Anthropic has opened enrollment for OSS Scanner, a free service that periodically examines eligible open-source repositories for security vulnerabilities using the company’s strongest AI models. The offer could give maintainers faster access to suspected bugs, reproducible test cases and proposed patches—but the speed comes with a crucial warning: reports delivered through this fast-track program are generated by AI and are not reviewed by a human before they reach a project.
The program was announced on October 8, 2026, as part of Anthropic’s broader cyber initiative. It is aimed at established open-source projects that have a meaningful effect on infrastructure or user security, not every small repository on GitHub. Applications are reviewed individually, and Anthropic says it will verify that the applicant is a core maintainer.
What OSS Scanner actually provides
Accepted projects receive recurring security scans at no charge. According to Anthropic’s launch documentation, its models look for flaws in a project’s source code and can produce a report describing a suspected vulnerability, a reproducer that helps demonstrate the issue and a proposed patch when one is available.
This is different from Anthropic’s normal coordinated vulnerability disclosure process. The company says it has manually reviewed more than 6,000 open-source vulnerability reports through that slower workflow. OSS Scanner is an optional fast track: enrolled maintainers receive model output shortly after a scan rather than waiting for Anthropic’s penetration testers to triage it first.
Anthropic says its strongest models, including Claude Mythos, are used for these scans. However, it has not published a guaranteed scan frequency, service-level agreement or fixed turnaround time. “Periodic” should therefore not be interpreted as a promise of daily, weekly or release-by-release coverage.
Early results look promising, but they are not a guarantee
Anthropic tested an early version by asking expert penetration testers to review 97 critical- or high-severity findings across 48 projects. The company reports that 85 findings, or 88%, met the threshold for its coordinated-disclosure process. Of the other 12, eleven were real issues that duplicated known bugs or other scan findings, while one was considered invalid.
Several participating projects reported useful results. Anthropic says wolfSSL found 72 of 74 reports valid and assigned CVEs to five findings, while the curl project described multiple actionable issues. These are encouraging company-supplied results, not an independent benchmark of every repository or programming language. Performance could vary with code quality, build complexity, documentation, test coverage and the threat model supplied by maintainers.
Independent coverage from The Verge also highlights the central tradeoff: AI can accelerate vulnerability discovery, but maintainers are already dealing with growing volumes of inaccurate or low-quality machine-generated bug reports. OSS Scanner’s value will depend not only on how many issues it finds, but on whether projects can efficiently verify and prioritize them.
Who can apply
Anthropic says eligibility broadly follows the approach used by Google’s OSS-Fuzz. It favors established projects with a critical effect on infrastructure and user security. Factors include whether the software processes untrusted input, whether it is exposed to remote attacks and how many users or other projects depend on it.
The company warns that this service is best suited to teams already capable of handling verified high- and critical-severity reports. A small volunteer project with little triage capacity may find a stream of unreviewed reports difficult to manage, even when the scanner is free.
Only a lead maintainer or someone authorized by the lead maintainer may enroll a project. Anthropic can approve or reject applications case by case and may contact a project through other channels to confirm that the applicant has authority.
How maintainers enroll a project
Enrollment is handled through the public Anthropic OSS Scanner repository. A maintainer opens a pull request containing a configuration file at projects/<project>/project.yaml. The required setup includes:
- The repository URL and optional branch.
- A primary maintainer contact email.
- A Dockerfile path—or a Dockerfile supplied beside the project configuration—that builds the software and installs its dependencies.
Maintainers can also provide extra contacts, a project homepage, a PGP key for encrypted reports and a threat-model file explaining which code and inputs matter most. Anthropic recommends testing the container locally first. The Dockerfile may download dependencies while it builds, but the scanning agent runs without internet access afterward inside a hardened sandbox.
A project can pause automated reports by setting disabled: true in its configuration or opt out by removing its project directory through another pull request.
The limitations matter as much as the price
OSS Scanner is free, but it is not a replacement for code review, dependency monitoring, fuzzing, penetration testing or a mature disclosure process. Anthropic’s service agreement says reports may miss vulnerabilities, identify harmless behavior as a bug, misjudge severity or propose a patch that breaks functionality. Maintainers are responsible for reviewing every finding and testing any patch before relying on it.
The reports may contain sensitive details about unpatched flaws and must be kept secure until remediation or disclosure. If Anthropic later validates a finding through its human-reviewed disclosure program, its standard policy may permit disclosure beginning 90 days after notifying the project.
The agreement also provides the service and reports “as is,” with no guarantee that every flaw will be found. Anthropic may change, suspend or end the service, and its stated total liability is capped at $1,000. Those terms reinforce a practical point: free access does not transfer security responsibility from the project to Anthropic.
Why this could matter beyond open-source maintainers
Most consumers will never apply to OSS Scanner, but they use phones, browsers, routers, cars and cloud services built on open-source components. Faster discovery of high-impact bugs could help reduce the time vulnerable code remains unnoticed across a broad software supply chain.
The immediate beneficiaries are maintainers with enough expertise to verify model output and patch responsibly. For them, OSS Scanner may add a capable second set of eyes without adding a subscription bill. For everyone else, the safer takeaway is measured: AI-assisted security scanning is becoming more accessible, but human judgment, testing and disclosure discipline remain essential.
