Anthropic launches free AI security scanner that skips human review

Anthropic is letting its strongest AI models send unreviewed vulnerability reports directly to open-source developers.

Tools · Source: SecurityWeek

What happened

Anthropic just launched OSS Scanner. It is a free tool that uses their most capable AI models, including Claude Mythos, to hunt for security flaws in open-source software. Maintainers must explicitly opt in to get their projects scanned. The AI generates a comprehensive report for every bug it finds. Each report includes a self-contained proof of concept showing exactly how the exploit works. It also provides a timeline of when the bug was introduced and suggests a candidate patch to fix it.

The wild part is that these reports skip human review entirely. Anthropic made this choice because developers actually asked for raw AI outputs. Over the last six months, Anthropic models found over 29,000 candidate vulnerabilities across major software projects. Human reviewers could only process 6,000 of them, creating a massive bottleneck. Maintainers got tired of waiting. They asked Anthropic to send the remaining 5,000 unverified reports directly to them. Now, the AI just sends the data straight to the builders at machine speed.

Anthropic also launched the Critical Infrastructure Defense Program. They partnered with eleven major firms like CrowdStrike, Palo Alto Networks, Dragos, and Rockwell Automation. This program uses Claude models to defend operational technology like power grids, water systems, and transportation networks. These industrial networks often run on legacy code built to last for decades. They cannot be taken offline for patching without risking a total plant shutdown. Anthropic is deploying on-site engineers and threat research to help these providers secure unpatchable systems.

Key facts

Why it matters

This changes the speed of defense for anyone building software. Exploit development now takes minutes instead of months. If you wait for a human security researcher to verify a bug, you are already too late. By piping raw AI findings directly to maintainers, Anthropic gives open-source projects a fighting chance against automated attacks. You get a patch before a state-sponsored hacker even finds the hole. Defenders face severe resource shortages, but AI scales infinitely to fill that gap.

The second-order effect is a massive shift in trust toward AI accuracy. We are moving past the era where AI generated mostly garbage code and false positives. Anthropic tested 97 critical findings with expert penetration testers, and 85 of them were completely valid. Eleven others were real but duplicate issues. Only one was a false positive. When developers at wolfSSL received 74 raw AI reports, 72 were real bugs and five became official CVEs. AI is no longer just an attack vector. It is becoming the primary shield for the internet.

For builders

Fast-track patches for open-source maintainers

Core maintainers of critical open-source projects can enroll via GitHub. You get free, continuous audits from frontier models like Claude Mythos. You save thousands on security audits, but you must have the internal engineering bandwidth to triage raw reports.

New defense tools for critical infrastructure

Companies building security products for power grids or factories can join the new defense program. You get access to on-site engineers and Anthropic threat research. Legacy hardware vendors win big by using AI to secure systems that cannot go offline.

AI accuracy replaces human bottlenecks

Security teams lose their monopoly on bug discovery. AI models found 29,000 bugs in six months, crushing human review capacity. Companies paying for manual penetration testing will soon realize automated AI scans offer better speed and return on investment.

My take

I love that developers literally begged Anthropic to stop filtering the AI output. We spend so much time worrying about AI safety that we forget humans are the actual bottleneck in cybersecurity. Shipping raw, unreviewed bug reports is a bold move, but it is exactly how we beat hackers at their own game.

Original reporting: SecurityWeek. This is my rewrite and opinion.

More AI news for builders