Anthropic offers free AI security scans to open-source maintainers

Anthropic OSS scanner analysing glowing code stack with an orange beam

Written by

in

Open-source maintainers can now sign up for free, AI-driven security scans that surface vulnerabilities directly in their inboxes, with reports that explain the suspected flaw, how to reproduce it and, when possible, how to fix it. The service is built on the same model work that powered Project Glasswing, and it ships findings to project teams without waiting for a human reviewer to clear them first.

What the OSS Scanner does

OSS Scanner is a free program from Anthropic aimed at the people who look after widely used open-source projects. Maintainers who opt in get periodic scans and a bundle of reports by email. The first batch covers the project as it stands; later runs look for vulnerabilities introduced after the previous scan, plus issues the earlier ones may have missed. How often those follow-up scans happen depends on demand and how broadly the project is used.

Reports are designed to be acted on. Each one explains the suspected vulnerability, lays out the steps to reproduce it, and, when a fix is realistic, suggests how a patch could look. Maintainers can also tell the scanner what to focus on: which inputs should be treated as potentially malicious, how severity should be rated, and what kinds of proposed patches would actually be useful for the project. That feedback shapes future runs.

Why findings go out without a human filter

Anthropic has said human validation has become a bottleneck in its own vulnerability research. To clear that bottleneck, OSS Scanner sends AI-generated findings straight to project teams, skipping the human-review step that used to gate every report. Anthropic’s experience with Project Glasswing, which used Claude to search for software vulnerabilities, is what the new service is built on.

The trade-off is speed. The point of skipping the human step is to get information to maintainers faster. The point of not skipping it is accuracy, which is why the company stresses that the responsibility for checking each finding and deciding what to fix still sits with the project team.

What early testing showed

Before the public launch, penetration testers worked through 97 high and critical severity findings produced by an early version of the scanner, drawn from 48 projects. Anthropic reports that 85 of those met its coordinated disclosure criteria, 11 turned out to be real but duplicated known issues or other findings, and one was invalid. Put differently, the early scanner produced one false positive out of 97 high and critical reports, and a meaningful share of the rest overlapped with vulnerabilities already on file.

An early user of the underlying capability described the raw model output as comparable to, and sometimes better than, what a human reviewer would produce, particularly when a report came with a working exploit attached so an engineer could verify it on the spot.

Known limits of the reports

Anthropic is explicit that the scanner is not perfect. Reports can overstate how severe an issue is, or they can miss the security assumptions a particular project operates under. That is why the program is aimed at teams that already have the capacity to keep up with verified high and critical findings and can absorb extra reports to investigate. A project that cannot triage a flood of new reports will not get the same value out of the service as one that can.

Who can apply, and how disclosure works

Core maintainers apply through the OSS Scanner GitHub repository. Each application is reviewed on its own, and eligibility is weighted toward established projects that matter to infrastructure and to user security. Anthropic also reserves the right to decide which projects to take on.

Because findings are unvalidated when they reach a maintainer, they do not come with a mandatory 90-day disclosure deadline. If a report is later confirmed through Anthropic’s existing coordinated disclosure program, a 90-day clock can start from the moment the maintainer is told of that validation. Projects can also pause automated reports at any time, or opt out entirely and fall back to receiving only reports that go through Anthropic’s standard disclosure process.

Who the service is meant for

The intended user is a team that already keeps up with verified high and critical reports and has the spare capacity to look at more. For those teams, the scanner is positioned as a way to find new issues sooner and to catch things earlier scans missed. For teams without that capacity, the same volume of reports is more likely to become noise than help.

FAQ

What is Anthropic’s OSS Scanner?

OSS Scanner is a free service from Anthropic that uses the company’s AI models to find security vulnerabilities in open-source projects. Maintainers who opt in get periodic scans and reports describing the suspected flaw, how to reproduce it, and, when available, how to fix it.

How accurate are the scanner’s reports?

Penetration testers reviewed 97 high and critical severity findings from an early version of the scanner across 48 projects. Anthropic says 85 met its coordinated disclosure criteria, 11 were real but duplicated known issues, and one was invalid. The company also acknowledges reports can overstate severity or miss a project’s security assumptions.

How can a project sign up for OSS Scanner?

Core maintainers apply through the OSS Scanner GitHub repository. Applications are reviewed individually, with eligibility focused on established projects that are important to infrastructure and user security. Unvalidated reports do not carry a mandatory 90-day disclosure deadline unless they are later confirmed through Anthropic’s coordinated disclosure program.


This article summarizes reporting from helpnetsecurity.com.