OSS Scanner is Anthropic’s new offer of free, periodic AI security scans for eligible open-source projects that opt in. Announced on October 8, the service uses the company’s strongest models, including Claude Mythos, to look for vulnerabilities. However, its reports arrive without human review or triage, leaving maintainers responsible for checking the findings and proposed fixes.
That trade-off is the point: Anthropic wants teams that can handle additional reports to receive them sooner. Each report includes a self-contained reproducer and an explanation, with a candidate patch when available. A reported vulnerability is still something to investigate, rather than a guarantee of a confirmed flaw or a safe patch.
Why Anthropic built OSS Scanner
Anthropic describes a human bottleneck. By its count, its latest models turned up more than 29,000 candidate vulnerabilities in important projects over six months. Its team has manually triaged only about 6,000. Meanwhile, some maintainers began asking for everything the models had found, validated or not. Anthropic says it has already sent nearly 5,000 such reports directly. OSS Scanner turns that request into an opt-in service.
Who can enroll in OSS Scanner?
According to the official FAQ, acceptance follows criteria similar to Google’s OSS-Fuzz. Anthropic favors established projects that matter to infrastructure and user security. It weighs their exposure to remote attacks and how many users or projects depend on them. It evaluates requests case by case and manually checks that applicants are core maintainers. Anthropic may adjust the criteria over time. It also asks maintainers to explain a project’s importance when that is not obvious.
To apply, a maintainer opens a pull request in Anthropic’s enrollment repository, adding a project directory and configuration. The setup needs the repository address, a primary contact and a Dockerfile that installs dependencies and builds the project. Maintainers can also supply a threat model to explain the intended security boundaries and severity rules.
The build stage has network access, but the subsequent security audit runs without internet access in an isolated virtual machine. Findings go to the configured email contacts. Those addresses appear in the public configuration. Anthropic recommends an address suitable for publication, such as a security alias.
Faster reports still need careful review
After an initial scan, the service checks projects again for newly introduced or previously missed vulnerabilities. Still, the FAQ promises no fixed schedule. Frequency can depend on demand, a project’s reach and other factors. Maintainers can pause reports or withdraw through another pull request.
Anthropic says an early evaluation examined 97 high- or critical-severity findings across 48 projects. Of those, 85 met its coordinated-disclosure standard; 11 duplicated real issues and one was invalid. Those company-reported results concern a selected set of serious findings, not a measured accuracy rate for every future report. Severity ratings and threat-model assumptions can also be wrong.
Anthropic’s launch post also publishes feedback from early testers it chose. Daniel Stenberg, who maintains curl, said:
OSS Scanner has helped us find multiple issues in curl worthy of addressing, including one of the worst curl vulnerabilities reported in the last few years.
Daniel Stenberg, curl
Todd Ouska of wolfSSL said all but two of the 74 reports received were valid. Five became CVEs. These are vendor-selected comments. They show what the service can do, not what every project will get.
Meanwhile, Anthropic will continue its human-verified disclosure process for projects that need it. Raw OSS Scanner findings have no automatic 90-day disclosure deadline. Anthropic says it will not make those unreviewed findings public. If Anthropic later validates a finding through that separate process, a disclosure clock can begin. According to the FAQ, it starts when the maintainer receives notice of human validation. The FAQ adds that Anthropic may later impose a disclosure period on some high-severity reports. Projects would get notice and an option to opt out.
Part of a broader defensive AI push
OSS Scanner is one branch of the Anthropic Cyber Mission. The other new branch brings Claude models, engineers and threat research to providers defending critical infrastructure. Partners include CrowdStrike, Dragos and Rockwell Automation. Our coverage of Gemini 4 Argon’s restricted rollout shows another case of advanced AI reaching vetted cyber defenders first.
Maintainers also have other routes to help. Anthropic’s Claude for OSS program offers free Claude Max 20x subscriptions for fixing vulnerabilities. Its Cyber Verification Program gives qualifying security professionals advanced cyber capabilities with reduced blocking classifiers.
For open-source teams, the practical question is capacity. Free scanning can surface more work. Maintainers still need time to reproduce bugs, judge their impact and test fixes.
