Anthropic Offers Free AI Security Scans to Open-Source Projects
Anthropic has unveiled OSS Scanner, an opt-in service designed to help secure the open-source software that many businesses rely on. Projects that join receive periodic security scans from the company's strongest models, including Claude Mythos, at no cost. The service draws on Anthropic's experience using Claude to find vulnerabilities during Project Glasswing. Project selection is expected to use criteria similar to Google's OSS-Fuzz, though Anthropic says this may change over time.
The reports will be fully model-generated and will not require human review or triage, which Anthropic says allows faster and more frequent scanning. Core maintainers enrol by opening a pull request on the scanner's GitHub repository with a YAML configuration file. A Dockerfile sets up the project's environment so the agent can run its audit without internet access. As of writing, 116 pull requests had been submitted.
Because automated findings may include false positives, Anthropic does not plan to apply a 90-day disclosure period to these reports. If a report is later validated by a human through its existing coordinated vulnerability disclosure program, it may be disclosed 90 days after the maintainer is told of that validation. Anthropic says it has identified more than 29,000 candidate vulnerabilities in important software projects. A little more than 6,000 have been reported to maintainers, resulting in 584 advisories as of October 2, 2026.