Anthropic has launched OSS Scanner, a free opt-in service that uses the company's strongest AI models — including Claude Mythos — to periodically scan eligible open-source projects for security vulnerabilities and deliver fully model-generated bug reports directly to maintainers.
The service, announced Wednesday in a company blog post, is the product of a quiet shift in Anthropic's security work: its models have recently been finding vulnerabilities faster than Anthropic's own security team can verify them. For developers tracking the tools reshaping software security, the launch is a significant moment for our coverage of AI developments in open-source infrastructure.
From Project Glasswing to a Public Service
OSS Scanner is informed by Anthropic's experience using Claude to hunt vulnerabilities during Project Glasswing, the company's internal vulnerability discovery effort. The numbers from that work explain why Anthropic is opening the pipeline to the public.
Over the past six months, Anthropic says its latest models surfaced more than 29,000 candidate vulnerabilities in some of the world's most important software projects — but the company has only been able to manually review and triage around 6,000 of them. Human validation capacity, not model capability, has become the bottleneck.
The demand side tells a similar story. Anthropic reports that maintainers who receive its first reports increasingly ask for everything the company has: nearly 5,000 reports have already been sent directly to maintainers who requested bulk submissions of unverified findings, patches included.
The capability context is stark. On CyberGym, an academic vulnerability-finding benchmark, large language models have gone from finding under 20 percent of vulnerabilities at the beginning of last year to more than 85 percent this year, according to Anthropic — a jump that has transformed AI bug reports from noise into actionable findings.
How the Numbers Held Up in Testing
Before launching, Anthropic validated the pipeline with dozens of open-source projects, producing hundreds of bug reports — including vulnerabilities the company says could be chained into unauthenticated remote code execution exploits.
The most telling test involved outside scrutiny. Anthropic asked the expert penetration testers who review its coordinated vulnerability disclosure (CVD) findings to examine 97 critical and high-severity findings from the scanner, drawn from 48 projects. Of those, 85 — 88 percent — met the bar for Anthropic's CVD process. Of the remaining 12, 11 were real but duplicated known issues or other findings from the same scan. Only one was an outright false positive.
Each report, the company says, contains a self-contained reproducer and an explanation of the vulnerability, including a bisection to determine when the flaw was introduced.
The Trade-Off: Speed Over Certainty
The central design decision of OSS Scanner is also its biggest risk: the reports are fully model-generated, with no human review or triage. Anthropic is explicit that this enables faster, more frequent scanning, but also that some reports will be incorrect or invalid.
The company frames the trade-off as responsive to maintainer demand. Since exploits can now be developed in minutes, projects increasingly prefer receiving every unverified finding immediately — with proposed patches attached — over waiting for human vetting. Inspired by Google's OSS-Fuzz, which has scanned open-source software with fuzzers for years, OSS Scanner applies the same logic to AI-driven code analysis.
Projects that prefer traditional handling are not left out: Anthropic says it will continue manually disclosing human-verified vulnerability reports through its existing CVD process, especially for projects without the resources to triage reports themselves. An optional fast-track is available for those who want raw findings as soon as they are generated.
Who Can Enroll — and What Else Anthropic Announced
Core maintainers of eligible projects can enroll by submitting a pull request to a GitHub repository following a standard project template. Eligibility mirrors OSS-Fuzz criteria: projects should have a critical impact on infrastructure and user security, with admissions decided case by case.
The scanner arrives alongside a broader set of Anthropic security initiatives. The company's Cyber Verification Program makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals — a program Anthropic expanded earlier this week with three tiers of Claude access for security teams. A separate Claude for OSS effort provides free Claude Max 20x subscriptions to help maintainers remediate vulnerabilities and improve their projects. SiliconANGLE also reported a new Anthropic program focused on protecting critical infrastructure, framing the week's announcements as a coordinated push into defensive cybersecurity.
What It Means for Open-Source Security
If OSS Scanner works as advertised, it marks a structural shift in open-source security: AI finds the bugs, and humans shift from hunting to verifying. That shift moves real burden onto maintainers, who must triage machine-generated reports — some of them wrong — while deciding whether to trust automated patches.
The 88 percent validation rate suggests the signal-to-noise ratio is now good enough to be worth a maintainer's time, at least for critical infrastructure projects. Whether the wider ecosystem agrees will show up in enrollment numbers — and in how many enrolled projects quietly opt back out after their first flood of reports.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →