Anthropic launches free vulnerability scanner for eligible open-source projects
AI

Anthropic launches free vulnerability scanner for eligible open-source projects

TechNews Editorial
TechNews EditorialOct 9, 2026 · 1 min read
Share

Why it matters

Eligible maintainers can receive vulnerability findings sooner, though Anthropic says the unreviewed reports may contain errors.

The facts

  • Anthropic has launched free, opt-in OSS Scanner scans for eligible open-source projects.
  • Reports are model-generated and sent without human review, so some findings may be invalid.
  • Core maintainers can apply through Anthropic’s GitHub repository; eligibility is decided case by case.

Anthropic has launched OSS Scanner, an opt-in service that periodically scans eligible open-source projects for security vulnerabilities at no cost. It sends maintainers reports generated by its language models, including Claude Mythos, without waiting for human review.

The company says each report includes a way to reproduce the issue and an explanation of the vulnerability. It also includes a proposed patch when one is available and, where possible, identifies when the bug was introduced. Because the reports are not reviewed or triaged by people before delivery, some may be incorrect or invalid.

Anthropic tested reports with maintainers

Anthropic says it tested the scanning process with dozens of open-source projects over several weeks, sending hundreds of bug reports. In a separate check, expert penetration testers reviewed 97 critical and high-severity findings across 48 projects. Anthropic says 85 met the standard for its coordinated vulnerability disclosure process. Of the other 12, 11 were real issues that duplicated known problems or other scan findings, and one was invalid.

The service follows six months of scanning in which Anthropic says its models found more than 29,000 candidate vulnerabilities. Its team manually reviewed and triaged about 6,000 of them. Anthropic says it has also sent nearly 5,000 reports directly to maintainers who asked to receive all available findings, including unverified ones.

Security reviewers check vulnerability reports, assemble a verified stack, pair duplicate findings and cross out an invalid report.
Illustration: AI & Tech News

Anthropic says it will continue to disclose human-verified findings through its existing coordinated process, particularly for projects without the resources to assess reports themselves. OSS Scanner offers maintainers who can assess the findings a way to receive them sooner.

Core maintainers can apply by submitting a pull request to Anthropic’s GitHub repository using its project template. Anthropic says eligible projects should have a critical impact on infrastructure and user security, and it will decide eligibility case by case. The service is now available to more open-source projects.

Source: Anthropic

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading