Anthropic announced on October 8, 2026 the launch of OSS Scanner, a free opt-in service that uses its most advanced AI models, including Claude Mythos, to perform periodic vulnerability scans on open-source software projects.
The goal is to reduce the human bottleneck in validating security findings. Over the past six months, the company's models identified more than 29,000 candidate vulnerabilities in important projects, but the team was only able to manually review about 6,000. Some maintainers were already requesting all unvalidated reports, and Anthropic has already sent nearly 5,000 in that form.
How Anthropic's OSS Scanner works
Reports are generated entirely by the models, without human review or triage. Each includes a self-contained reproducer, an explanation of the vulnerability (with bisection when possible to identify when the bug was introduced), and a candidate patch if available. This enables more frequent and faster scans, but the company warns that reports may contain errors or be invalid.
The service is inspired by Google's OSS-Fuzz. Core maintainers of eligible projects — those with "critical impact on infrastructure and user security" — can enroll by opening a pull request on Anthropic's GitHub repository with a YAML configuration file.
In initial tests with dozens of projects, experts reviewed 97 critical and high-severity vulnerabilities across 48 projects: 85 (88%) met the criteria for coordinated disclosure, 11 were real but duplicated, and only one was invalid. Feedback from projects such as PostgreSQL, OpenSSL, wolfSSL, and curl was positive.
Context and limitations
Anthropic continues with the traditional coordinated vulnerability disclosure (CVD) process for projects without the capacity to triage raw reports. OSS Scanner is the fast track for those with resources. The company also launched related initiatives for critical infrastructure security as part of the Anthropic Cyber Mission.
With AI models increasingly capable of finding (and potentially exploiting) vulnerabilities in minutes, the race between defenders and attackers intensifies. The scanner aims to give an advantage to open-source maintainers who choose to participate.
Sources
Transparency: This content was created, edited, or reviewed with the assistance of artificial intelligence. Information was cross-checked with public posts on X and sources available on the internet. Consult the original sources to verify the full context.
By GeekikiBot