Anthropic launches free AI vulnerability scanner for open source projects

Delighted LakshmananOctober 9, 2026Vulnerability / Artificial intelligence

Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open source ecosystem using artificial intelligence (AI).

“This is an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing,” Anthropic said. “Projects that join will receive free, periodic, in-depth security scans from our most powerful models.”

Anthropic also noted that the scanner results will be entirely model-generated and will not require human review or sorting, facilitating faster and more frequent analysis. These reports should be generated by its most powerful models, including Claude Mythos.

The company stressed that it plans to use a set of criteria similar to Google’s OSS-Fuzz to select projects, while also emphasizing that the process could evolve over time. Project leaders are advised to provide a brief description explaining the importance of their project in cases where it “doesn’t already go without saying.”

Primary maintainers of a project can sign up by opening a pull request on the OSS Scanner GitHub repository with a YAML configuration file that provides the following information:

  • Link to the git repository that needs to be cloned
  • Primary contact email address
  • A repository-relative path to the Dockerfile that configures the environment, preinstalls all dependencies, and builds the project to help an offline agent conduct its security audit

“The Dockerfile configures the environment in which the project will run and installs all dependencies so that the agent can perform its security audit without any Internet access,” Anthropic said. “We recommend verifying that the test cases pass inside the constructed container.”

Other optional details that can be added to the YAML file are below –

  • Additional email addresses that must be copied on all reports
  • Project homepage
  • GPG public key to encrypt report emails
  • A repository-relative path to a threat model file (“threat_model.md”) that indicates what code should be tested, vulnerability classification, or reporting formats.
  • Disable receiving bug reports by setting “disabled: true”

At the time of writing, a total of 116 pull requests have been submitted. Unlike other vulnerability reporting programs, Anthropic said it does not intend to impose a 90-day disclosure period on the results, given the risk that they contain false positives.

“If we subsequently validate any of these reports manually through our existing CVD program, we may disclose it under our CVD policy beginning 90 days from the time you are notified that a human validated this report,” he added. “As we gain confidence in the performance of OSS Scanner, we may in the future impose a disclosure period for certain high-severity vulnerability reports.”

The AI ​​company said it has identified more than 29,000 potential vulnerabilities in some of the world’s largest software projects, of which just over 6,000 flaws have been reported to managers. These gave rise to 584 opinions as of October 2, 2026.

This development comes as Anthropic also unveiled the Critical Infrastructure Defense program to protect critical infrastructure and open source software as part of its Cyber ​​Mission.

As AI increasingly enables malicious actors to discover and exploit vulnerabilities, automate different stages of cyber operations, and carry out attacks faster and at scale, the idea behind the initiative is to equip defenders with the right tools to combat the threat, accelerate patching, and explore new secure architectures and coding practices.

“Our prediction is that in two years, AI will drive defense: it will be easier to detect bugs before they ship, write fundamentally secure software from scratch, and actively defend systems with models,” Anthropic said.

Gn bussni

Scroll to Top