data suggests that the accuracy of the model is quite high, although some reports may have inaccurate severity ratings.

Critical Infrastructure Program Context

OSS Scanner is just one of two parts of the Anthropic Cyber Mission. The other, the Critical Infrastructure Defense Program, is designed to help security companies that work with power grids, water systems, and other OT (operational technology) solutions. The program has already attracted 11 partners, including Accenture, Deloitte, CrowdStrike, Palo Alto Networks, Hitachi, and Rockwell Automation. These partners provide consulting, security solutions, and even manufacture and upgrade hardware that often cannot be turned off due to long periods of operation.

Open source community reaction

Open source fragment on a computer screen

The new service has attracted a lot of interest from the cryptocurrency and other technology sectors. According to Cointelegraph, Ethereum client developers Nethermind and Bitcoin and Lightning wallet ZEUS have already applied to join the OSS Scanner. These projects hope to receive fast and reliable notifications of potential vulnerabilities so that they can patch them in time and prevent potential attacks. Other candidates – such as VirtEngine, a decentralized cloud computing platform – are also looking to take advantage of the opportunity.

Financing and future prospects

„The Anthropic Cyber Mission relies not only on technological means, but also on financial support. The company has committed $1.4T4 million to various organizations, including OpenSSF and the Apache Software Foundation, and has provided $1.4T100 million in usage credits through Project Glasswing. This investment allows the OSS Scanner to remain free and ensures that projects can receive ongoing scans at no additional cost.

While the service is still in its early stages, early tests suggest that AI models can provide a significant advantage over potential attackers, especially when it comes to OT systems that cannot be shut down due to long service cycles. Anthropic says this approach will help reduce the „vulnerability-to-exploit“ time frame, where a vulnerability is discovered but not yet patched.

Conclusions

Anthropic OSS Scanner is a significant step towards strengthening open source security, giving projects access to cutting-edge AI models at no direct cost. The service’s integration with existing disclosure processes, partnerships with critical infrastructure security leaders, and significant financial backing demonstrate that the company is serious about addressing the cybersecurity challenges associated with AI. If this initiative remains effective, it could become standard practice not only in the open source community but also in the broader technology sector.

Sources

IT SERVICES

Let's transform technology real results for your business.

We help companies apply artificial intelligence, automation, internet systems, and other digital solutions to real business processes.

Contact us Initial consultation is free of charge.