Anthropic is sending AI-written vulnerability reports to open-source maintainers, and no human will check them first. The company expects the reports to be more than 90 percent accurate. It also says they may contain errors.
A free scanner that skips human review
The tool is a free “OSS” AI scanner. It will regularly check open-source projects, flag vulnerabilities automatically, explain what it found and suggest patches.
This matters because nearly all modern software depends on open-source code. Much of that code is maintained by small volunteer teams who don’t have a security department behind them.
That’s also the problem. If a scanner is wrong almost 10 percent of the time, a two-person project still has to sort the real flaws from the false ones. Anthropic is offering the scanning for free, but checking the reports still costs the maintainers time.
Who can use it
Use of the scanner is opt-in. Maintainers of projects that are critical to infrastructure or user safety can sign up through GitHub. Anthropic hasn’t opened it to every repository.
The company’s argument is about which side has the tools. Attackers already have powerful AI models, Anthropic said, while defenders still lack comparable tools.
The bigger program behind it
The scanner is separate from Cyber Mission, a long-term Anthropic program to protect critical infrastructure and open-source software from cyberattacks.
Inside Cyber Mission sits the Critical Infrastructure Defense Program, or CIDP. It gives operators of power grids, water systems and transportation networks access to Claude models, Anthropic engineers and threat analysis.
The founding partners are CrowdStrike, Palo Alto Networks, Deloitte and Rockwell Automation. That’s two security vendors, a consulting firm and an industrial automation company, which suggests the program is aimed at large utility operators more than at hobby projects.
What maintainers should do
If you maintain a project that infrastructure or user safety depends on, signing up through GitHub won’t cost you anything. Just handle the first batch of reports the way you’d handle a pull request from a stranger. Reproduce each flaw yourself before you merge a suggested patch, because nobody at Anthropic will have checked it before it reached you.
Free crypto, NFTs & new crypto games, before everyone else
Airdrops, free games and launches the day they drop. One email, no spam, unsubscribe anytime.














