Finn's Take· TL;DRMuch of the world's digital infrastructure relies on open-source software maintained by small, under-resourced volunteer teams. For years, that reality has meant countless critical projects go without the kind of rigorous security review that well-funded commercial software receives. Anthropic is now stepping in to change that.
On October 8, Anthropic announced OSS Scanner, an opt-in service that uses AI models, including Claude Mythos, to search eligible open-source projects for security vulnerabilities. Maintainers who opt in receive periodic scans and reports explaining suspected flaws, how to reproduce them, and — when available — how to fix them. And the price tag? Zero.
Anthropic says human validation has become a bottleneck in its vulnerability research, so OSS Scanner sends AI-generated findings directly to project teams without human review, speeding up reporting while leaving maintainers responsible for checking findings and prioritizing fixes. It's a deliberate tradeoff: faster delivery in exchange for the possibility of occasional inaccuracies.
That means maintainers receive reports faster, but it also means that some will contain inaccuracies, such as a wrong severity rating. Anthropic expects a true-positive rate above 90%, and will work to improve the true positive rate and fix quality over time. The early numbers back up that confidence. Anthropic tested an early version by asking penetration testers to examine 97 critical- and high-severity findings across 48 projects. According to the company, 85 findings — or 88% — met its coordinated vulnerability disclosure standards. Eleven of the remaining 12 were genuine but duplicated known issues or other findings, while one was invalid.
Real-world partners have taken notice. One early tester said the reports were "as good and sometimes better than what we get from people," adding that when a report comes with a real exploit attached, "that's basically job done for an engineer as you can verify it right away" — Anton Arapov, OpenSSL Corporation.
OSS Scanner is the public version of Project Glasswing, Anthropic's internal security research program. Over six months, Glasswing scanned 591 open-source projects and generated 29,439 candidate vulnerability findings. The company said it had manually reviewed only about 6,000 of those, exposing a major bottleneck in validating AI-generated findings — which is precisely what OSS Scanner is designed to overcome by putting findings directly in maintainers' hands.
The Defender Advantage Fund (0xDAF), which Anthropic launched in August, supports pilot programs in these areas and keeps OSS Scanner free. Maintainers can also apply for free Claude Max 20x subscriptions through a separate Claude for OSS programme to help fix what turns up.
Eligibility follows OSS-Fuzz-style criteria: a project needs critical impact on infrastructure and user security, and Anthropic decides case by case. It weighs exposure to remote attacks, such as libraries that process untrusted input, and the number of users or projects that depend on the code.
Only a project's core maintainers can enroll it, by opening a pull request to the anthropics/oss-scanner repository that adds a projects/name/ directory. The Dockerfile included must build a fully offline environment — all dependencies installed, project compiled — so the scanning agent can work without internet access. Anthropic verifies that you are a core maintainer before activating the scans.
Highly cyber-capable AI models are widely available to attackers now, but defensive tools have not yet reached enough of the defenders who need them. OSS Scanner is Anthropic's most direct attempt yet to close that gap — and given how much of the internet quietly runs on volunteer-maintained code, the stakes for getting it right couldn't be higher.