Skip to content
ossscanner.org
Anthropic just launched OSS Scanner — here is an alternative open to every project

Find real vulnerabilities in your open-source project

Paste a public repository link. AI agents map the attack surface, audit the riskiest code and then try to disprove every finding. You get a private report with verified bugs, root cause, the commit that introduced each one and a candidate patch.

$
Try:
  • Free, no sign-up
  • Second agent verifies every finding
  • Patch + introducing commit
  • Markdown, JSON and SARIF export

What you get

A report written for maintainers, not a wall of warnings

The scanner follows the same playbook that projects like curl, OpenSSL and the Linux kernel ask from AI bug reporters: verified, short, reproducible and with a fix.

Verified findings

A separate verifier agent re-reads the code and actively tries to prove each finding wrong. Candidates it can't defend are dropped and counted, not shown.

Reproducer

A concrete input or test that triggers the bug. Shown only after you prove you maintain the repository, so reports can't be turned into ready-made exploits.

Root cause

Why the code is wrong, not just where. Duplicates of the same underlying bug are merged into one report.

Introducing commit

git blame on the vulnerable lines points to the commit that most likely introduced the bug, ready for a Fixes: tag and for working out affected releases.

Candidate patch

A minimal unified diff you can review, apply with git apply and adapt. Download it as a .patch file.

SARIF, JSON, Markdown

Upload SARIF to GitHub code scanning, feed JSON into your tooling or paste Markdown into a private advisory.

Pipeline

Five stages, the same shape as Anthropic's scanner

We never run your code. The repository is cloned with hooks and symlinks disabled, read as text and deleted after the scan.

How it works in detail
  1. 01

    Clone

    Shallow clone of the branch you choose over HTTPS, with git hooks, symlinks and non-HTTPS transports disabled.

  2. 02

    Map and threat model

    Inventory of every source file, ranked by risky sinks. Reads your threat_model.md and SECURITY.md, or drafts a threat model when there is none.

  3. 03

    Audit

    A strong reasoning model reviews the riskiest files in large batches with line numbers, looking for memory-safety, injection, auth and logic bugs.

  4. 04

    Verify and fix

    Every candidate goes to a second agent that tries to disprove it, then writes the root cause, a reproducer and a minimal patch.

  5. 05

    Report

    Deduplicated findings with severity, CWE, introducing commit and exports. The report lives at a private, unguessable link.

For maintainers

Enroll your project for weekly deep scans

Anthropic's OSS Scanner accepts only critical, widely used projects and asks for a pull request plus a Dockerfile. Ours is open to any public repository: fill in a form, prove you have write access and get deep scans by email.

Enroll a project
  • Deep scans with the strongest model and a larger audit budget
  • Automatic rescans every week when new commits land
  • Reports by email to you and up to 5 co-maintainers
  • Your threat model is used on every scan — edit it any time

Built responsibly

Designed not to add to maintainers' load

AI bug reports have flooded security inboxes. We follow the rules projects have published for AI-assisted reports.

Reproducers stay locked

Anyone can scan a public repo, but proof-of-concept inputs are revealed only to people who can commit to it.

Reports are private

Each report has a random link, is never indexed and is not listed anywhere. We don't publish findings.

Your code never runs

Static reading only: no builds, no install scripts, no network calls from the repository.

No disclosure clock

We never set a 90-day deadline on model-generated findings. What you do with them is up to you.

Read the disclosure policy

Compare

How it compares

Anthropic's OSS Scanner and Google's OSS-Fuzz are excellent programs for critical infrastructure. ossscanner.org covers everything else.

ossscanner.orgAnthropic OSS ScannerOSS-Fuzz
Who can use itAny public repositoryCritical projects, accepted case by caseCritical projects, accepted case by case
How to startPaste a link; enroll with a formPull request with project.yaml and a DockerfilePull request with build scripts and fuzz targets
First resultsMinutesAfter manual maintainer validation and buildAfter integration and fuzzing time
EngineFrontier LLMs (Claude Opus / Sonnet)Anthropic's strongest models, incl. Claude MythosCoverage-guided fuzzers
False-positive controlIndependent verifier agent per findingMulti-agent double-check, no human reviewCrashes are reproducible by design
OutputWeb report, email, Markdown, JSON, SARIFEmail bundleIssue tracker
PriceFreeFreeFree
Full comparison with CodeQL, Semgrep and others

FAQ

Common questions

All questions
Is it really free?

Yes. Quick scans are free for any public repository and enrolled projects get free weekly deep scans. We cap the total daily budget, so on very busy days new scans may have to wait until the next day.

Is this the same as Anthropic's OSS Scanner?

No. It is an independent service inspired by the pipeline Anthropic described: threat model, AI audit, a second agent that double-checks findings, root cause, introducing commit and a candidate patch. It uses Claude models through a public API, not Anthropic's internal harness, and is not affiliated with Anthropic.

Who can see my report?

Only people who have the link. Reports are not listed, not indexed and not published. Reproducers are hidden until someone proves write access to the repository.

Should I apply to Anthropic's program as well?

If your project is critical infrastructure, yes — their models and harnesses go deeper. Our guide explains eligibility and generates the project.yaml for your pull request.

News

AI vulnerability research, tracked