Launching today

OSS Scanner by Anthropic
Free AI vulnerability scans for open-source projects
1 follower
Free AI vulnerability scans for open-source projects
1 follower
OSS Scanner is Anthropic’s free, opt-in vulnerability-finding service for open-source projects, built on its strongest models including Claude Mythos. Maintainers enroll with a pull request. Each report comes with a reproducer, an explanation, and a candidate patch when available. In an early validation, 85 of 97 critical and high findings (88%) met the disclosure bar. Reports get no human review, so some may be wrong. Modeled on Google OSS-Fuzz.





Free
Launch Team

Framer AI AgentsDesign and publish professional sites with AI
Promoted
OSS Scanner is Anthropic’s free, opt-in vulnerability-finding service for open-source projects. It’s modeled on Google’s OSS-Fuzz, but it uses Anthropic’s strongest models, including Claude Mythos, instead of fuzzers.
Problem: Open-source projects sit under a lot of infrastructure, and finding security bugs in them takes time and expertise that many maintainers don’t have.
Solution: Maintainers opt in, and the scanner audits their code on a recurring basis and sends back reports. Each report includes a self-contained reproducer and an explanation of the vulnerability, with a bisection to when the bug was introduced where possible. It also includes a candidate patch when available.
What makes it different: it’s built on the same approach Anthropic used to find vulnerabilities during Project Glasswing, and it costs eligible projects nothing. It’s also an optional fast track. Anthropic keeps running its human-verified coordinated disclosure process for projects without triage resources.
Does it work? These numbers are from Anthropic’s own post, not independent. In an early validation, expert penetration testers checked 97 critical and high-severity findings across 48 projects, and 85 (88%) met the disclosure bar. Of the other 12, 11 were real but duplicated known issues, and one was a false positive. wolfSSL’s Todd Ouska wrote that of the 74 reports they received, all but two were valid, and five became CVEs.
Key features:
Free for eligible open-source projects
Opt-in: enroll by opening a pull request to anthropics/oss-scanner with a project.yaml and a Dockerfile
Periodic scans with reports emailed to the maintainers
Reports with a reproducer, an explanation, and a candidate patch when available
Pause or remove a project whenever you want
Scans run in sandboxes with internet access disabled
Reports get no human review before delivery, so some may be wrong. Anthropic says severity ratings can be inflated and the scanner can misread a project’s threat model.
Who it’s for: core maintainers of open-source projects with a critical impact on infrastructure and user security. Eligibility follows criteria similar to OSS-Fuzz and is decided case by case.