Skip to main content

Anthropic announces opt-in OSS vulnerability scanner

9 OCTOBER 2026·2 MIN READ·3 SOURCES

Anthropic announced OSS Scanner, an opt-in vulnerability-scanning service for open-source projects, on October 8, 2026. The company says enrolled projects will receive periodic scans by its strongest models at no cost.

Anthropic announces opt-in OSS vulnerability scanner

Key takeaways · 3

  • 01

    Anthropic says scans are free, periodic and run by its strongest models, including Claude Mythos.

  • 02

    Reports include a vulnerability explanation and self-contained reproducer, plus a bisection or candidate patch when available.

  • 03

    Because reports are not human-reviewed before delivery, maintainers should be prepared to assess them for accuracy and severity.

A free, opt-in scanning service

The service is opt-in: core maintainers of eligible open-source projects can apply by submitting a pull request to Anthropic’s OSS Scanner GitHub repository.[1] Anthropic says it considers projects case by case and looks for critical impact on infrastructure and user security.[1] It manually verifies that an applicant is a project’s core maintainer before enrolling the project.[2]

What maintainers receive

Anthropic says enrolled projects receive regular scans at no cost, using its strongest models, including Claude Mythos.[1] Maintainers receive a bundle of bug reports by email.[2] Each report includes a self-contained reproducer and an explanation of the vulnerability; it may also include a bisection showing when the bug was introduced, where possible, and a candidate patch when one is available.[1] After an initial scan, projects are scanned regularly for newly introduced vulnerabilities and issues missed earlier, although later scan frequency may depend on pipeline size, project usage and other factors.[2]

Fast reports come with caveats

The scanner’s reports are generated by models without human review or triage.[1] Anthropic says this allows faster and more frequent scans, but reports may be incorrect or invalid.[1] The company says some maintainers have reported inflated severity ratings or misunderstandings of their projects’ threat models.[1] Anthropic says the service is intended for projects able to keep up with verified high- or critical-severity reports, a consideration for maintainers assessing whether to enroll.[2] Maintainers can pause reports through a configuration field or remove their project from the program.[2]

Anthropic’s reported validation results

Anthropic says it scanned hundreds of widely used open-source projects under Project Glasswing, finding more than 29,000 candidate vulnerabilities and manually reviewing and triaging approximately 6,000.[3][1] It says it sent nearly 5,000 reports to maintainers who requested all findings, including ones that had not been validated.[1] In a check of 97 critical- and high-severity scanner findings across 48 projects, Anthropic says 85 met the bar for coordinated disclosure; 11 of the remaining 12 were real but duplicates, and one was invalid.[1] These are Anthropic’s reported results, not a guarantee that future reports will be valid.

Maintainers weighing enrollment should consider both the potential value of recurring model-generated findings and the work of validating reports without an initial human review. Teams should assess whether they can handle verified high- or critical-severity issues and establish an internal review process before acting on scanner output.

Why it matters
Daily session

Put this to work — one session a day, built for your industry.

Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.

Start free

How this developed

  1. 9 October 2026

    Anthropic announces opt-in OSS vulnerability scanner

Sources

AI fluency, one session a day, built for your work.