Agents

Anthropic Debuts Free OSS Scanner Using Claude Mythos

Anthropic has released OSS Scanner, a free AI tool powered by Claude Mythos that detects security vulnerabilities in critical open-source software and delivers raw reports directly to maintainers.

AlphaSignal1 day agoAgents
Image: AlphaSignal

Anthropic has introduced OSS Scanner, an automated security service designed to uncover flaws in vital open-source projects. Powered by the company's advanced models, including Claude Mythos, the free, opt-in platform builds target software inside an isolated virtual machine, cuts off internet access after the initial setup phase, and deploys security agents against the codebase. Open-source maintainers can enroll by submitting a pull request containing a project.yaml file and a Dockerfile to the designated GitHub repository, provided their software meets OSS-Fuzz-style eligibility criteria focused on critical infrastructure.

The launch builds upon a six-month internal security initiative named Project Glasswing. During that period, Anthropic models uncovered more than 29,000 candidate vulnerabilities across major software codebases. While human researchers manually reviewed approximately 6,000 of those results, 88 percent of 97 critical or high-severity findings met the standard for Coordinated Vulnerability Disclosure. OSS Scanner opens this pipeline directly to maintainers, bypassing internal manual triage to accelerate security notifications.

Under the new service, reports are generated entirely by AI models without prior human review from Anthropic. Eligible project leads receive automated emails detailing suspected vulnerabilities and severity levels, alongside self-contained proof-of-concept reproducers, Git bisections identifying the introducing commits, and candidate patches when available. Project security contacts can also supply public keys to receive PGP-encrypted messages.

For software maintainers, this shift offers automated code analysis, but it transfers the burden of validation to project teams. Developers must independently evaluate raw model outputs to verify exploitability, gauge actual severity, and confirm that candidate fixes fit their project's threat model.

This is our own summary of reporting by AlphaSignal

More in Agents