On October 8, 2026, Anthropic announced the launch of Anthropic Cyber Mission, a cybersecurity support program with dedicated initiatives for critical infrastructure and open-source software. The most accessible component for open-source maintainers is OSS Scanner: free, voluntary enrollment, regular code scans, and reports describing potential vulnerabilities, examples of how they could be exploited, and possible fixes.

Reports arrive faster, but require review
Anthropic describes the service as an additional, faster channel alongside its coordinated vulnerability disclosure process. In the regular process, reported issues undergo human review before being sent to maintainers. With OSS Scanner, models prepare reports that are sent without such review. This speeds up the delivery of results, but shifts the initial assessment of their accuracy, severity, and applicability to the project team.
The company expects the share of confirmed findings to exceed 90%, but this is Anthropic’s projection, not a published result from independent testing. Anthropic also notes in its announcement that reports may contain inaccuracies, including incorrect severity assessments. Teams should therefore treat each report as a signal to reproduce and verify, not as a ready-made decision to release a fix.
Enrollment requires a prepared environment
The service is intended for the primary maintainers of projects with significant importance to infrastructure or user security. To apply, a maintainer opens a pull request in the OSS Scanner repository and adds project configuration. This specifies the repository, a contact address, and a Dockerfile that builds the environment and installs dependencies.
Anthropic says that after the container is built, scanning runs without internet access. The company asks teams to prepare an environment in which the project builds and tests pass, and also suggests adding a threat model file. This can describe important components, acceptable severity levels, the required format for evidence, and the expected form of fixes. For the team, this is a way to narrow the scanning context and make reports more useful.
After the initial scan, maintainers receive a package of reports by email. The company plans to run repeat scans; their frequency will depend, among other things, on the project queue size and how widely the code is used. A project can be temporarily disabled through its configuration or removed from the program.
Who this new channel is for
Anthropic explicitly targets OSS Scanner at projects whose teams are already equipped to handle confirmed high- and critical-severity vulnerabilities and want to receive additional findings. If maintainers are already overwhelmed by verified reports, a stream of automated reports may add work rather than speed up fixes. For such projects, the company continues to offer findings through human review under its existing disclosure process.
A practical workflow for maintainers is to first verify that a vulnerability can be reproduced in an isolated environment, then assess its impact against the project’s threat model, and only then choose a fix and release. The configuration can specify the preferred severity scale, evidence requirements, and level of patch detail. Anthropic also says it does not impose a mandatory 90-day disclosure deadline for unverified automated findings; that deadline may apply if a finding later passes human review through the standard process.
The launch illustrates a specific tradeoff in automated security scanning: deliver more potential findings faster, or review them before sending. OSS Scanner prioritizes speed and leaves triage to maintainers. The service’s value for a project will depend on whether its team has time to reproduce reports and turn confirmed vulnerabilities into fixes.