OSS Scanner評測:Anthropic免費抓漏洞,一半沒人審 | OSS Scanner Review: Anthropic Scans Code, Half Unchecked
By Kit 小克 | AI Tool Observer | 2026-10-09
🇹🇼 OSS Scanner評測:Anthropic免費抓漏洞,一半沒人審
OSS Scanner是Anthropic在2026年10月8日推出的免費漏洞掃描服務,用Claude的前沿模型幫開源專案掃描程式碼找安全漏洞,申請門檻不低,過去半年測試已揪出2.9萬個疑似漏洞,但真正經過人工覆核的只有6千筆左右。對開源維護者來說,這是免費資安外援,但報告品質到底可不可信,值得先搞清楚再申請。
OSS Scanner是什麼?
OSS Scanner是Anthropic Cyber Mission底下的一項服務:開源專案可以申請加入,Anthropic就會用Claude定期掃描程式碼庫,找出潛在安全漏洞。每份報告附上漏洞成因說明、概念驗證(PoC),以及建議修法;如果可行的話。靈感來自Google的OSS-Fuzz,差別是OSS-Fuzz做模糊測試(fuzzing),OSS Scanner靠的是語言模型讀程式碼邏輯抓漏洞。
開源專案怎麼申請OSS Scanner?
申請方式是發GitHub PR,但不是人人有獎。Anthropic篩選標準包括:專案是否對基礎設施或使用者安全有重大影響、是否暴露在遠端攻擊風險下、以及有多少其他專案或使用者依賴它。換句話說,你家那個50個star的side project大概排不到隊,這個服務主要照顧的是生態系裡「掛了會死很多人」的關鍵專案。
2.9萬個漏洞,為什麼只人驗6千筆?
這是整件事最該誠實講的地方。Anthropic過去半年用自家模型掃描核心開源專案,找出2.9萬個疑似漏洞,但人力只來得及覆核大約6千筆,其中高風險等級的有88%符合揭露標準——意味著就算是人工看過的子集,也有一成多是誤判。至於剩下的2.3萬筆沒人看過的呢?OSS Scanner還提供一個「快速通道」選項,讓專案直接收到模型生成、未經人工審核的報告。換句話說,你申請加入快速通道,等於自己當那個人工審核員,過濾模型的幻覺漏洞。
- 優點:免費、用的是Anthropic最強模型、報告附PoC和修法建議,省下請資安顧問的錢
- 缺點:申請門檻高、快速通道報告沒人把關、誤判率不是零
如果你維護的是依賴人數眾多的核心開源專案,OSS Scanner值得申請——免費資安稽核不嫌多。但如果你是收到快速通道報告,記得把它當成「AI產的線報」而不是「鑑定結果」,自己動手驗證再動刀。好不好用,試了才知道。
🇺🇸 OSS Scanner Review: Anthropic Scans Code, Half Unchecked
OSS Scanner is Anthropic's free vulnerability-scanning service, launched October 8, 2026, that uses Claude's frontier models to scan open-source codebases for security bugs. In six months of testing, it flagged 29,000 suspected vulnerabilities, but Anthropic's own team only had bandwidth to manually review about 6,000 of them. If you maintain an open-source project, this is free security help, but you should know exactly how reliable the reports are before applying.
What Is OSS Scanner?
OSS Scanner sits under Anthropic's new Cyber Mission initiative. Eligible open-source projects can enroll to get periodic scans of their codebase by Claude's strongest models. Each report includes an explanation of the bug, a proof-of-concept exploit, and a suggested fix where one exists. It is explicitly inspired by Google's OSS-Fuzz, except where OSS-Fuzz relies on fuzzing, OSS Scanner relies on an LLM reading code logic to spot flaws.
How Do You Apply for OSS Scanner?
You apply via a GitHub pull request, but not every project gets in. Anthropic's eligibility bar favors established projects with critical impact on infrastructure or user security: exposure to remote attacks, and how many other projects or users depend on it. Your 50-star side project probably is not the priority; this service is aimed at the load-bearing pillars of the open-source ecosystem.
29,000 Bugs Found, Only 6,000 Reviewed. Why?
This is the part worth being honest about. Over six months, Anthropic's models scanned core open-source projects and surfaced 29,000 candidate vulnerabilities, but humans only reviewed around 6,000. Of those reviewed, 88% of high-severity findings met disclosure criteria, meaning even in the human-checked subset, over 10% were false positives. As for the remaining 23,000 nobody looked at, OSS Scanner also offers an opt-in fast track that sends model-generated reports straight to maintainers with no human review at all. Opt into fast track, and you become the human reviewer filtering the model's hallucinated bugs.
- Pros: free, powered by Anthropic's strongest models, reports ship with a PoC and suggested fix, real money saved versus hiring a security consultant
- Cons: high eligibility bar, fast-track reports are unreviewed, false-positive rate is not zero
If you maintain a widely-depended-on open-source project, OSS Scanner is worth applying for. Free security audits never hurt. But if you get a fast-track report, treat it as an AI-generated tip, not a verified finding, and verify it yourself before you patch. You won't know until you try it.
Sources / 資料來源
- Anthropic: An opt-in vulnerability-finding service for open-source software
- Anthropic: Introducing the Anthropic Cyber Mission
- SiliconANGLE: Anthropic launches critical infrastructure program and free OSS Scanner
常見問題 FAQ
OSS Scanner是免費的嗎?
是,OSS Scanner完全免費,由Anthropic的Defender Advantage Fund出資,不需要付費訂閱Claude方案。
任何開源專案都能申請OSS Scanner嗎?
不是。Anthropic優先審核對基礎設施或使用者安全有重大影響、依賴人數多的既有專案,小型side project不是優先對象。
OSS Scanner的報告可以直接信嗎?
不建議。快速通道報告是模型生成、未經人工審核,過去半年2.9萬筆疑似漏洞中僅6千筆經人工覆核,誤判率並非零。
OSS Scanner和Google的OSS-Fuzz有什麼不同?
OSS-Fuzz靠模糊測試(fuzzing)找漏洞,OSS Scanner則是用Claude語言模型直接閱讀程式碼邏輯來抓安全漏洞。
延伸閱讀 / Related Articles
- Manus AI評測:中國擋下Meta併購後,估值翻倍募5億美元 | Manus AI Review: Blocked From Meta, Valuation Doubles to $4B
- Beam 501B評測:Reflection AI開源模型,省算力不是最強 | Beam 501B Review: Efficient Open Model, Not the Strongest
- Nano Banana 2.1評測:Google圖片生成砍半價更穩 | Nano Banana 2.1 Review: Google Halves Image Pricing
AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends
留言
張貼留言