Why Anthropic built it
Over six months Anthropic's models found more than 29,000 candidate vulnerabilities in important open-source software, but its security team could manually review only about 6,000. Many maintainers who received the first human-verified reports asked to simply get everything, unverified, with proposed patches — nearly 5,000 reports were sent that way.
OSS Scanner turns that into an opt-in fast track. Human-verified reports continue through Anthropic's coordinated vulnerability disclosure (CVD) process; enrolled projects additionally get raw model output as soon as it's ready. Anthropic says it was inspired by Google's OSS-Fuzz.
What maintainers receive
After enrollment the project is scanned and the maintainers receive a bundle of reports by email. Anthropic's pipeline includes agents that double-check bugs, propose patches and perform root cause analysis. Each report contains:
- a self-contained reproducer
- an explanation of the vulnerability, including a bisection to find when the bug was introduced where possible
- a candidate patch when one is available
Projects are rescanned regularly to catch newly introduced bugs and ones missed earlier. The frequency depends on how many projects are in the pipeline, how widely the project is used and other factors.
How accurate is it?
Before launch Anthropic's penetration testers checked 97 critical and high-severity findings across 48 projects. 85 (88%) met the bar for Anthropic's CVD process; 11 of the remaining 12 were real but duplicated known issues, and only one was a false positive. Anthropic expects a true-positive rate above 90% and warns that severity ratings can be inflated or the scanner can misunderstand a project's threat model.
Early participants were positive. wolfSSL reported that of 74 reports, all but two were valid and five became CVEs. Daniel Stenberg said it found one of the worst curl vulnerabilities in years; PostgreSQL, OpenSSL and HotCRP maintainers also praised the reports.
Who is eligible
Anthropic uses criteria similar to OSS-Fuzz: established projects with a critical impact on infrastructure and user security, judged case by case. Important factors are exposure to remote attacks (for example libraries that process untrusted input) and the number of users and dependent projects. If importance isn't obvious, add a short sentence explaining it.
Anthropic manually validates that the person applying is a core maintainer and may contact the project through other channels. The service is meant for projects that already keep up with verified high and critical reports — if your inbox is already overwhelmed, it may not be the right fit yet.
How to apply
Core maintainers open a pull request to github.com/anthropics/oss-scanner that adds projects/your-project/project.yaml, starting from the template in that repository.
Required fields:
- repo — the git URL to clone, optionally with #branch; it doesn't have to be on GitHub
- primary_contact — the email that receives every report
- Dockerfile — repo-relative path to a Dockerfile that installs dependencies and builds the project; or put a file named Dockerfile next to project.yaml and omit the field
Optional fields:
- auto_ccs — extra addresses copied on every report
- homepage — the project's website
- threat_model — path to your threat model, default .oss-scanner/threat_model.md
- pgp — a public key to encrypt report emails; when set, CCs are not allowed
- disabled — set to true to pause reports
Run tools/validate.py and build the Dockerfile locally before opening the PR. After acceptance Anthropic builds the image on its infrastructure and emails you if it fails.
The Dockerfile and offline audit
The Dockerfile is built with network access. Everything after that — the agents' audit — runs with internet access fully disabled inside hardened sandboxes. So the image must pre-install all dependencies and build the project. Anthropic recommends making sure the tests pass inside the container: that lets agents compile and run code to confirm bugs.
The threat model file
threat_model.md is optional and has no required format. It's your chance to tell the agents what isn't documented elsewhere:
- which code should be tested, which inputs are adversarial and what is out of scope
- a severity rubric for critical, high, medium and low
- how reports should look, whether patches should be minimal or merge-ready, which proofs of concept are useful
- how granular deduplication should be
Without it the scanner guesses. You can change the file between scans to change the reports. Our threat model builder generates a ready file.
Disclosure, pausing and attribution
There is no 90-day deadline on these unvalidated findings. If Anthropic later validates a report through its CVD program, it may disclose it 90 days after telling you a human has validated it. Anthropic says it may introduce deadlines for some high-severity reports in future, with notice and an opt-out.
To pause, add disabled: true to project.yaml in a PR; to leave, delete your projects/ directory. Feedback goes in replies to the report emails; if you're not enrolled, write to oss-scanner-questions@anthropic.com.
Credit is optional. Anthropic suggests a commit-message line such as “Discovered by Anthropic's OSS Scanner, as vulnerability ANT-2026-ABCD1234”.
Data security
Reports are handled like Anthropic's standard CVD findings: stored in an isolated, locked-down cloud project accessible only to the security staff who run the program.
OSS Scanner vs Claude Security
Claude Security is Anthropic's commercial product for enterprises to find and fix vulnerabilities in their own code. OSS Scanner is for open-source maintainers: it adds token-hungry, experimental harnesses to find deeper bugs, and Anthropic covers the full cost. Maintainers can also get free Claude Max 20x through Claude for OSS, and security professionals can apply to the Cyber Verification Program.
project.yaml generator
Fill in the fields to get a project.yaml in the format described in Anthropic's FAQ, plus the commands to open the pull request. Always check the current template in the repository before submitting.
Any public git host. The branch is appended as #branch.
The folder under projects/ in Anthropic's repository.
Usually your own email. Receives every report.
Repo-relative. Clear it if you place a Dockerfile next to project.yaml instead.
Optional, separated by commas.
Leave the default unless your file lives elsewhere.
Optional. Reports will be encrypted; CCs are then not allowed.
projects/my-project/project.yaml
repo: https://github.com/owner/project primary_contact: you@example.org Dockerfile: Dockerfile
Open the pull request
gh repo fork anthropics/oss-scanner --clone cd oss-scanner mkdir -p projects/my-project cp ~/Downloads/project.yaml projects/my-project/project.yaml python3 tools/validate.py git checkout -b enroll-my-project git add projects/my-project git commit -m "Enroll my-project in OSS Scanner" git push -u origin enroll-my-project gh pr create --repo anthropics/oss-scanner --fill
Requires the GitHub CLI (gh) and Python 3. Anthropic manually verifies that you're a core maintainer before accepting.
Sample Dockerfile
A starting point for a C/C++ project built with CMake. Adapt the packages and build commands to your project; the key is that everything is installed and built inside the image, because the audit runs offline.
FROM debian:bookworm
RUN apt-get update && apt-get install -y --no-install-recommends \
build-essential cmake git ca-certificates pkg-config \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /src
COPY . .
# Build everything and fetch all dependencies now:
# the audit itself runs with no network access.
RUN cmake -B build -DCMAKE_BUILD_TYPE=Debug && cmake --build build -j"$(nproc)"
# Optional, but recommended: make sure tests pass inside the image.
RUN ctest --test-dir build --output-on-failureQuestions about Anthropic's OSS Scanner
Is Anthropic's OSS Scanner free?
Yes. Anthropic covers the full cost of the scans for enrolled projects.
Does my project have to be on GitHub?
No. The repo field can point to any git host. Only the enrollment pull request goes to GitHub.
Are the reports reviewed by a human?
No. Fast-track reports are fully model-generated. Human-verified reports continue to arrive separately via Anthropic's CVD process.
What if my project isn't accepted?
You can scan it on ossscanner.org at any time and enroll here for weekly deep scans — any public repository qualifies.
How do I stop receiving reports?
Open a PR adding disabled: true to your project.yaml, or delete your project directory. You'll go back to only receiving human-verified CVD reports.