Ask Finn← Discover
YOUR MONEY

Anthropic's Free AI Scanner Hunts Security Bugs in Open-Source Code

By Sydney Parker · Saturday, October 10, 2026
Finn's Take· TL;DR
  • Anthropic launches free OSS Scanner using AI to identify security vulnerabilities in open-source projects, delivering findings directly to maintainers without human review bottlenecks.
  • Early testing shows 88% of flagged vulnerabilities meet disclosure standards; tool trades speed for occasional inaccuracies, aiming for 90%+ accuracy rate.
  • Eligibility requires critical infrastructure impact; maintainers submit pull requests with offline Docker environments; Claude Max subscriptions available to help fix discovered issues.
See this from any side — with sources:
Left takeNeutralRight take

A Security Gap Gets an AI Fix

Much of the world's digital infrastructure relies on open-source software maintained by small, under-resourced volunteer teams. For years, that reality has meant countless critical projects go without the kind of rigorous security review that well-funded commercial software receives. Anthropic is now stepping in to change that.

On October 8, Anthropic announced OSS Scanner, an opt-in service that uses AI models, including Claude Mythos, to search eligible open-source projects for security vulnerabilities. Maintainers who opt in receive periodic scans and reports explaining suspected flaws, how to reproduce them, and — when available — how to fix them. And the price tag? Zero.

Speed Over Human Review — By Design

Anthropic says human validation has become a bottleneck in its vulnerability research, so OSS Scanner sends AI-generated findings directly to project teams without human review, speeding up reporting while leaving maintainers responsible for checking findings and prioritizing fixes. It's a deliberate tradeoff: faster delivery in exchange for the possibility of occasional inaccuracies.

That means maintainers receive reports faster, but it also means that some will contain inaccuracies, such as a wrong severity rating. Anthropic expects a true-positive rate above 90%, and will work to improve the true positive rate and fix quality over time. The early numbers back up that confidence. Anthropic tested an early version by asking penetration testers to examine 97 critical- and high-severity findings across 48 projects. According to the company, 85 findings — or 88% — met its coordinated vulnerability disclosure standards. Eleven of the remaining 12 were genuine but duplicated known issues or other findings, while one was invalid.

Real-world partners have taken notice. One early tester said the reports were "as good and sometimes better than what we get from people," adding that when a report comes with a real exploit attached, "that's basically job done for an engineer as you can verify it right away" — Anton Arapov, OpenSSL Corporation.

Built on Lessons From Project Glasswing

OSS Scanner is the public version of Project Glasswing, Anthropic's internal security research program. Over six months, Glasswing scanned 591 open-source projects and generated 29,439 candidate vulnerability findings. The company said it had manually reviewed only about 6,000 of those, exposing a major bottleneck in validating AI-generated findings — which is precisely what OSS Scanner is designed to overcome by putting findings directly in maintainers' hands.

The Defender Advantage Fund (0xDAF), which Anthropic launched in August, supports pilot programs in these areas and keeps OSS Scanner free. Maintainers can also apply for free Claude Max 20x subscriptions through a separate Claude for OSS programme to help fix what turns up.

How to Get In — and Who Qualifies

Eligibility follows OSS-Fuzz-style criteria: a project needs critical impact on infrastructure and user security, and Anthropic decides case by case. It weighs exposure to remote attacks, such as libraries that process untrusted input, and the number of users or projects that depend on the code.

Only a project's core maintainers can enroll it, by opening a pull request to the anthropics/oss-scanner repository that adds a projects/name/ directory. The Dockerfile included must build a fully offline environment — all dependencies installed, project compiled — so the scanning agent can work without internet access. Anthropic verifies that you are a core maintainer before activating the scans.

Highly cyber-capable AI models are widely available to attackers now, but defensive tools have not yet reached enough of the defenders who need them. OSS Scanner is Anthropic's most direct attempt yet to close that gap — and given how much of the internet quietly runs on volunteer-maintained code, the stakes for getting it right couldn't be higher.

Have a question about this story?
Ask Finn — answers grounded in this article, from any viewpoint.