Anthropic launched a new service called OSS Scanner to help open-source projects find security vulnerabilities. The company announced that participating projects will receive thorough and periodic security scans by its strongest models at no cost. This initiative aims to alert developers about possible security issues much sooner than traditional methods allow.
The new offering relies entirely on artificial intelligence without human oversight. Anthropic stated that the outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage. This approach enables faster and more frequent scanning across participating codebases.
The lack of human review introduces a specific trade-off for developers. Anthropic explicitly noted that it is possible reports will be incorrect or invalid due to the automated nature of the tool. To maximize effectiveness, these reports will be generated by the company's strongest models, including Claude Mythos, to give open-source projects the largest defensive advantage.
Artificial intelligence tools hunt bugs
OSS Scanner enters a crowded field of automated security helpers. Artificial intelligence tools have helped find several major security flaws in open-source software over recent months. One notable example includes the Copy Fail bug that impacted nearly every Linux distribution in May.

At the same time, software maintainers face new operational pressures from automation. Some open-source projects are struggling to keep up with the sudden onslaught of AI-generated bug reports. Prominent figures and organizations, including Linus Torvalds and Google, have experienced this influx of automated findings.
Anthropic continues to deploy its models for defensive software tasks. The company expects the new scanner to help developers secure complex codebases against evolving threats.
Participating open-source maintainers must now decide whether to opt into the automated scanning service.



