Anthropic OSS Scanner audits open source code for free
The service runs Anthropic's strongest models over opt-in repositories and ships a reproducer, a candidate patch and a bisect with every finding.
In short
Anthropic's OSS Scanner gives opted-in open source projects recurring vulnerability scans by the company's strongest models at no cost.
At a glance
- OSS Scanner: free recurring scans of enrolled open source projects by Anthropic's strongest models.
- Each report carries a self-contained reproducer, a candidate patch where possible, and a bisection to the offending commit.
- Early version: pen testers checked 97 critical and high-severity findings across 48 projects and cleared 85.
- wolfSSL: 74 reports in early trials, all but two valid, five turned into CVEs.
- Launched alongside: a critical infrastructure program with 11 founding partners; commercial terms undisclosed.
Anthropic will scan open source projects for security flaws at no charge. Projects that opt in get recurring passes from the company's strongest models, and nothing in the loop waits on a human reviewer. The service is called OSS Scanner.
What lands in a maintainer's inbox
Every report bundles three things: a self-contained reproducer, a candidate patch when the model can produce one, and a bisection pinning the commit that introduced the flaw. The framing matters more than the scanner itself. Anthropic's argument is that discovery stopped being the bottleneck a while ago, and that verifying, triaging and repairing is where the labor still sits.
Skipping human pre-review is a deliberate trade. Maintainers hear about a flaw sooner, and they also inherit the model's mistakes — the company specifically flags severity ratings that come back wrong. A report is a lead, not a verdict.
The hit rate so far
The penetration testers who vet Anthropic's coordinated disclosures went through 97 critical and high-severity findings from an early version, spread across 48 projects. They cleared 85 for disclosure. Of the remaining 12, all but one were genuine bugs that duplicated either known issues or other findings from the same scan.
One maintainer has published its own tally. wolfSSL, which builds an encryption library for embedded systems, received 74 reports during early trials; all but two held up, and five became CVEs.
Getting in
Enrollment runs through GitHub, with core maintainers opening a pull request against an Anthropic repository. Eligibility borrows the OSS-Fuzz bar — projects of "critical impact on infrastructure and user security" — and each case is judged on its own.
The bill goes to the Defender Advantage Fund, set up in August 2026, which has also backed the Python Software Foundation, the Apache Software Foundation, Alpha-Omega and the OpenSSF.
Grids and water systems get a separate program
The same day, Anthropic opened a critical infrastructure effort that puts frontier models and onsite engineers inside power and water utilities. 11 providers signed on as founding partners, spanning consultancies, operational-technology security vendors and industrial equipment makers. The target is the gear in plants and substations that runs for decades and cannot simply be taken offline to apply a patch.
Andrew Turner, who leads commercial cyber at Booz Allen, calls that operational technology "the next frontier for autonomous AI-enabled attacks." Several partners already lean on Claude to close vulnerabilities. The predecessor, Project Glasswing, ran from April to October 2026 and gave vetted organizations access to Claude Mythos; it now folds into an expanded Cyber Verification Program.
What nobody has priced
The infrastructure program's commercial terms are blank. Per the report, Anthropic has not said whether access is free or who pays for the compute. The company expects AI to tilt toward defenders within two years — even as the cost of mounting an attack keeps dropping and confirming a fix stays slow.
FAQ
Does Anthropic's OSS Scanner cost anything?
Not for enrolled open source projects. Compute is paid out of the Defender Advantage Fund, which Anthropic set up in August 2026.
How does an open source project sign up for OSS Scanner?
Core maintainers open a pull request against an Anthropic GitHub repository. Eligibility follows the OSS-Fuzz criteria and is assessed case by case.
How accurate are findings that no human reviewed?
In an early version, testers cleared 85 of 97 findings; of the other 12, all but one were real but duplicate bugs. Wrong severity ratings do slip through.