ChengRang

OSS Scanner

AI Coding Free

Anthropic launched this opt-in vulnerability scanner for open source on October 8, 2026, inspired by Google OSS-Fuzz and powered by its strongest models including Claude Mythos, at no cost to projects. Core maintainers enroll by opening a pull request against a designated repository, and eligibility follows criteria similar to OSS-Fuzz, judged case by case on impact to infrastructure and user security. Each report carries a self-contained reproducer, an explanation of the flaw, a bisection identifying when the bug was introduced where possible, and a candidate patch. Output is fully model generated with no human review, so reports may be incorrect. In early validation, 85 of 97 critical and high severity findings met the bar for disclosure, with a single false positive

Vulnerability ScanningOpen Source SecurityCode AuditAnthropicFree Service
Visit OSS Scanner

Disclaimer: Review content represents our editorial team's views and experience, not commercial recommendation or investment advice. Product info and pricing may change; refer to official sources.

Overview

OSS Scanner is the opt-in vulnerability scanning service Anthropic launched on October 8, 2026 for open-source projects, running periodic scans with its strongest models including Claude Mythos at no cost. The idea comes straight from Google OSS-Fuzz: continuous automated scanning of open source proved its worth with fuzzers, and Anthropic wants to run the same play with language models.

The backdrop is that models changed character over two years. Anthropic cites CyberGym, an academic vulnerability-finding benchmark, where the share of vulnerabilities models can find went from under 20 percent early last year to over 85 percent this year. What maintainers receive changed with it, moving from mostly slop to high-quality bug reports. Over the past six months Anthropic used its latest models to scan some of the most important software projects in the world and discovered over 29,000 candidate vulnerabilities, but human capacity to validate them only covered about 6,000. That bottleneck is the direct reason OSS Scanner exists: rather than letting reports queue for human triage, open a fast track for projects willing to consume raw findings themselves.

To be clear about what that fast track means, its output is fully model generated with no human review or triage. What that buys is faster and more frequent scanning, and the trade-off is that reports may be incorrect or invalid. Anthropic keeps its existing human-verified coordinated vulnerability disclosure process running in parallel, so both paths stay available.

Key Features

Use Cases

Pros

Pricing

Free for eligible open-source projects with no scanning fee. Projects enroll when a core maintainer submits a pull request, and eligibility is assessed case by case on critical impact to infrastructure and user security. Reports are model generated without human review, so projects verify and triage them themselves. Claude for OSS complements the service with free Claude Max 20x subscriptions for open-source work.

Summary

What OSS Scanner actually fixes is a throughput mismatch: models find vulnerabilities far faster than humans can verify them, and Anthropic is sitting on 29,000 candidates with only 6,000 triaged. Rather than letting the remainder queue indefinitely, hand them to maintainers who are willing to do their own triage.

For open-source projects that is a good deal, free, periodic, with reproducers and patches attached, and an 88 percent bar-meeting rate on critical and high-severity findings showing the signal is solid. What matters to remember is its nature: fast-track output is raw model output with no human backstop, so reports still need your own verification, and severity ratings may run high or misread a project threat model. Anthropic kept the human-verified CVD path precisely for projects without the resourcing to triage themselves.

If your project is widely depended-upon infrastructure, it is worth having a core maintainer open that pull request.

Version History

Category
AI Coding
Pricing
Free
Tags
Vulnerability Scanning · Open Source Security · Code Audit

Related Tools