Anthropic Opens Free, Model-Only Vulnerability Scanning to Open Source Maintainers
Anthropic on October 8, 2026 launched OSS Scanner, a free, opt-in vulnerability-finding service that runs its most capable AI models against open-source software on a recurring basis. The company says the service is "informed by our experience using Claude to find vulnerabilities during Project Glasswing" — the research effort that previously surfaced thousands of flaws in major codebases using the Claude Mythos model family. OSS Scanner turns that research pipeline into a standing, no-cost service that any eligible maintainer can apply to join.
The launch is one half of what Anthropic calls its broader Cyber Mission, alongside a new Critical Infrastructure Defense Program aimed at operational technology — plants, substations, and water systems — where equipment often cannot be taken offline to patch known flaws for years at a time.
Program Details
| Attribute | Value |
|---|---|
| Service name | OSS Scanner |
| Announced | October 8, 2026 |
| Cost to maintainers | Free |
| Model(s) used | Anthropic's strongest available models, including Claude Mythos |
| Inspired by | Google's OSS-Fuzz |
| Informed by | Project Glasswing (Anthropic's AI vulnerability-research initiative) |
| Eligibility | Open-source projects with "critical impact on infrastructure and user security," reviewed case by case |
| How to enroll | Maintainer submits a pull request to the anthropics/oss-scanner GitHub repository with a config file and Dockerfile |
| Human review before delivery | None — reports are fully model-generated |
| Report contents | Self-contained reproducer, vulnerability write-up, bisection to the introducing commit (where possible), candidate patch (when available) |
| Scale so far (as of October 2, 2026) | 29,000+ candidate vulnerabilities found over six months; ~6,000 manually triaged by Anthropic; 584 advisories issued |
| Validity rate | 88% (85 of 97 critical/high findings validated by independent penetration testers); wolfSSL measured 72 of 74 (≈97%) |
| Early enrollment interest | 116 pull requests submitted to the scanner repo as of launch week |
How It Works
Enrollment and Eligibility
Participation is entirely voluntary and starts with a project's core maintainers, not outside researchers. To enroll, a maintainer opens a pull request against Anthropic's anthropics/oss-scanner GitHub repository containing a configuration file that specifies the project's git repository URL, a primary contact email, and a Dockerfile describing how to build and run the project in a sandboxed environment. Optional fields include additional contact emails, a project homepage, a GPG public key for encrypted communication, and a threat-model file to steer the scanner toward what actually matters for that codebase.
Anthropic evaluates applications using criteria it describes as similar to Google's OSS-Fuzz program: the project needs meaningful reach into infrastructure or user safety, and acceptance is a case-by-case engineering judgment rather than an automatic gate. Anthropic has said the bar may evolve as the service matures.
No Human Review Before Delivery
The defining — and most debated — design choice in OSS Scanner is that findings reach maintainers without any human triage on Anthropic's side first. That's a deliberate break from Anthropic's existing coordinated-disclosure process, where a security team reviews a model's output before it goes anywhere. Skipping that step is what makes frequent, periodic scanning of many projects at once possible — but Anthropic is explicit that it also means some reports "can still be incorrect." Maintainers become the first human reviewers of each finding, not Anthropic engineers.
Each report is still built to be self-contained: a reproducer the maintainer can run directly, a written explanation of the flaw, a bisection identifying the commit that introduced it where that's determinable, and — when the model can produce one — a candidate patch. Because reports aren't pre-validated, Anthropic doesn't start a mandatory 90-day coordinated-disclosure clock until a finding is manually confirmed real; once that happens, the standard 90-day timeline applies as it would for any other disclosure.
Attribution, Not Obligation
Anthropic isn't requiring anything from maintainers who act on a finding. If a team patches a bug OSS Scanner surfaced, Anthropic asks — but doesn't require — that the commit message include the report's ID, which the company uses to track the service's real-world impact.
Early Results and Partner Feedback
Anthropic spent several weeks validating the pipeline with dozens of open-source projects before the public launch, and says those pilot runs alone produced hundreds of bug reports, including multiple vulnerability chains that reached unauthenticated remote code execution. Maintainers who took part offered specific, attributed feedback in Anthropic's launch post:
| Project | Maintainer | Takeaway |
|---|---|---|
| PostgreSQL | Noah Misch | Reports included fixes usable "nearly as-is" |
| OpenSSL | Anton Arapov | Raw model output is "as good and sometimes better than what we get from people"; a report with a working exploit attached is "basically job done for an engineer" |
| wolfSSL | Todd Ouska | 72 of 74 reports were valid; five became tracked CVEs |
| curl | Daniel Stenberg | The scanner helped surface "one of the worst curl vulnerabilities reported in the last few years" |
Anthropic did not attach a CVE number or severity rating to the curl claim in its launch post, so that specific flaw cannot yet be independently verified — it is a maintainer quote, not a published advisory.
Why This Matters
The Manual-Triage Bottleneck
Anthropic's own numbers make the case for automation: across six months of scanning major projects, its models flagged more than 29,000 candidate vulnerabilities, but Anthropic's security team could only manually review and triage roughly 6,000 of them. That gap — not a shortage of findings — is what OSS Scanner is built to close. Removing human review from the delivery path doesn't make the underlying analysis better; it removes the bottleneck that was keeping most of it from ever reaching a maintainer.
A Capability Jump Anthropic Says Is Real
Anthropic points to the CyberGym benchmark as evidence the underlying capability has moved quickly: AI models reportedly went from finding fewer than 20% of benchmark vulnerabilities at the start of last year to more than 85% this year. If that trajectory holds, the triage bottleneck OSS Scanner addresses today will only grow — which is also Anthropic's argument for standing up a scalable, opt-in delivery mechanism now rather than later.
Free Access Changes Who Benefits
Unlike Claude Security — Anthropic's enterprise-facing, access-gated scanning and patching product for paying Claude customers — OSS Scanner costs nothing and targets the maintainers of critical open-source infrastructure, many of whom run security-sensitive projects (cryptographic libraries, web servers, databases) with minimal dedicated security staffing. That's the same population Google's OSS-Fuzz has targeted with fuzzing since 2016, and Anthropic is explicit that OSS Scanner is designed in that program's image.
Recommendations
For Open-Source Maintainers
- Check eligibility before applying. OSS Scanner is scoped to projects with meaningful infrastructure or user-safety impact — review the criteria in the
anthropics/oss-scannerrepository before submitting a pull request. - Treat every report as a lead, not a verdict. Because findings aren't reviewed by Anthropic staff before delivery, validate the reproducer yourself before assuming an issue is real, especially for severity ratings — Anthropic has acknowledged the model can occasionally misjudge a threat model or overstate severity.
- Use the bisection and candidate patch as a head start, not a merge-ready fix. Partners like PostgreSQL and OpenSSL reported patches close to usable, but maintainer review before merge remains essential.
- Credit report IDs in commit messages when you patch a finding. It's optional, but it's how Anthropic measures the program's impact, and it helps future researchers trace a fix back to its origin.
For Security Teams Consuming Open-Source Software
- Don't assume unreviewed reports mean no real risk. A project enrolled in OSS Scanner may be sitting on a genuine, high-severity finding before it's ever publicly disclosed — track security advisories for your critical dependencies closely as adoption grows.
- Watch for a wave of advisories as the program scales. With 116 projects already applying in launch week alone, expect advisory volume for enrolled dependencies to rise over the coming months.
For Enterprises Evaluating AI Security Tooling
- Understand the Claude Security vs. OSS Scanner split. Claude Security is the paid, enterprise product with a controlled interface; OSS Scanner is free, open-source-only, and delivers raw model output. They serve different populations and different risk tolerances — don't conflate the two when assessing AI vendor security claims.
Key Takeaways
- Anthropic launched OSS Scanner on October 8, 2026 — a free, opt-in vulnerability scanner for open-source projects, powered by its strongest models including Claude Mythos, and explicitly informed by its Project Glasswing research.
- Maintainers enroll by submitting a pull request to the
anthropics/oss-scannerGitHub repository with a config file and Dockerfile; eligibility criteria mirror Google's OSS-Fuzz, focused on projects with critical infrastructure or safety impact. - Reports are fully model-generated with no human review before reaching maintainers — faster and more frequent scanning, at the cost of occasional false or overstated findings.
- In six months of scanning, Anthropic's models surfaced over 29,000 candidate vulnerabilities, of which only about 6,000 could be manually triaged — the exact bottleneck OSS Scanner is designed to remove.
- Independent validation puts accuracy around 88% overall, with wolfSSL reporting 72 of 74 reports valid (five became CVEs); partners including PostgreSQL, OpenSSL, and curl gave the pilot positive marks.
- OSS Scanner is one piece of Anthropic's broader Cyber Mission, alongside a new Critical Infrastructure Defense Program targeting long-lived operational technology in utilities and industrial environments.
Sources
- Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects — The Hacker News
- An opt-in vulnerability-finding service for open-source software — Anthropic
- Claude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning — Security Affairs