Anthropic OSS Scanner: what it is and how to enroll
2026-10-09 · 4 min read
Anthropic OSS Scanner is a free, opt-in service that uses Anthropic's strongest models, Claude Mythos among them, to scan open-source projects for security holes on a recurring schedule and email the maintainers a report. To enroll, a core maintainer opens a pull request to the anthropics/oss-scanner GitHub repository, and Anthropic decides case by case which projects get in.
The post
On October 8, @AnthropicAI announced it with a short post: "To secure open-source software, we're launching OSS Scanner." The rest of the post says scans of opted-in projects will run "at no cost," and each report comes with a proof of concept, an explanation and a suggested fix. The post passed 450,000 views within a day.
The next morning @mark_k helped spread it, calling it "a FREE AI-powered vulnerability scanning service for open-source projects." His post leaned on the two numbers from Anthropic's write-up that people kept repeating, which I get to below.
What OSS Scanner actually does
According to Anthropic's announcement, the model is Google's OSS-Fuzz, with one difference: OSS-Fuzz throws random inputs at code, and this throws a language model at it. The scanner builds your project inside an isolated VM, cuts it off from the internet, and goes hunting.
Each report includes a self-contained reproducer and an explanation of the bug. Where it can, it bisects the history to show when the bug was introduced, and it attaches a candidate patch when it has one.
The catch is that no human reviews these reports before they reach you. Anthropic says plainly that some will be wrong. Because of that, findings carry no 90-day disclosure clock, and Anthropic doesn't publish them. Its separate, human-verified disclosure process keeps running, and OSS Scanner is pitched as an optional fast track for maintainers who want findings as soon as they exist.
The numbers behind it
Anthropic says that over the past six months its models turned up more than 29,000 candidate vulnerabilities, and its people could manually review only about 6,000. That backlog is why this exists. The models were finding more than people could check.
On quality, expert penetration testers looked at 97 critical and high-severity findings across 48 projects. 85 of them (88%) met Anthropic's disclosure bar. Of the other 12, 11 were real but duplicates and one was a false positive. Anthropic also says models went from finding under 20% of the vulnerabilities on the CyberGym benchmark early last year to over 85% this year.
The maintainer quotes are what make me take it seriously. curl's Daniel Stenberg says it "has helped us find multiple issues in curl worthy of addressing." PostgreSQL's Noah Misch says several reports "came with fixes we can use nearly as-is." Anthropic also reports complaints: inflated severity ratings, and a scanner that sometimes misreads a project's threat model.
How to enroll
The repository README lays out a short process:
- Add a
projects/<name>/folder with aproject.yaml(your repo URL and a security contact email) and aDockerfilethat builds the project and fetches everything the tests need. - Add a
threat_model.md. It's optional, but strongly recommended, and it's the place to head off the severity complaints by spelling out what counts as critical for your project. - Run
tools/validate.pyandtools/checklocally, then open the pull request.
Reports go out by email. If you want them encrypted, add a PGP key. If the volume gets to be too much, setting disabled: true pauses them.
Is it free? Yes, for projects Anthropic accepts. It's aimed at established projects with real infrastructure and security impact, so not every hobby repo will get in. Anthropic keeps this separate from Claude Security, its paid product for scanning company code.
My read
This is a good move, and the threat model file is the smartest part of it. A scanner that doesn't know what your software is for will flag the wrong things. Asking maintainers to write that down first is how you keep AI reports from becoming the spam that open-source projects already complain about.
The less comfortable point is the CyberGym jump. If defenders' models find 85% of known bugs, attackers' models are not far behind. We've written about open models that write exploits, and the window between a bug being found and someone using it keeps getting shorter.
What it means for a small business
You probably don't maintain an open-source project. But your website and the tools you run the business on are built from them. When more of those bugs get found and fixed, the fixes only help you if your vendors ship them and somebody actually applies the updates.
So the practical step is boring: know what software you run, who keeps it updated, and how fast. If that list lives in nobody's head, New Face Design's free process audit is a good place to write it down.