AI & DevelopmentOpen SourceSecurity

Anthropic OSS Scanner: Free AI Vulnerability Scans for Open Source

Blue security shield with magnifying glass scanning code lines representing Anthropic OSS Scanner vulnerability detection
Anthropic OSS Scanner uses Claude Mythos to find vulnerabilities in open-source projects

Anthropic opened enrollment for OSS Scanner on October 8 — a free, recurring vulnerability scanner for open-source projects powered by Claude Mythos, its strongest model. The scanner finds security flaws, writes up proof-of-concept exploits, and emails the report directly to the project maintainer. No Anthropic employee reviews the output before it lands in your inbox. That design choice is deliberate, and it matters.

Where This Came From

OSS Scanner is the public version of Project Glasswing, Anthropic’s internal security research program that ran from April through October 2026. Over six months, Glasswing scanned 591 open-source projects and generated 29,439 candidate vulnerability findings. External security firms reviewed 6,123 of those and confirmed 5,674 as valid — a 92.7% true-positive rate that holds up against any commercial scanner on the market.

The most striking results were not statistical. Glasswing’s models found a 27-year-old vulnerability in OpenBSD and a 16-year-old flaw in FFmpeg hidden in a code path that automated tools had tested five million times without triggering. The AI was not running faster pattern matching — it was reasoning about the code differently.

By October, Glasswing had issued 584 advisory IDs (219 CVEs, 365 GitHub Security Advisories) and seen 516 patches shipped upstream. The bottleneck was human review capacity: Anthropic could generate findings faster than its team could manually triage them. So they stopped requiring it.

How to Enroll

Enrollment is open now. To add your project, open a pull request to github.com/anthropics/oss-scanner and add a project.yaml file at projects/<project>/project.yaml. The file needs three fields:

repo: https://github.com/yourorg/yourproject
primary_contact: security@yourproject.org
dockerfile: .oss-scanner/Dockerfile

The Dockerfile is the significant requirement. It must build a fully offline environment — all dependencies installed, project compiled — so the scanning agent can work without internet access. Anthropic verifies that you are a core maintainer before activating the scans. Optional but recommended: include a threat_model.md explaining what the project considers in scope.

The full enrollment details and terms are on the OSS Scanner page at Anthropic’s Frontier Red Team site.

The No-Human-Review Trade-Off

Anthropic is explicit in its terms: reports may contain incorrect details, invalid findings, or inaccurate severity ratings. They are sending you AI output, not vetted disclosures. Some in the security community flagged this as concerning. It is worth examining the actual numbers before deciding how worried to be.

Penetration testers reviewed 97 of the most critical and high-severity findings across 48 projects. They confirmed 85 as serious enough for formal disclosure — an 88% confirmation rate. One was a false positive. The other 11 were real vulnerabilities that were already known or found elsewhere in the same scan.

For context, traditional static analysis tools typically run false positive rates between 30% and 60%. AI-native SAST tools have brought that closer to 20% in production environments. One invalid finding out of 97 critical/high results is not a noise problem — it is a signal quality that most paid security tooling cannot match.

The right frame is to treat OSS Scanner output as high-quality triage leads, not verdicts. Experienced security teams read SAST findings this way regardless of the tool. The reports include reproduction steps and suggested fixes, so you have enough context to verify quickly.

The Bigger Picture

OSS Scanner is one part of Anthropic’s broader Cyber Mission, which also includes $100 million in usage credits to organizations maintaining critical software, $4 million in donations to open-source security foundations, and the Critical Infrastructure Defense Program deploying Claude alongside on-site engineers at CrowdStrike, Palo Alto Networks, Dragos, and Deloitte.

The OSS Scanner announcement is the piece most developers can act on today. Free, recurring, high-signal vulnerability scans using the same model that found decade-old flaws in software tested millions of times before — that is a meaningful resource for maintainers who do not have a dedicated security budget.

Who Should Enroll

If you maintain an actively-used open-source project and do not have dedicated security review in place, enroll. The Dockerfile requirement adds some setup work, but it is a one-time cost for ongoing scans. If your project already has a professional security program, OSS Scanner is still worth adding — a second high-quality signal source that runs for free does not hurt.

Enrollment details and the full research announcement are available on Anthropic’s site.

ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *