The Anthropic OSS Scanner is a free service that points Anthropic’s strongest AI models at open-source code and emails maintainers the security bugs it finds. Enrollment opened on October 9, 2026. It’s built for people who maintain widely used projects, so most readers will feel its effects rather than use it directly.
Here are the quick facts before the details.
- Cost: free, with no paid tier mentioned in launch coverage.
- Who can apply: core maintainers of established projects that matter for infrastructure and user security.
- How to apply: through the OSS Scanner GitHub repository, and Anthropic reviews each application on its own.
- Review: findings go straight to project teams with no human check first.
- Control: projects can pause automated reports or opt out entirely.
What the Anthropic OSS Scanner actually does
Think of it as a security audit that shows up in your inbox. Once a project is accepted, it gets an initial scan, then a bundle of reports by email. Each report describes a suspected flaw, how to reproduce it, and a fix when one exists, according to Help Net Security.
Later scans look for newly added vulnerabilities and for issues the earlier passes missed. How often that happens depends on demand and on how widely a project is used.
The idea echoes OSS-Fuzz, the Google and OpenSSF project that has fuzzed open-source code since 2016, as Engadget notes. The difference is that this one uses AI models, which Engadget says include Claude Mythos, to read the code and reason about it.
Anthropic also sells a paid product, Claude Security, for general code scanning and patching. The OSS Scanner offers similar audits for open-source projects at no cost.
Who can get in, and how to apply
This isn’t open to every hobby repo. Anthropic wants core maintainers of established projects that infrastructure and everyday users rely on. It also wants teams that can already handle verified high and critical reports and have spare time to chase more.
That last point matters. A scanner that finds ten real bugs is a gift to a funded team and a burden to a solo maintainer with a day job.
Applications go through the OSS Scanner repository on GitHub, at github.com/anthropics/oss-scanner. Maintainers can tell Anthropic what to test, which inputs to treat as hostile, how to rate severity, and what kinds of patches would help.
How good are the findings? The early numbers
Anthropic shared results from an early version of the scanner. Penetration testers reviewed 97 high and critical findings across 48 projects. Here’s how they came out.
| Outcome | Findings | What it means |
|---|---|---|
| Met disclosure criteria | 85 | Real flaws that qualified for coordinated disclosure |
| Real but duplicate | 11 | Valid, but already known or covered by another finding |
| Invalid | 1 | A false alarm |
Those are strong numbers for a first pass. Even so, Anthropic says “We can’t guarantee the scanner will be perfect.” It admits that reports can overstate severity or misread what a project assumes about its own security.
The catches maintainers should know about
The biggest one is that nobody at Anthropic reads the reports first. Results go from the models to your inbox, so you have to verify each one and decide what matters. Fast and frequent scans come at the cost of some noise.
Disclosure timing is the second catch. Unvalidated findings have no mandatory 90-day deadline. But if Anthropic validates a report through its existing coordinated disclosure program, the 90-day clock may start when maintainers are notified.
The third is workload. If you join, plan for triage time. A free audit still costs hours.
What it means if you only use open-source software
You can’t enroll, but you may still benefit. More bugs found and fixed upstream means fewer surprises in the apps and servers you run. Recent history shows why that matters, like the unpatched LMCache flaw that exposed LLM servers.
It also fits a wider push by Anthropic into security work. If you want the background on its access programs, see our guide to the cyber verification program tiers.
Keep your own habits up too. Update dependencies promptly, and run a quick check on packages you install, like the one in our npm malware check guide.
Frequently Asked Questions
Is the Anthropic OSS Scanner really free?
Yes. Launch coverage describes it as a no-cost, opt-in service. It runs scans with Anthropic’s strongest models at no charge to accepted projects.
Can any developer sign up?
Not quite. It targets core maintainers of established, high-impact projects, and Anthropic reviews each application individually.
Do humans check the reports before I get them?
No. Findings go directly to project teams without human review, so you need to verify each one yourself.
Can I stop the reports if they get overwhelming?
Yes. Projects can pause automated reports or opt out completely and return to the standard disclosure process.
How is this different from OSS-Fuzz?
OSS-Fuzz uses fuzzing to find crashes and bugs. The OSS Scanner uses AI models to read code and report suspected flaws, with reproduction steps and sometimes fixes.
Should you apply? Our verdict
If you maintain a project people depend on and have time to triage, apply. An 85-out-of-97 hit rate on early findings is hard to ignore, and you can opt out if it turns noisy. If you’re a solo maintainer already underwater, wait and watch how the first accepted projects fare before you add to your inbox.


Leave a Reply