Anthropic has launched OSS Scanner, a free opt-in AI-powered vulnerability scanning service for open-source projects that offers thorough, periodic security scans by its strongest models at no cost.[2][3][11] Announced on October 8, 2026 as part of Anthropic’s broader Cyber Mission effort, the service is designed to help maintainers uncover and remediate bugs before attackers exploit them.[2][12][15]
OSS Scanner builds enrolled projects in isolated virtual machines without internet access, then uses Anthropic’s frontier language models, including Claude Mythos, to analyze the code for potential security issues.[1][2][3][11] For each suspected vulnerability, the system emails maintainers an automated report that includes an explanation, a proof-of-concept reproducer and, where feasible, a suggested patch.[1][2][3][5] Anthropic emphasizes that these reports are fully model-generated with no human review or triage, which speeds up scanning but means maintainers must validate findings and decide which issues to prioritize.[2][3][11][4]
The program is currently focused on open-source projects whose compromise could seriously impact critical infrastructure or end-user security, with eligibility criteria modeled on initiatives like Google’s OSS-Fuzz.[2][12][13] Core maintainers of qualifying projects can request enrollment by submitting a pull request to Anthropic’s OSS Scanner repository that adds a project configuration file and primary contact details.[1][3][2][8] Anthropic retains discretion to approve or withdraw projects from the service, and participants must agree to terms governing how source code and automated reports are handled.[7][1][3]
OSS Scanner grew out of Anthropic’s experience using its Claude models during Project Glasswing, an internal effort to systematically search widely used open-source software for vulnerabilities.[2][3][15] By offering targeted, free scanning to maintainers, Anthropic is attempting to scale that research-style work into a standing defensive capability for the open-source ecosystem.[2][4][11] The company explicitly cites Google’s OSS-Fuzz as inspiration but positions OSS Scanner as complementary, relying on AI code analysis and suggested fixes rather than classical fuzzing alone.[2][12][13]
Early interest appears strong, with projects such as Ethereum client developer Nethermind and Bitcoin and Lightning wallet ZEUS among the open-source teams that have already applied to participate.[15] Security teams and maintainers who opt in gain another source of telemetry on potential flaws, but Anthropic cautions that some AI-generated reports may turn out to be incorrect or non-exploitable and should be treated as leads rather than confirmed vulnerabilities.[2][3][11][4] Responsible disclosure practices remain unchanged: verified issues must still be tracked, assigned CVEs where appropriate, and communicated via project advisories or platforms such as NVD and CISA.[2][4][11]
Maintainers interested in the program are encouraged to assess whether their projects meet Anthropic’s impact criteria, review the OSS Scanner terms, and plan how to incorporate AI-generated findings into existing testing, SAST, and fuzzing workflows.[1][2][7][12] Used thoughtfully, OSS Scanner could help overburdened open-source teams surface subtle bugs and hard-to-reach attack paths faster, while keeping human experts firmly in charge of risk assessment and remediations.[2][3][4][11]
References
- oss-scanner – anthropics – GitHub
- An opt-in vulnerability-finding service for open-source software
- OSS Scanner – Frontier Red Team
- Anthropic offers free AI security scans to open-source maintainers
- Anthropic on X: “We’re launching the Anthropic Cyber Mission …
- OSS Scanner Terms & Conditions
- Anthropic OSS Scanner: AI Security Scans for Open Source
- Anthropic launches free AI security scans for open-source projects
- Anthropic、サイバー防御の新たな取り組み「Cyber Mission」 OSS …
- Anthropic 推出 OSS Scanner:用 AI 为开源软件免费扫漏洞
- Today in Crypto: NY-Wyoming Pact, Binance EU Scrutiny …
