THE CRUNCH

Anthropic has launched OSS Scanner, a free service that runs periodic security scans on open-source projects that opt in. The company says participating projects will get "thorough, periodic security scans by our strongest models at no cost," with the aim of surfacing possible vulnerabilities sooner.

The scanner does more than raise the alarm. According to The Decoder, it automatically flags vulnerabilities, explains them and suggests patches to maintainers, and Anthropic expects its accuracy to be above 90 percent. Maintainers of projects critical to infrastructure or user safety can opt in via GitHub.

There is a catch worth knowing about. Anthropic states that the scanner's reports are fully model-generated, without human review or triage. That enables faster and more frequent scanning, but it also means some reports may turn out to be incorrect or invalid, so maintainers will need to weigh each alert themselves.

SecurityWeek likewise describes the service as sending unreviewed, model-generated vulnerability reports to maintainers who opt in, which matches Anthropic's own framing of the speed-versus-accuracy trade-off.