Anthropic’s AI Flagged 29,000 Possible Software Vulnerabilities. Humans Checked Just 6,000

Anthropic's models flagged more possible software flaws than its reviewers could check. Its free new scanner changes who receives the unverified findings.

Anthropic says its AI models flagged more than 29,000 possible software vulnerabilities over six months. Its human reviewers could examine only about 6,000. On October 8, the company launched Anthropic OSS Scanner, a free service designed to send eligible open-source maintainers security findings before a human at Anthropic checks them.

The offer could shorten the time between discovering a dangerous bug and telling the people who can fix it. It also moves a difficult job onto projects that may already be stretched thin: deciding which machine-generated warnings deserve urgent attention.

What Anthropic OSS Scanner actually delivers

Accepted projects receive periodic scans from Anthropic’s strongest models, including Claude Mythos. According to the service FAQ, reports arrive by email with a description, a way to reproduce the suspected issue and a proposed patch when available. They are not human-reviewed before delivery. The scan schedule is not guaranteed.

Enrollment is not open to every developer seeking a free code audit. Core maintainers must submit a configuration through the project’s repository and pass eligibility checks focused on software with substantial infrastructure or user-security impact. Anthropic says it verifies maintainer status.

The accuracy numbers need context

In an early test, Anthropic’s reviewers examined 97 selected high- or critical-severity findings across 48 projects. The company says 85 met its coordinated-disclosure standard; 11 others were genuine but duplicated known or separately reported problems, and one was invalid. Those figures describe a selected, company-run evaluation—not a measured accuracy rate for every future report.

As The Verge notes, open-source maintainers are already grappling with floods of AI-generated bug reports. Faster detection is useful only if teams can reproduce, prioritize and patch findings safely. SiliconANGLE likewise points to the gap between finding a flaw and repairing it.

Who carries the risk?

Anthropic’s published policy imposes no automatic 90-day public-disclosure deadline on these unvalidated reports. Its separate, human-reviewed disclosure process remains in place. That gives maintainers room to investigate uncertain findings, but the new fast track does not guarantee that a warning is real, correctly rated or fixed.

The shift matters beyond security teams. Much of the software people use depends on open-source libraries maintained by small groups. If AI can discover suspected weaknesses faster than humans can verify them, the scarce resource is no longer just detection. It is the judgment—and time—needed to turn an alert into a reliable fix.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 403

Newsletter Updates

Enter your email address below and subscribe to our newsletter