jsonscraper

Anthropic opens free AI vulnerability scanner for open source

OSS Scanner sends maintainers periodic reports with reproduction examples and potential fixes. Every report is generated without human review.

Editorial Policy Report an error

On October 8, 2026, Anthropic launched OSS Scanner, a free service that periodically searches participating open-source projects for vulnerabilities and sends the results to maintainers. The main condition for joining is that teams must be prepared to assess reports generated by models without prior human review.

Article: Anthropic opens a free AI vulnerability scanner for open source
Summary: On October 8, Anthropic launched OSS Scanner, a free service for open-source projects that opt in. Its reports could speed up vulnerability discovery, but maintainers will need to verify every finding themselves.
Image role: cover — the central idea
Section: 
Visual subject: Open-source software security code vulnerability report with reproducible test case and patch review shown on a printed engineer
© jsonscraper · AI-generated illustration

The service is intended for projects that maintainers voluntarily add to the program. According to the OSS Scanner launch announcement, a report may include a reproducible example, an explanation of the issue, and a proposed patch, if available. Anthropic says scanning is free; the company notes that the frequency of repeat scans may depend on queue size and the project's popularity.

A faster channel requires independent review

Anthropic distinguishes between two routes. In the standard coordinated vulnerability disclosure process, specialists review reports before sending them to maintainers. OSS Scanner offers an additional fast channel: reports come directly from models, without prior human review or triage.

To join, a project's lead maintainer opens a pull request in the OSS Scanner repository and adds the project configuration. It specifies the repository, a contact address, and a Dockerfile that prepares the audit environment. According to the OSS Scanner documentation, scanning agents operate without internet access once the environment has been built; maintainers can also provide a threat model and a PGP key to encrypt reports.

Anthropic is targeting projects with a substantial impact on infrastructure and user security, and reviews applications individually. Its criteria include, for example, handling untrusted data and the number of dependent projects. The company also verifies that the application was submitted by a lead maintainer.

What the published results show

Anthropic says its models identified more than 29,000 potential vulnerabilities in significant projects over the past six months, and that specialists manually reviewed about 6,000. In a separate evaluation of an early version of the scanner, external testers assessed 97 high- and critical-severity findings across 48 projects: 85 met the company's vulnerability disclosure process criteria. Of the remaining 12, one report was a false positive; 11 described real but duplicate or already known issues.

These figures relate to Anthropic's sample and methodology: the published evaluation covered 97 selected findings, not every kind of project or all service reports. The company also says some maintainers considered severity ratings inflated or noted that models had misunderstood project threats. When assessing a report, it is useful to check the reproducible example and patch against the code and threat model rather than relying solely on the assigned severity level.

A practical process for maintainers

Before applying, teams should consider whether they have enough time to review additional vulnerability reports. The OSS Scanner participation guidelines say the service is intended for projects able to handle this volume of reports; a project can be paused or removed through its configuration.

  • Describe the review boundaries, priority issue classes, and the project's severity scale in the threat model file.
  • Test reproduction examples in an isolated environment, then compare the vulnerable code and proposed fix with the current version of the project.
  • Check for duplicates, assess the impact, and verify whether the issue is actually reachable within the project's threat model.
  • Agree on who is responsible for reviewing and securely transmitting reports: the documentation provides for email delivery and a field for a PGP key.

Anthropic does not set a 90-day coordinated disclosure deadline for unreviewed reports. If the company later confirms a finding manually, the standard disclosure process deadline begins when the maintainer is notified of that review, as explained in the OSS Scanner public disclosure policy. Teams should agree on a communications process in advance so they can review reports quickly and coordinate fixes.

OSS Scanner expands access to automated vulnerability discovery for teams prepared to verify results and deliver fixes. For maintainers with limited resources, Anthropic retains its usual disclosure process after specialist review; teams that are ready can add another channel and receive model-generated reports without waiting for that review.

People

No people listed for this article yet.

Keep readingAnthropic launches free vulnerability scanning for open source
Read the next article

Turn what you read into a working integration

Explore jsonscraper's social-data APIs, test requests and build your next workflow.

Explore APIs