Security/ ai · open-source · security · anthropic

Anthropic's New Scanner Finds Bugs, Skips the Human Check

Anthropic will run free, AI-only security scans on opted-in open-source projects, but the model-generated reports get no human review before they land.

Anthropic is offering to scan open-source projects for security flaws for free, as long as maintainers are fine with getting zero human review of the results.

The new service, called OSS Scanner, is opt-in only. Projects that sign up get what Anthropic calls thorough, periodic security scans run by its strongest models, at no cost. Every report is fully model-generated: no human reviews or triages the findings before maintainers see them. Anthropic says cutting humans out of the loop allows for faster and more frequent scanning, though it also means some reports will be incorrect or simply invalid.

For under-resourced maintainers, the pitch is more eyes on their code without hiring a security team they can't afford. But unreviewed AI output is also exactly the kind of thing that creates alert fatigue: a maintainer who spends an afternoon chasing a hallucinated vulnerability report ends up worse off than one who got no scan at all.

Automated vulnerability hunting is not new. Google has used fuzzing and, more recently, large language models for similar work for years. Anthropic's twist is handing maintainers the raw, unreviewed output and trusting them to sort out what's real.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →