Skip to content
ossscanner.org

About

About ossscanner.org

An independent, free AI vulnerability scanner for open-source projects, built for maintainers who don't qualify for — or can't wait for — invitation-only programs.

AI models have become genuinely good at finding security bugs. Anthropic's Project Glasswing showed it at scale, and on October 8, 2026 Anthropic opened OSS Scanner to critical open-source projects. Most of the open-source world isn't critical infrastructure by that definition, yet it still ships code that people depend on.

ossscanner.org brings the same approach to any public repository: a threat model, an AI audit of the riskiest code, a second agent that tries to disprove every finding, a root cause, the introducing commit and a candidate patch. Quick scans need nothing but a link. Maintainers can enroll for weekly deep scans by email.

Independence

We are not affiliated with, endorsed by or sponsored by Anthropic. We use Claude models through a public API, under the same usage policies as any other customer. The name describes what the service does — scanning open-source software — and our guide to Anthropic's program is written from public sources.

Principles

  • Help maintainers, don't burden them: concise reports, verified findings, a fix with every bug.
  • Never publish findings and never set disclosure deadlines.
  • Keep proofs of concept away from people who can't fix the code.
  • Be honest about limits: AI output can be wrong and a clean scan is not a certificate.

Contact

Questions, feedback, or a report about the scanner itself: hello@ossscanner.org.