OSS Scanner gives eligible open-source projects free, periodic vulnerability scans using Anthropic’s strongest models, including Claude Mythos. The service is opt-in, and its reports are sent without human review or triage.
That trade-off is central to the launch. Maintainers can receive findings faster, but Anthropic says the model-generated reports may be incorrect or invalid. Each report can include a self-contained reproducer, an explanation of the vulnerability and when it was introduced, plus a candidate patch when one is available.
A backlog too large to review by hand
Anthropic says its models found more than 29,000 candidate vulnerabilities over the past six months, while its team manually reviewed and triaged about 6,000. The company also says it has sent nearly 5,000 unverified reports to maintainers who asked to receive everything available.
During early testing across dozens of open-source projects, the company says the scanner produced hundreds of reports. Some findings could be combined into unauthenticated remote-code-execution exploits, according to Anthropic.
The company also asked penetration testers to review 97 critical or high-severity findings across 48 projects. Anthropic says 85, or 88%, met the standard for its coordinated vulnerability disclosure process. Of the remaining 12, 11 duplicated known issues or other scan findings and one was invalid. It cautions that severity ratings can still be inflated or based on a mistaken understanding of a project’s threat model.
Who can enroll
Core maintainers can apply through Anthropic’s OSS Scanner repository. The company says eligibility will be decided case by case for projects with a critical impact on infrastructure and user security.
OSS Scanner is an optional fast track for projects that can triage raw findings. Anthropic says it will continue its human-reviewed disclosure process, particularly for projects that lack the resources to evaluate a stream of unverified reports.