Loading prices...
All news
Conveyor belt carrying four identical blank reports with nobody beside it

Anthropic OSS Scanner sends model-generated reports with no human review

11:00 · 09.10.2026
Source: The Verge
4

Anthropic launched OSS Scanner on 8 October, a free vulnerability-finding service for open-source projects. Maintainers enrol by opening a pull request. Scans run periodically on Anthropic's strongest models, Claude Mythos among them.

“The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage”

— Anthropic, Анонс 8 октября 2026

Opt-in is the whole design

Google froze its open-source bug bounty on 1 October because of «a significant rise in automated submissions, the vast majority of which are not valid». Seven days later Anthropic shipped a service that generates vulnerability reports with a model and sends them without triage.

The difference is who asked. Google's inbox was open to anyone with a form. OSS Scanner reaches a maintainer only after that maintainer submits a pull request with a project.yaml and a Dockerfile. A maintainer who enrolled is reading reports they asked for.

The Anthropic OSS Scanner inherits the problem that froze Google's programme and answers it with consent instead of filtering. A vulnerability report written by an LLM reads like one written by a person, so triage costs the same either way. What changes is whether the recipient volunteered for the reading.

The accuracy number, as Anthropic published it

In validation, 97 critical and high-severity findings went through Anthropic's process and 85 of them met the bar for coordinated disclosure. That is 88%, and it means 12 did not.

Coverage has rendered this as a forecast of above 90%. The company's own text reports a measured 88% on a sample of 97, which is a different claim and a smaller one. A maintainer enrolling should expect roughly one report in eight to miss the bar, including wrong severity ratings.

The human review still exists elsewhere

Anthropic keeps its existing coordinated vulnerability disclosure process for externally reported bugs: «We will continue to manually disclose human-verified vulnerability reports». The no-review arrangement applies to projects that enrolled, and nowhere else.

Eligibility follows the criteria OSS-Fuzz uses, which limits the service to projects with critical impact on infrastructure and user security. The scanner sits alongside a second programme putting Anthropic models and onsite engineers into companies defending power grids and water systems, both under a banner the company calls the Anthropic Cyber Mission. The timing lands in a week when AI tooling turned up in the Korean bank breaches on the other side of the same equation.

What to watch

The measurement that matters comes later: whether enrolled maintainers stay enrolled after a quarter of model-generated reports. A false positive costs the person reading it, and a true one benefits everybody downstream.

Informational material, not investment advice. The accuracy figure comes from Anthropic's own validation sample and describes that sample, not future output.

Published: 11:00 · 09.10.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!

The market talks all day. We write when it says something

Short, and it tells you why it came