OSS Scanner
Anthropic launched OSS Scanner, a free opt-in service that scans open-source projects for vulnerabilities with its strongest models, including Claude Mythos, and sends fully model-generated reports.
Anthropic had found over 29,000 candidate vulnerabilities in six months but could manually triage only about 6,000. OSS Scanner skips human review so scans can run faster and more often, and each report includes a reproducer, an explanation and a candidate patch when available. Anthropic says it is inspired by Google's OSS-Fuzz and is separate from its paid Claude Security product for enterprises.
- Date
- Thursday 8 October 2026
- Lab
- Anthropic
- Kind
- product
- Access
- app only
- Price
- Free for enrolled open-source projects
Figures
| Measure | Value | Measured by |
|---|---|---|
| Candidate vulnerabilities found in the last six months | over 29,000 about 6,000 manually reviewed and triaged | company |
| Critical and high-severity findings that met the CVD bar in expert review | 85 of 97 (88%) across 48 projects; 11 of the other 12 were real but duplicates, 1 was a false positive | company |
| CyberGym vulnerability-finding rate | under 20% to over 85% from early last year to this year, for LLMs generally | company |
Projects must apply by submitting a PR to a GitHub repo and are accepted case by case on OSS-Fuzz-like criteria. Reports are not human reviewed and may be wrong.
Sources
- anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source
- saasrise.com/news/anthropic-unveils-free-aidriven-oss-vulnerability-scanner-for-opensource
- theverge.com/search?q=anthropic+free+AI+security+scans+open-source
This record was partly confirmed: some claims could not be checked on 10 October 2026. How we check