Product Launches

Anthropic's free AI scanner flags 29,000 open-source vulnerabilities, no human review needed

Share
Anthropic's free AI scanner flags 29,000 open-source vulnerabilities, no human review needed

Anthropic has launched OSS Scanner, a free AI-powered vulnerability scanner for open-source projects. The tool has already flagged over 29,000 potential vulnerabilities, with no human review required for reports.

TL;DR

  • Anthropic introduces OSS Scanner, a free AI tool for open-source vulnerability scanning.
  • The scanner has identified 29,000 potential vulnerabilities, with 6,000 reported to maintainers.
  • Anthropic's Critical Infrastructure Defense Program aims to bolster cybersecurity using AI.

What happened

Anthropic unveiled OSS Scanner, an opt-in AI vulnerability scanner for open-source projects. The tool uses Anthropic's strongest models, including Claude Mythos, to perform thorough, periodic security scans at no cost to projects. Project maintainers can enroll by submitting a pull request on the OSS Scanner's GitHub repository with a YAML configuration file.

As of writing, 116 pull requests have been submitted. Anthropic does not impose a 90-day disclosure period on findings, citing the risk of false positives. However, they may implement a disclosure period for high-severity vulnerabilities in the future as confidence in the scanner's performance grows.

Why it matters

For developers, OSS Scanner offers a free, automated way to identify and address vulnerabilities in open-source projects, potentially speeding up the secure development process. Startups relying on open-source components can benefit from increased security and reduced risk.

Investors should note the strategic move by Anthropic to position itself as a leader in AI-driven cybersecurity. The Critical Infrastructure Defense Program further emphasizes the company's commitment to using AI for defensive purposes, which could attract investment and partnerships.

Key facts

  • OSS Scanner is free and opt-in for open-source projects.
  • The tool has identified over 29,000 potential vulnerabilities.
  • More than 6,000 flaws have been reported to maintainers, resulting in 584 advisories as of October 2, 2026.
  • Anthropic uses its strongest models, including Claude Mythos, for scanning.
  • Projects are selected based on criteria similar to Google's OSS-Fuzz.
  • 116 pull requests have been submitted for enrollment as of writing.
  • Anthropic does not currently impose a 90-day disclosure period on findings.
  • The Critical Infrastructure Defense Program aims to safeguard critical infrastructure and open-source software.

Context

Anthropic's OSS Scanner launch comes at a time when AI is increasingly being used by bad actors to discover and exploit vulnerabilities. The company's Critical Infrastructure Defense Program is a proactive step to arm defenders with AI tools to combat these threats.

The open-source ecosystem is a critical component of modern software development. Tools like OSS Scanner can help maintainers and developers ensure the security and stability of the projects they rely on. As AI continues to advance, we can expect more AI-driven tools to emerge in the cybersecurity space.

Topics

Related coverage

Join the discussion

Have a take on this story? Weigh in with our community on Facebook.

💬 Discuss on Facebook →