Anthropic has launched OSS Scanner, an opt-in service that will run periodic, automated vulnerability scans of enrolled open-source projects using its Claude models at no charge to maintainers.

The company disclosed the programme on Thursday, describing it as "an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing." Participating projects, it said, "will receive thorough, periodic security scans by our strongest models at no cost."

Anthropic has not yet disclosed how often scans will run, what the enrolment criteria are, how submitted source code will be handled, or whether findings will be shared with third parties — questions that matter to maintainers working under restrictive licences, export controls, or with proprietary dependencies in their trees. Nor has it said whether it will operate a coordinated vulnerability disclosure process for flaws found in projects that are slow to patch. Those are the details to watch before treating the service as production-grade assurance.

An early-warning stream that runs in one direction

The opt-in model carries a structural consequence worth naming plainly. Once a project enrols, Anthropic holds advance knowledge of unpatched flaws in code that may sit inside critical enterprise dependency graphs — potentially weeks before any public advisory exists. That creates a private early-warning stream controlled by a single frontier lab, with the timing and terms of its release currently undefined. This is not a criticism of the programme's intent; it is what the opt-in structure necessarily produces, and it is why the disclosure question above is not a footnote.

Why the price point matters — and what it does not solve

For the long tail of open-source maintainers — often unpaid individuals or tiny teams stewarding libraries that quietly sit deep inside enterprise dependency graphs — zero cost and opt-in enrolment genuinely change the calculus. The history of supply-chain attacks, from XZ Utils to repeated npm and PyPI incidents, is a history of critical code maintained with almost no security budget. A scanner that costs nothing and requires no integration work lowers the barrier to entry to effectively zero, which is precisely why it may reach projects that commercial scanners never did.

But free scanning removes only the detection budget barrier. It does nothing for remediation capacity. A single-maintainer project that receives a dozen findings from Anthropic's strongest models has not become more secure on the day the report lands; it has acquired triage debt it has no funded hours to service. Without a paired remediation path — whether through coordinated disclosure support, patching assistance, or funding — increased discovery can degrade a small project's security posture rather than improve it, particularly where the gap between discovery and patch is measured in weeks.

A complement to CodeQL and oss-fuzz, not a replacement

It is worth being precise about what LLM-driven analysis can and cannot do relative to the tools that already dominate open-source security. GitHub's CodeQL performs deterministic, query-based static analysis: it is effective at pattern-matching known classes of flaw across large codebases with reproducible results. OSS-Fuzz, run under the Linux Foundation with Google's backing, continuously fuzzes parsers and adjacent code to surface memory-safety and crash bugs through brute-force input generation. Google's Big Sleep project has separately applied AI agents to real-world vulnerability research.

Anthropic has not specified OSS Scanner's target defect classes. However, the expected strength of LLM-based scanning lies in a different slice — logic flaws, authentication and authorisation gaps, and misuse of cryptographic or cloud APIs — precisely because that is how comparable LLM tools, including those used during Project Glasswing, have delivered results in practice: finding defects that pattern-matching and fuzzing routinely miss because there is no fixed pattern to match and no crash to observe. The trade-off is that probabilistic reasoning produces false positives. Findings from OSS Scanner should be read as leads to verify, not as confirmed vulnerabilities, and human triage remains mandatory.

There is also a systemic caveat. Any tool that raises the discovery rate of vulnerabilities in widely deployed libraries simultaneously widens the exposure window between discovery and patch — unless it is paired with disciplined coordinated disclosure. Anthropic's silence on that process remains the single biggest unanswered question in this launch.

What this means for Hong Kong teams

For IT and security teams across Hong Kong's banking, insurance, and critical-infrastructure sectors, the practical response is a dependency audit, not a press release. The steps:

  1. Build an SBOM. You cannot act on a scanner's findings for a library you do not know you depend on. Generate a software bill of materials for production systems and map it against the upstream projects enrolled in OSS Scanner and similar programmes.
  2. Keep internal SCA, static analysis, and fuzzing in CI. Third-party scanning does not replace your own pipeline; treat AI-generated findings as one additional input.
  3. Route upstream findings through your patch cycle. If a dependency you rely on is enrolled and receives a report, your upgrade path should not wait for the maintainer's convenience.
  4. Document the compliance question. Whether AI-generated scan results satisfy third-party software-assurance obligations under Hong Kong supervisory expectations is an open interpretive question. Regulated organisations should record their position on it now rather than improvise during an incident.

Editor's note: Anthropic's announcement was covered by The Hacker News; independent comment from open-source maintainers and Hong Kong security practitioners was not available at the time of publication. This article reflects publicly disclosed information only.


Anthropic 推出了 OSS Scanner,一項選擇性參與的服務,會免費為已登記的開源項目,以旗下 Claude 模型定期執行自動化漏洞掃描,維護者無需支付任何費用。

公司於星期四公布了該計劃,形容它是「一項選擇性參與的服務,源自我們在 Project Glasswing 期間運用 Claude 尋找漏洞的經驗」。公司表示,參與項目「將免費獲得我們最強模型所進行的全面、定期安全掃描」。

Anthropic 尚未披露掃描的運行頻率、登記準則、提交的源碼將如何處理,以及相關發現會否與第三方共享——這些問題對處於限制性許可證、出口管制之下,或其代碼庫中含有專有依賴項的維護者而言至關重要。公司亦未說明會否為修補進度緩慢的項目所發現的漏洞,運作一套協調式漏洞披露流程。在將此服務視為生產級安全保障之前,這些正是需要關注的細節。

單向流動的預警渠道

選擇性參與的模式帶來一個值得直言的結構性後果。一旦項目登記,Anthropic 便會先於公眾掌握代碼中尚未修補的漏洞資訊——這些代碼可能位於關鍵企業依賴關係圖譜深處,領先任何公開安全通告的時間可能長達數星期。這便形成了一條由單一前沿實驗室掌控的私人預警渠道,而其發布的時間與條款目前並無界定。這並非對計劃初衷的批評;而是選擇性參與結構必然產生的結果,亦正因如此,上述披露問題絕非一項附註。

為何收費模式關鍵——以及它無法解決什麼

對於處於長尾的開源維護者——往往是無償的個人或極小團隊,管理著靜靜嵌入企業依賴關係圖譜深處的函式庫——零成本與選擇性登記確實改變了成本效益的計算方式。從 XZ Utils 到接連發生的 npm 及 PyPI 事件,供應鏈攻擊的歷史,就是一部關鍵代碼幾乎在毫無安全預算下維護的歷史。一款零成本、無需任何整合工作的掃描器,把入門門檻實質上降至零,正因如此,它有可能觸及商業掃描器從來無法到達的項目。

然而,免費掃描只移除了檢測預算的門檻,對修復能力毫無幫助。一個單人維護的項目從 Anthropic 最強模型收到十幾項發現之日,並不會因此變得更安全;它只是獲得了一筆分類工作債務,卻沒有獲資助的工時去處理。如果沒有配套的修復途徑——不論是透過協調式披露支援、修補協助還是資金——增加發現量反而可能惡化而非改善小型項目的安全狀況,尤其當發現與修補之間的時間差以數星期計算時。

是 CodeQL 與 oss-fuzz 的補充,而非取代

有必要就 LLM 驅動的分析相對於現有主導開源安全領域的工具,能做與不能做什麼,作出準確說明。GitHub 的 CodeQL 執行的是確定性的、基於查詢的靜態分析:它善於在大型代碼庫中對已知漏洞類別進行模式匹配,結果可重現。OSS-Fuzz 由 Linux 基金會在 Google 支援下運作,透過暴力生成輸入持續對解析器及相鄰代碼進行 fuzz 測試,以浮現記憶體安全及崩潰類缺陷。Google 的 Big Sleep 項目則另行將 AI agent 應用於現實世界的漏洞研究。

Anthropic 並未指明 OSS Scanner 的目標缺陷類別。然而,預期 LLM 掃描的強項在於另一個範疇——邏輯缺陷、身份驗證與授權缺口、以及加密或雲端 API 的誤用——恰恰因為這正是同類 LLM 工具(包括 Project Glasswing 期間所使用的工具)在實踐中取得成效的方式:找出模式匹配與 fuzz 測試經常遺漏的缺陷,因為這類缺陷既無固定模式可供匹配,也無崩潰可供觀察。代價是機率式推理會產生誤報。OSS Scanner 的發現應被視為有待核實的線索,而非已確認的漏洞,人工分類仍然必不可少。

另有一項系統性問題需要注意。任何提升廣泛部署函式庫漏洞發現率的工具,都會同時擴大從發現到修補之間的暴露窗口——除非配合有紀律的協調式披露。Anthropic 對該流程的沉默,仍是此次發布中最大的單一未解問題。

這對香港團隊意味著什麼

對於香港銀行、保險及關鍵基礎設施行業的 IT 與安全團隊而言,務實的回應是一次依賴項審計,而非一份新聞稿。具體步驟如下:

  1. 建立 SBOM。 如果你不知道自己依賴某個函式庫,就無法對掃描器的發現採取行動。為生產系統生成軟件物料清單(software bill of materials),並與已登記參與 OSS Scanner 及類似計劃的上游項目進行對照。
  2. 在 CI 中保留內部 SCA、靜態分析與 fuzz 測試。 第三方掃描並不能取代你自己的 pipeline;應將 AI 生成的發現視為多一個輸入來源。
  3. 將上游發現納入你的修補周期。 若你所依賴的某個依賴項已登記並收到報告,你的升級路徑不應等待維護者方便時才行動。
  4. 記錄合規問題。 AI 生成的掃描結果能否滿足香港監管期望下的第三方軟件保證義務,是一個尚待解釋的開放問題。受規管機構應現在就記錄其立場,而非在事故發生時臨場應變。

編按:Anthropic 的公告由 The Hacker News 報導;出版時未能取得開源維護者及香港安全從業員的獨立評論。本文僅反映公開披露的資訊。

新聞來源 / Original News Source