Radar / AI security / Anthropic OSS Scanner
Anthropic OSS Scanner: free AI vulnerability scans for open-source projects
Opt-in service giving critical open-source projects periodic security audits from Anthropic's strongest models (including Claude Mythos), with fully model-generated reports (self-contained reproducer, explanation, bisection, candidate patch) and no human review or triage.
Why it matters
First time a frontier lab offers free, continuous AI-driven security audits to the OSS ecosystem at scale; 29,000+ candidate findings already surfaced, with early pilots (wolfSSL: 72 of 74 reports valid, 5 CVEs) showing unusually high signal.
What you could build with it
A security startup could build a triage and remediation concierge for open-source foundations: enroll client projects in OSS Scanner, route the raw model-generated findings through a human-vetted queue, and auto-open pull requests with the candidate patches for maintainer approval, turning AI-found bugs into merged fixes within days.
Does it hold up?
Early pilot evidence is strong: wolfSSL validated 72 of 74 reports with 5 CVEs, and Anthropic's check of 97 critical/high-severity findings found 88% met the coordinated-vulnerability-disclosure bar. Caveats: reports are unreviewed and may include false positives, and enrollment is limited to projects with critical infrastructure impact, so most indie projects cannot use it yet.
Built with Anthropic OSS Scanner
- wolfSSL early trial: 72 of 74 reports valid, 5 became CVEsarticle · Encryption library vendor wolfSSL, an early participant, said nearly all scanner reports it received were valid and five turned into CVEs — the first public third-party signal on report quality.
- Implicator breakdown: 116 enrollment PRs within 24 hours of launcharticle · Reports the scanner repo drew 116 enrollment pull requests by Oct 9 and summarizes disclosure stats (6,157 findings reported to maintainers, 516 patched upstream as of Oct 2).
Learn more
First spotted on github: source.
More AI security
OpenAI, Anthropic and Google DeepMind jointly unveil cyber-focused safety models and safeguardsThe three rival labs disclosed weeks of behind-the-scenes coordination and jointly released a set of cyber-focused AI…security · JEV 0.73OpenAI textGrain watermarking for ChatGPT and Codex in the EUOpenAI will roll out its invisible textGrain watermarking system to ChatGPT/Codex users in the EU over the coming…security · JEV 0.65Cloudflare security-audit-skill: multi-phase security audits for coding agentsA coding-agent skill that runs multi-phase security audits with independently verified, machine-checkable findings.security · JEV 0.63LiveNerf: a pre-registered benchmark for post-release model driftOpen-source, pre-registered 30-day benchmark that detects whether Claude Opus 5.5 quietly gets worse after launch.security · JEV 0.61Sandlock 0.8.8: deferred commit for agent sandboxesThe process-based Linux AI sandbox (no container, no VM) ships deferred commit: every run returns a changeset of what…security · JEV 0.58Microsoft Execution Containers (MXC) goes GA on Windows 11At its Oct 7 Windows AI event with NVIDIA, Microsoft announced general availability of Microsoft Execution Containers…security · JEV 0.58
Get the week's best AI launches, plus 3 ideas worth building
One email every Saturday. Ranked by traction, not hype. Free.