Anthropic announces opt-in OSS vulnerability scanner
Anthropic announced OSS Scanner, an opt-in vulnerability-scanning service for open-source projects, on October 8, 2026. The company says enrolled projects will receive periodic scans by its strongest models at no cost.

Key takeaways · 3
- 01
Anthropic says scans are free, periodic and run by its strongest models, including Claude Mythos.
- 02
Reports include a vulnerability explanation and self-contained reproducer, plus a bisection or candidate patch when available.
- 03
Because reports are not human-reviewed before delivery, maintainers should be prepared to assess them for accuracy and severity.
A free, opt-in scanning service
The service is opt-in: core maintainers of eligible open-source projects can apply by submitting a pull request to Anthropic’s OSS Scanner GitHub repository.[1] Anthropic says it considers projects case by case and looks for critical impact on infrastructure and user security.[1] It manually verifies that an applicant is a project’s core maintainer before enrolling the project.[2]
What maintainers receive
Anthropic says enrolled projects receive regular scans at no cost, using its strongest models, including Claude Mythos.[1] Maintainers receive a bundle of bug reports by email.[2] Each report includes a self-contained reproducer and an explanation of the vulnerability; it may also include a bisection showing when the bug was introduced, where possible, and a candidate patch when one is available.[1] After an initial scan, projects are scanned regularly for newly introduced vulnerabilities and issues missed earlier, although later scan frequency may depend on pipeline size, project usage and other factors.[2]
Fast reports come with caveats
The scanner’s reports are generated by models without human review or triage.[1] Anthropic says this allows faster and more frequent scans, but reports may be incorrect or invalid.[1] The company says some maintainers have reported inflated severity ratings or misunderstandings of their projects’ threat models.[1] Anthropic says the service is intended for projects able to keep up with verified high- or critical-severity reports, a consideration for maintainers assessing whether to enroll.[2] Maintainers can pause reports through a configuration field or remove their project from the program.[2]
Anthropic’s reported validation results
Anthropic says it scanned hundreds of widely used open-source projects under Project Glasswing, finding more than 29,000 candidate vulnerabilities and manually reviewing and triaging approximately 6,000.[3][1] It says it sent nearly 5,000 reports to maintainers who requested all findings, including ones that had not been validated.[1] In a check of 97 critical- and high-severity scanner findings across 48 projects, Anthropic says 85 met the bar for coordinated disclosure; 11 of the remaining 12 were real but duplicates, and one was invalid.[1] These are Anthropic’s reported results, not a guarantee that future reports will be valid.
Maintainers weighing enrollment should consider both the potential value of recurring model-generated findings and the work of validating reports without an initial human review. Teams should assess whether they can handle verified high- or critical-severity issues and establish an internal review process before acting on scanner output.
Why it matters
Put this to work — one session a day, built for your industry.
Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.
Start freeHow this developed
9 October 2026
Anthropic announces opt-in OSS vulnerability scanner
Sources
- An opt-in vulnerability-finding service for open-source software \ Anthropicanthropic.com
- OSS Scannerred.anthropic.com
- Introducing the Anthropic Cyber Mission \ Anthropicanthropic.com