Science & Tech · Cybersecurity · 2 days ago
Anthropic offers free AI vulnerability scans to open-source projects
Anthropic has launched OSS Scanner, a free service that periodically checks participating open-source projects for security flaws.
Open-source software is code that developers can use and build on, and many widely used services rely on it.
The scanner uses Anthropic’s strongest AI models, including Claude Mythos, and sends suspected flaws and possible fixes to project maintainers without human review.
That can help teams find problems sooner, but maintainers must check the findings because some may be incorrect or misjudge a flaw’s severity.
Anthropic says it has identified more than 29,000 possible vulnerabilities in major projects and manually reviewed a little over 6,000.
In an early test, penetration testers assessed 97 high- and critical-severity findings: 85 met the company’s coordinated disclosure criteria, 11 duplicated known issues or other findings, and one was invalid.
Core maintainers can apply through the OSS Scanner GitHub repository, and Anthropic says scan frequency will depend partly on demand and how widely a project is used.
Anthropic has launched OSS Scanner, a free, opt-in service that uses its AI models, including Claude Mythos, to scan open-source software for vulnerabilities.
Projects that join receive periodic, model-generated reports with explanations of suspected flaws, reproduction details and, when available, suggested fixes; the reports are not reviewed by humans before being sent.
Anthropic said it found more than 29,000 candidate vulnerabilities over six months, while its experts had manually reviewed about 6,000; The Hacker News reported that those findings had led to 584 advisories as of October 2, 2026.
In an assessment of 97 high- and critical-severity findings across 48 projects, Anthropic said 85 met its coordinated disclosure criteria, 11 were real but duplicative, and one was invalid.
Maintainers apply through the OSS Scanner GitHub repository, and Anthropic says it will assess applications individually, focusing on established projects important to infrastructure and user security.
Unvalidated reports do not have a mandatory 90-day disclosure deadline; if Anthropic later validates a report through its coordinated disclosure program, a 90-day period may begin when maintainers are notified.
- Who
- Anthropic and maintainers of open-source projects
- What
- Anthropic launched OSS Scanner, a free, opt-in AI vulnerability-scanning service.
- When
- Announced on October 9, 2026
- Where
- For open-source projects; applications are submitted through the OSS Scanner GitHub repository.
- Why
- To help open-source maintainers identify and fix security vulnerabilities, with faster reporting than a process requiring human review.
This story does not have two clearly opposing sides.
Projects that join will receive thorough, periodic security scans by our strongest models at no cost.
The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage.
The reports we received from Anthropic, raw model output included, were as good and sometimes better than what we get from people.
We can’t guarantee the scanner will be perfect.
Anthropic said it used its latest models to scan widely used open-source software and identified more than 29,000 candidate vulnerabilities.
Penetration testers assessed 97 high- and critical-severity findings across 48 projects; Anthropic reported that 85 met its criteria, 11 were genuine duplicates and one was invalid.
The Hacker News reported that Anthropic's findings had resulted in 584 advisories by this date.
Anthropic announced OSS Scanner as a free, opt-in vulnerability-scanning service for open-source projects.
- Service
- OSS Scanner, a free, opt-in vulnerability scanner for open-source projects
- Models
- Anthropic's strongest models, including Claude Mythos
- Candidate vulnerabilities
- More than 29,000 identified over six months
- Manual review
- About 6,000 findings manually reviewed, according to Security Affairs
- Assessment
- 97 findings across 48 projects: 85 met criteria, 11 were real duplicates, and one was invalid
- Advisories
- 584 as of October 2, 2026, according to The Hacker News
Sources
Anthropic scannt Open-Source-Projekte kostenlos auf Sicherheitslücken
Claude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning
Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects
Anthropic now offers a free vulnerability-finding service for open-source software











