AI Briefing
KOSign in

Anthropic launches OSS Scanner, an opt-in AI vulnerability-finding service for open-source software

·2026.10.09 04:00

Key point

The service provides free, periodic security scans by Anthropic's strongest models, including Claude Mythos, to open-source projects.

Details

Anthropic has launched OSS Scanner, an opt-in vulnerability-finding service for the open-source ecosystem. Informed by experience from Project Glasswing, the service provides thorough, periodic security scans by Anthropic's strongest models at no cost to participating projects.

Scaling Vulnerability Discovery

Language models have rapidly advanced in vulnerability discovery, with LLMs moving from finding under 20% of vulnerabilities on the CyberGym benchmark to over 85% this year. Anthropic has used its latest models to scan major software projects, discovering over 29,000 candidate vulnerabilities in the last six months. However, human capacity to validate these findings remains a bottleneck, with only approximately 6,000 manually reviewed. To address this, OSS Scanner offers a fast-track for maintainers who wish to receive reports as soon as they are available, even if unverified.

Model-Generated Reports and Validation

Unlike Anthropic's Claude Security product for enterprises, OSS Scanner is designed specifically for open-source projects. The outputs are fully model-generated without human review or triage, enabling faster scanning but carrying the risk of incorrect or invalid reports. Reports include self-contained reproducers, explanations, bisection data, and candidate patches. The scanner uses models including Claude Mythos to maximize defensive advantages.

Early Feedback and Accuracy

Anthropic validated the pipeline with dozens of open-source projects. In a test of 97 critical and high-severity vulnerabilities across 48 projects, 88% met the bar for Anthropic's coordinated vulnerability disclosure process. Only one finding was a false positive, while 11 were real but duplicated known issues. Feedback from maintainers at PostgreSQL, OpenSSL, wolfSSL, and HotCRP highlighted the high signal-to-noise ratio and the utility of included patches.

Eligibility and Enrollment

Core maintainers of eligible projects can enroll by submitting a pull request to the anthropics/oss-scanner GitHub repository. Eligibility criteria mirror those of Google's OSS-Fuzz, focusing on projects with a "critical impact on infrastructure and user security." Decisions are made on a case-by-case basis. Anthropic also notes that its Cyber Verification Program and Claude for OSS offer additional resources for security professionals and open-source remediation.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.