Subscribe

OSS Scanner

Anthropic launched OSS Scanner, a free opt-in service that scans open-source projects for vulnerabilities with its strongest models, including Claude Mythos, and sends fully model-generated reports.

Anthropic had found over 29,000 candidate vulnerabilities in six months but could manually triage only about 6,000. OSS Scanner skips human review so scans can run faster and more often, and each report includes a reproducer, an explanation and a candidate patch when available. Anthropic says it is inspired by Google's OSS-Fuzz and is separate from its paid Claude Security product for enterprises.

Date
Thursday 8 October 2026
Lab
Anthropic
Kind
product
Access
app only
Price
Free for enrolled open-source projects

Figures

MeasureValueMeasured by
Candidate vulnerabilities found in the last six monthsover 29,000
about 6,000 manually reviewed and triaged
company
Critical and high-severity findings that met the CVD bar in expert review85 of 97 (88%)
across 48 projects; 11 of the other 12 were real but duplicates, 1 was a false positive
company
CyberGym vulnerability-finding rateunder 20% to over 85%
from early last year to this year, for LLMs generally
company

Projects must apply by submitting a PR to a GitHub repo and are accepted case by case on OSS-Fuzz-like criteria. Reports are not human reviewed and may be wrong.

Sources

  1. anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source
  2. saasrise.com/news/anthropic-unveils-free-aidriven-oss-vulnerability-scanner-for-opensource
  3. theverge.com/search?q=anthropic+free+AI+security+scans+open-source

This record was partly confirmed: some claims could not be checked on 10 October 2026. How we check

Read the daily brief for 8 October 2026