MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-09 · via Engadget

Anthropic debuts free AI-powered vulnerability scans for open-source code

Image via Engadget
Image via Engadget

Anthropic has introduced OSS Scanner, a free service that periodically checks open-source projects for security flaws using its most capable AI models. Because the reports are generated entirely by models and are not reviewed by people, they may contain errors or invalid findings. The effort mirrors Google and OpenSSF's OSS-Fuzz and aims to help protect widely used open-source code.

Expanded Detail

Anthropic's OSS Scanner is an opt-in, no-cost service that regularly examines open-source projects with the company's most advanced models. Its findings are produced without human review or triage, so they may be mistaken or invalid, though this approach allows faster, more frequent scanning.

The tool follows OSS-Fuzz, a Google and Open Source Security Foundation effort running since 2016. Anthropic already sells Claude Security for broader code scanning and patching; OSS Scanner offers comparable audits free. Such work matters because widely used open-source code, often maintained by volunteers, can contain severe flaws like the XZ Utils backdoor.

Count? First para: Anthropic's(1) OSS(2) Scanner(3) is(4) an(5) opt-in(6), no-cost(7) service(8) that(9) regularly(10) examines(11) open-source(12) projects(13) with(14) the(15) company's(16) most(17) advanced(18) models(19). Its(20) findings(21) are(22) produced(23) without(24) human(25) review(26) or(27) triage(28), so(29) they(30) may(31) be(32) mistaken(33) or(34) invalid(35), though(36) this(37) approach(38) allows(39) faster(40), more(41) frequent(42) scanning(43). =43. Second: The(1) tool(2) follows(3) OSS-Fuzz(4), a(5) Google(6) and(7) Open(8) Source(9) Security(10) Foundation(11) effort(12) running(13) since(14) 2016(15). Anthropic(16) already(17) sells(18) Claude(19) Security(20) for(21) broader(22) code(23) scanning(24) and(25) patching(26); OSS(27) Scanner(28) offers(29) comparable(30) audits(31) free(32). Such(33) wo

Context

... No extra. Need maybe no bullet. Good. Need ensure no source phrasing copied. We used "opt-in" from source? Source says "opt-in vulnerability scanner" and "no cost" etc. "opt-in" is common but source phrase. They said never copying source phrasing. Could avoid exact phrases? "opt-in" maybe okay? But to be safe, "voluntary" instead of opt-in. "no-cost" source says "at no cost", "free". Fine. "human review or triage" source exact phrase. We used "without human review or triage" which is close. Need original wording. Could say "without people checking or sorting them." Better. "most advanced models" source "strongest models". Fine. "OSS-Fuzz" proper. "Open Source Security Foundation" proper. "Claude Security" proper. "code scanning and patching" source exact. Could rephrase "scanning and fixing code". "comparable audits free" okay. "widely used open-source code" source "widely used open-source code" exact? Source: "widely used open-source code" in summary? Actually full article: "open

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Engadget →
Related stories
Anthropic offers free vulnerability scanning for open-source code · Artificial intelligence
Anthropic rolls out no-cost OSS Scanner to flag flaws in open-source code · Cybersecurity
Sercomm and Broadcom launch set-top reference design built on RDK · Consumer gadgets
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Anthropic now offers a free vulnerability-finding service for open-source software.” Browse more stories.