
Anthropic OSS Scanner: Free AI Bug Scans for Open Source
Anthropic's OSS Scanner gives open-source maintainers free AI vulnerability scans with fixes; 85 of 97 tested severe findings met its disclosure bar.
Anthropic has launched OSS Scanner, a free, opt-in service that uses its most capable Claude models to scan open-source projects for security vulnerabilities and send maintainers ready-to-use reports. Announced on October 8, 2026, it is modeled on the idea behind Google's long-running OSS-Fuzz project: give the volunteers who maintain critical open-source software the same automated security help that large companies buy for themselves.
- What it is: periodic, free AI vulnerability scans for eligible open-source projects, opted in by core maintainers via a pull request to the anthropics/oss-scanner GitHub repository.
- What maintainers get: a self-contained reproducer, an explanation, a bisection showing when the bug was introduced where possible, and a candidate patch when available.
- Validation: penetration testers reviewed 97 high and critical findings from 48 projects; 85 (88%) met Anthropic's coordinated disclosure bar, 11 were real but duplicates, and 1 was a false positive.
- Scale: over six months Anthropic's models found more than 29,000 candidate vulnerabilities, about 6,000 were triaged, and nearly 5,000 reports went to maintainers.
How Does OSS Scanner Work?
OSS Scanner grew out of Anthropic's experience with Project Glasswing, its effort to find and patch vulnerabilities with AI. Anthropic found that human validation had become the bottleneck, so OSS Scanner sends model-generated findings directly to project teams without a human review step. Maintainers stay in control: they verify findings, decide priorities, and can pause automated reports or opt out at any time.
Enrolled projects receive an initial scan and report bundle, and later scans focus on newly introduced issues, according to Help Net Security. Eligibility follows criteria similar to OSS-Fuzz, prioritizing established projects with a critical impact on infrastructure and user security, and decisions are made case by case.
Is AI Vulnerability Scanning Accurate Enough?
That is the right question, and Anthropic answered it with data. In its validation study, 88% of high and critical findings met its disclosure bar, and only one of 97 was a false positive. For the wider program Anthropic says it expects a true-positive rate above 90%, and it is candid that reports can sometimes overstate severity or misread a project's security assumptions.
Maintainers who tested early versions were enthusiastic. Anthropic quotes wolfSSL's Todd Ouska saying all but two of 74 reports were valid, with five becoming CVEs, and curl's Daniel Stenberg noting the scanner found multiple issues in the project. OpenSSL Corporation's Anton Arapov told Help Net Security that a report with a working exploit attached is "basically job done for an engineer."
Disclosure Rules That Respect Maintainers
Unvalidated findings carry no mandatory 90-day disclosure deadline, according to Help Net Security. If Anthropic validates a report through its coordinated vulnerability disclosure program, the 90-day clock may start when maintainers are notified. Maintainers who want everything immediately can opt into a fast track. That balance gives small volunteer teams breathing room while still moving serious bugs toward fixes.
Critical Infrastructure Defense Program
Alongside OSS Scanner, Anthropic announced the Critical Infrastructure Defense Program, which brings Claude models, on-site engineers and threat research to the providers that protect operational technology in power grids, water systems and transportation networks. Founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic also named the Python Software Foundation, Alpha-Omega and OpenSSF, and the Apache Software Foundation among the open-source organizations it supports.
Why OSS Scanner Matters
Open-source software sits under nearly everything, yet much of it is maintained by small teams with no security budget. Free, high-quality vulnerability reports with patches attached shift the balance toward defenders, and they do it at the scale where AI genuinely helps. For more defensive tools and practical guides, visit our AI security coverage.
Sources: Anthropic — Launching an opt-in vulnerability-finding service for open source — October 8, 2026; Anthropic — Anthropic's cyber mission — October 8, 2026; Help Net Security — Anthropic OSS Scanner brings AI security scans to open source — October 9, 2026; SecurityWeek — Anthropic fast-tracks AI bug reports to OSS maintainers — October 9, 2026.
More Ai Security Stories

What Is Prompt Injection? A Plain-English Defense Guide
What is prompt injection? Learn direct vs indirect attacks, 9 real scenarios, and the 7 OWASP-backed defenses that keep AI assistants and agents safe.

GitHub AI Secret Detection: How Push Protection Gets Smarter
GitHub is adding a ModernBERT classifier to push protection that spots unstructured passwords in under 2 ms and could more than double blocked secrets.

Anthropic Cyber Verification Program: Which Tier Fits You?
Anthropic split its Cyber Verification Program into 3 tiers, Defense, Red Team and Specialized, giving vetted defenders broader Claude access for security.
