Anthropic has released a free, AI-powered security scanner for open-source projects and expanded its Cyber Verification Program for professional testers.
Anthropic launched OSS Scanner, a service that employs its top-tier AI systems to detect security flaws in open-source code. Reports from this tool are fully model-generated, without human review or triage.
The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage. This will enable faster and more frequent scanning, but means that it is possible reports will be incorrect or invalid. These reports will be generated by our strongest models (including Claude Mythos) to give open-source projects the largest defensive advantage.
Anthropic said human validation has become a bottleneck in its vulnerability research. Those who join the program get regular scans and emails detailing potential bugs, steps to replicate them, and remediation advice if it exists.
Projects that sign up get a first scan and a set of reports via email. Later checks aim to spot fresh vulnerabilities and problems that previous reviews overlooked.
How often these later scans occur relies on variables like demand and project popularity. Maintainers may offer direction on testing targets, which inputs to view as hostile, severity ratings, and useful patch types.
Early AI reports about 18 months ago, before Project Glasswing, were appalling. The reports we received from Anthropic, raw model output included, were as good and sometimes better than what we get from people. Particularly when a report comes with a real exploit attached, that's basically job done for an engineer as you can verify it right away
Anthropic said it cannot guarantee the scanner will be perfect. The firm said that alerts might exaggerate risks or misinterpret a project's security premises.
What we know
- OSS Scanner reports are fully model-generated without human review.
- Unvalidated findings do not carry a mandatory 90-day disclosure deadline.
- Projects can pause automated reports or opt out entirely.
Still unclear
- The exact date the OSS Scanner service became available.
- How many projects have enrolled in OSS Scanner.
- The exact frequency of subsequent scans for enrolled projects.
There is no compulsory 90-day disclosure window for unverified results. A 90-day clock could start once maintainers are told of validation, should Anthropic confirm a report via its current coordinated disclosure scheme.
Projects can halt automated alerts or withdraw entirely, reverting to Anthropic's standard disclosure reports. The company said the tool suits teams already handling verified high and critical issues who have room to probe additional findings.
Those maintaining core code may submit requests via the GitHub repository for the OSS Scanner. Each application undergoes individual review, with priority given to established projects vital to user safety and infrastructure.
A surge in bug reports generated by AI is overwhelming certain open-source initiatives. Affected parties include Google and Linus Torvalds.
Anthropic is growing a scheme permitting screened cybersecurity experts to evaluate its strongest AI models with reduced protections. Partners in Project Glasswing identified at least 129,000 confirmed vulnerabilities from April through July.
Anthropic's own open-source scanning found 5,500 more vulnerabilities between April and October. More than 33,000 vulnerabilities have so far been rated critical or high severity.
Anthropic said the figures are likely an undercount. It anticipates the real effect is at least fivefold greater, given that the data stems from a survey involving a small group of partners.
Anthropic merged two initiatives from the last half-year into the updated Cyber Verification Program, or CVP. This new structure features three levels, each having distinct verification needs and security measures.
All three tiers provide Claude Opus 5.5, Sonnet 5.5, Mythos 5.1 and models released later. Anthropic said concerns arose in April when Claude Mythos Preview was revealed, suggesting AI might breach software prior to its protection.
CVP Tiers Comparison
Defense tier
Incident response and malware analysis
- Open to security teams and researchers
- Includes critical infrastructure operators
- Requires record of reported vulnerabilities
Red Team tier
Authorised penetration testing
- Adds red-teaming capabilities
- Only organisations can apply
- Higher verification requirements
Work like malware analysis and incident response falls under the Defense tier. Eligible applicants include researchers with a history of reporting bugs, open-source maintainers, critical infrastructure operators, and security teams.
Only organisations may apply for the Red Team tier, which includes authorised penetration testing and red-teaming. The Specialized tier imposes the least restrictions.
This level is limited to a select few organisations permitted to test systems critical to safety, including interbank transfer infrastructure, flight systems and power grids. Anthropic vets each member together with the US government, and existing Glasswing members will move into the Specialized tier.
