Anthropic Launches Free AI Security Scans for Open-Source Projects

Anthropic’s OSS Scanner offers free AI vulnerability scans for eligible open-source projects, with maintainers responsible for verifying reports and fixes.

Oct 9, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Anthropic wants open-source developers to catch dangerous software bugs before hackers do, and it’s putting its most powerful AI models to work for free.

Anthropic announced OSS Scanner on Oct. 8, an opt-in service that uses AI models, including Claude Mythos, to search eligible open-source projects for security vulnerabilities. Reports are generated without human review or triage. Eligible projects will receive periodic scans and reports containing explanations of potential flaws, reproduction steps and suggested fixes when available.

The service builds on Anthropic’s work under Project Glasswing, where its models helped identify weaknesses in widely used software. The company said it had discovered more than 29,000 candidate vulnerabilities over six months but manually reviewed only about 6,000, exposing a major bottleneck in validating AI-generated findings.

OSS Scanner offers an optional fast track for participating maintainers, while Anthropic continues its existing human-verified coordinated disclosure process.

Promising results, with a catch

Anthropic tested an early version by asking penetration testers to examine 97 critical- and high-severity findings across 48 projects. According to the company, 85 findings, or 88%, met its coordinated vulnerability disclosure standards. Eleven of the remaining 12 were genuine but duplicated known issues or other findings, while one was invalid.

Participating maintainers also reported useful results. PostgreSQL contributor Noah Misch said several reports uncovered defects and included fixes that required little additional work. The curl project’s Daniel Stenberg said the scanner identified multiple issues worth addressing.

However, Anthropic acknowledges that reports can be inaccurate, duplicate existing findings or misjudge a project's threat model. Maintainers must still verify the findings before acting on them.

Who can apply?

OSS Scanner is not open to every public repository. Anthropic will assess applications individually, using criteria similar to Google's OSS-Fuzz program, with priority given to established projects that have a significant impact on infrastructure and user security.

Core maintainers can apply by submitting a pull request to Anthropic’s enrollment repository using its standard template. Anthropic says the service is intended for projects already able to keep up with verified high- and critical-severity reports.

Advertisement

Anthropic also offers Claude Security, a separate enterprise product that scans code and proposes patches for review and approval.

Why faster bug hunting matters

AI-assisted vulnerability discovery creates a new race between developers fixing flaws and attackers exploiting them. Anthropic says language models’ performance on the CyberGym vulnerability-finding benchmark rose from below 20% at the beginning of 2025 to above 85% in 2026.

That improvement could help expose weaknesses in software used across businesses and internet infrastructure. But finding bugs faster does not automatically make software safer: teams still need the time, expertise and resources to validate reports, prioritize fixes and release secure updates.

What this means for developers and users

For maintainers of eligible projects, OSS Scanner could provide security expertise they might otherwise struggle to afford, along with actionable reports and proposed patches. Before acting on a report, maintainers should reproduce the issue, assess its severity against the project’s threat model and test any proposed patch.

For businesses and everyday users, stronger open-source security could reduce exposure to flaws in the libraries and tools their systems depend on. The benefit will depend on whether maintainers can turn the reports into tested fixes before attackers find and exploit the same weaknesses.

Read more: As AI takes on more security work, Anthropic’s safeguards following Claude’s live-system testing incidents highlight why isolation and monitoring matter when evaluating autonomous agents.

Aminu Abdullahi

Aminu Abdullahi

Content Writer

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. His work has appeared in publications including TechRepublic, eWEEK, Channel Insider, Geekflare, Enterprise Networking Planet, eSecurity Planet, CIO Insight, and Webopedia. With a technical background in computer science, he specializes in translating complex technology topics into clear, accessible content for business leaders and decision-makers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.