Anthropic debuts free AI-powered vulnerability scans for open-source code

Anthropic has introduced OSS Scanner, a free service that periodically checks open-source projects for security flaws using its most capable AI models. Because the reports are generated entirely by models and are not reviewed by people, they may contain errors or invalid findings. The effort mirrors Google and OpenSSF's OSS-Fuzz and aims to help protect widely used open-source code.
Anthropic's OSS Scanner is an opt-in, no-cost service that regularly examines open-source projects with the company's most advanced models. Its findings are produced without human review or triage, so they may be mistaken or invalid, though this approach allows faster, more frequent scanning.
The tool follows OSS-Fuzz, a Google and Open Source Security Foundation effort running since 2016. Anthropic already sells Claude Security for broader code scanning and patching; OSS Scanner offers comparable audits free. Such work matters because widely used open-source code, often maintained by volunteers, can contain severe flaws like the XZ Utils backdoor.
Count? First para: Anthropic's(1) OSS(2) Scanner(3) is(4) an(5) opt-in(6), no-cost(7) service(8) that(9) regularly(10) examines(11) open-source(12) projects(13) with(14) the(15) company's(16) most(17) advanced(18) models(19). Its(20) findings(21) are(22) produced(23) without(24) human(25) review(26) or(27) triage(28), so(29) they(30) may(31) be(32) mistaken(33) or(34) invalid(35), though(36) this(37) approach(38) allows(39) faster(40), more(41) frequent(42) scanning(43). =43. Second: The(1) tool(2) follows(3) OSS-Fuzz(4), a(5) Google(6) and(7) Open(8) Source(9) Security(10) Foundation(11) effort(12) running(13) since(14) 2016(15). Anthropic(16) already(17) sells(18) Claude(19) Security(20) for(21) broader(22) code(23) scanning(24) and(25) patching(26); OSS(27) Scanner(28) offers(29) comparable(30) audits(31) free(32). Such(33) wo
... No extra. Need maybe no bullet. Good. Need ensure no source phrasing copied. We used "opt-in" from source? Source says "opt-in vulnerability scanner" and "no cost" etc. "opt-in" is common but source phrase. They said never copying source phrasing. Could avoid exact phrases? "opt-in" maybe okay? But to be safe, "voluntary" instead of opt-in. "no-cost" source says "at no cost", "free". Fine. "human review or triage" source exact phrase. We used "without human review or triage" which is close. Need original wording. Could say "without people checking or sorting them." Better. "most advanced models" source "strongest models". Fine. "OSS-Fuzz" proper. "Open Source Security Foundation" proper. "Claude Security" proper. "code scanning and patching" source exact. Could rephrase "scanning and fixing code". "comparable audits free" okay. "widely used open-source code" source "widely used open-source code" exact? Source: "widely used open-source code" in summary? Actually full article: "open