October 8, 2026
Anthropic launches OSS Scanner, a free AI vulnerability scanner for open source
Opt-in projects get periodic scans by Anthropic's strongest models, including Claude Mythos, with unreviewed reports, reproducers and patches sent straight to maintainers.
On October 8, 2026 Anthropic opened OSS Scanner, an opt-in service that scans open-source repositories for vulnerabilities at no cost. Anthropic says it was inspired by Google's OSS-Fuzz and draws on its experience in Project Glasswing.
The key difference from Anthropic's existing disclosures is speed. Over six months its models found more than 29,000 candidate vulnerabilities, but its team could manually review only about 6,000. Enrolled projects now receive model output as soon as it's ready, without human review. Each report contains a self-contained reproducer, an explanation including a bisection to the introducing change where possible, and a candidate patch.
Anthropic's pentesters checked 97 critical and high findings across 48 projects before launch: 85 (88%) met the bar for its coordinated disclosure process, 11 were real duplicates and one was a false positive. SecurityWeek reports Anthropic expects a true-positive rate above 90%.
Enrollment is through a pull request to github.com/anthropics/oss-scanner with a project.yaml and a Dockerfile; eligibility follows OSS-Fuzz-like criteria for critical projects. There is no disclosure deadline on unvalidated findings. On the same day Anthropic also announced the Critical Infrastructure Defense Program with 11 founding partners in operational technology security.
Our guide covers the details and includes a project.yaml generator.
Want to see what an AI audit finds in your project? Quick scans are free and take a few minutes.
Scan a repository