Anthropic has launched OSS Scanner, an opt-in service that gives open-source projects free, periodic vulnerability scans from its strongest models, including Claude Mythos. Reports go straight to maintainers with no human review, which makes them faster but means some will be wrong.
The service is inspired by Google’s OSS-Fuzz, which runs fuzzers against open-source code. Anthropic already scans open-source software and sends reports after human vetting through its coordinated disclosure process. Of the more than 29,000 candidate vulnerabilities its models found over the past six months, staff have manually reviewed about 6,000, according to SiliconANGLE. OSS Scanner is the fast track for projects that don’t want to wait in that queue.
What maintainers get
Each report includes a self-contained reproducer and an explanation of the bug. Where the model can manage it, the report also adds a bisection showing when the flaw was introduced, plus a candidate patch. The Verge notes that the output is “fully model-generated, without human review or triage”, in Anthropic’s words, so incorrect or invalid reports are possible. Anthropic says an error might be something as simple as a wrong severity rating.
Anthropic has published early accuracy figures. Expert penetration testers checked 97 critical and high-severity findings from an early version across 48 projects and cleared 85 for disclosure. Of the other 12, all but one were real bugs that duplicated known issues or other findings. Embedded encryption library developer wolfSSL said all but two of the 74 reports it received in early trials were valid, and five became CVEs.
How to enrol
Core maintainers enrol by opening a pull request to the anthropics/oss-scanner GitHub repository that adds a `project.yaml` config file. Pivot News reports that the file includes a repository link, a contact address and a path to a Dockerfile, so the scanning agent can build and audit the project in a sandbox with no internet access.

Eligibility isn’t open to everyone. Anthropic borrows the OSS-Fuzz test of “critical impact on infrastructure and user security” and decides case by case. It will confirm that an applicant is a core maintainer first, and may tighten the criteria depending on demand. Projects without the staff to triage raw findings still get human-verified reports through the existing disclosure process.
The scans stay free through the Defender Advantage Fund that Anthropic set up in August. Maintainers can also apply for free Claude Max 20x subscriptions through a separate Claude for OSS programme to help fix what turns up.
Part of a wider cyber push
OSS Scanner launched alongside a Critical Infrastructure Defense Program under a new effort called the Anthropic Cyber Mission. That programme brings Anthropic’s models and engineers to 11 founding partners, among them Accenture, Deloitte, CrowdStrike and Palo Alto Networks, which protect power grids and water systems. Anthropic hasn’t said who covers the computing costs for those partners.
Both build on Project Glasswing, which gave vetted organisations access to Mythos from April. Anthropic admits that finding vulnerabilities has become easy, while verifying, prioritising and fixing them remains hard. The company expects AI to favour defenders within two years.
Anthropic’s announcements don’t mention region-specific availability, and nothing in them is UAE-specific. The enrolment process is a GitHub pull request, so maintainers anywhere can apply if their project qualifies. For more on Anthropic’s recent moves, see our coverage of Claude Haiku 5.5 and the company’s new usage policy.
Does OSS Scanner cost anything?
No. Anthropic says enrolled projects get periodic scans at no cost, funded by its Defender Advantage Fund.
Can any open-source project join?
Only eligible ones. Anthropic uses OSS-Fuzz-style criteria, meaning critical impact on infrastructure and user security, and verifies that you’re a core maintainer before enrolling a project.
Will a human check the reports?
No. Reports go to maintainers unreviewed, so some may be incorrect. Projects that prefer verified findings can use Anthropic’s existing coordinated disclosure process instead.


















