VMTech
Discuss a project →

Anthropic offers free AI vulnerability scans for open-source projects

Anthropic offers free AI vulnerability scans for open-source projects

Anthropic has introduced OSS Scanner, a free opt-in vulnerability scanning service for open-source projects. The service uses artificial intelligence, including Anthropic's Claude Mythos model, to deliver periodic security scans to participating maintainers. By 2 October 2026, Anthropic said its work had identified more than 29,000 candidate vulnerabilities in important software projects, with a little over 6,000 findings reported to maintainers and 584 resulting advisories.

The company said OSS Scanner draws on its experience using Claude to identify vulnerabilities during Project Glasswing. Scanner output will be fully model-generated and will not require human review or triage, a design Anthropic says will support faster and more frequent scanning.

How open-source projects can enrol

Core maintainers can apply by opening a pull request in the OSS Scanner GitHub repository and adding a YAML configuration file. The file must identify the Git repository to clone, provide an email address for the primary contact, and specify a repository-relative path to a Dockerfile.

That Dockerfile is central to the process. It must configure the runtime environment, install dependencies and build the project so that an offline agent can conduct a security audit without internet access. Anthropic recommends that maintainers verify their test cases pass inside the completed container before submitting the configuration.

Projects can also supply extra report recipients, a home-page address, a GPG public key for encrypted report emails, and a repository-relative threat_model.md file. The threat model can define code that should be tested, vulnerability classifications or report formats. A project can opt out of reports by setting disabled: true. At the time described, 116 pull requests had been submitted.

Disclosure rules reflect false-positive risk

Anthropic does not plan to impose a 90-day disclosure period on OSS Scanner findings because AI-generated reports may include false positives. If its existing coordinated vulnerability disclosure programme later validates a report manually, the company may disclose it under its policy starting 90 days after the maintainer is notified of that validation.

The company said it may introduce a disclosure period for some high-severity reports as confidence in OSS Scanner's performance grows. It also announced a Critical Infrastructure Defense Program under its Cyber Mission, aimed at protecting critical infrastructure and open-source software as AI enables faster vulnerability discovery, exploitation and other cyber operations.

What maintainers should prepare

OSS Scanner places the build environment and project context directly in the hands of maintainers. Teams considering enrolment should establish a reproducible Docker build, run tests in that offline container, document relevant security boundaries in a threat model, and assign an owner for reviewing incoming reports. Those preparations provide a practical way to evaluate model-generated findings and move credible issues into the project's existing security process.

#cybersecurity#opensource#vulnerability#claude
Open analytics
On the site 2 views
min read 3 09.10.2026
Instagram

Anthropic offers free AI vulnerability scans for open-source projects

Open the post on Instagram ↗