Telegram NewsSubmit game
Anthropic rolls out a free AI scanner for open-source projectsImage Source: The-decoder

Anthropic rolls out a free AI scanner for open-source projects

George Tsagkarakis 2 min read
Contents 5 sections
We may include affiliate links in our content, meaning we could earn a commission—or receive blockchain-based assets—if you click a link and make a purchase or take a specific action. Additionally, we use generative AI to help draft and refine our posts for clarity and grammar. All content is fact-checked and reviewed by a human editor before publication.

Anthropic is sending AI-written vulnerability reports to open-source maintainers, and no human will check them first. The company expects the reports to be more than 90 percent accurate. It also says they may contain errors.

A free scanner that skips human review

The tool is a free “OSS” AI scanner. It will regularly check open-source projects, flag vulnerabilities automatically, explain what it found and suggest patches.

This matters because nearly all modern software depends on open-source code. Much of that code is maintained by small volunteer teams who don’t have a security department behind them.

That’s also the problem. If a scanner is wrong almost 10 percent of the time, a two-person project still has to sort the real flaws from the false ones. Anthropic is offering the scanning for free, but checking the reports still costs the maintainers time.

Who can use it

Use of the scanner is opt-in. Maintainers of projects that are critical to infrastructure or user safety can sign up through GitHub. Anthropic hasn’t opened it to every repository.

The company’s argument is about which side has the tools. Attackers already have powerful AI models, Anthropic said, while defenders still lack comparable tools.

The bigger program behind it

The scanner is separate from Cyber Mission, a long-term Anthropic program to protect critical infrastructure and open-source software from cyberattacks.

Inside Cyber Mission sits the Critical Infrastructure Defense Program, or CIDP. It gives operators of power grids, water systems and transportation networks access to Claude models, Anthropic engineers and threat analysis.

The founding partners are CrowdStrike, Palo Alto Networks, Deloitte and Rockwell Automation. That’s two security vendors, a consulting firm and an industrial automation company, which suggests the program is aimed at large utility operators more than at hobby projects.

What maintainers should do

If you maintain a project that infrastructure or user safety depends on, signing up through GitHub won’t cost you anything. Just handle the first batch of reports the way you’d handle a pull request from a stranger. Reproduce each flaw yourself before you merge a suggested patch, because nobody at Anthropic will have checked it before it reached you.

Share this article
George Tsagkarakis

George Tsagkarakis, known as Staycalm4now is a professional author in the crypto gaming industry since early 2018. He has experienced all the growth of Blockchain Gaming and helped multiple projects achieve their goals and established a player base. He is the co-founder of egamers.io and now the Founder and owner of CryptoGames.gg He is also the COO of MyStage, an…

More from AI Safety & Ethics

Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted