Anthropic launched OSS Scanner on October 8, 2026: a free, opt-in service that runs its most capable models, including Claude Mythos, against open source codebases to find vulnerabilities before attackers do. Enrolled projects get periodic scans and reports that include a working reproducer, an explanation of the bug, and often a candidate patch. There’s no cost to maintainers, and no catch beyond one real one: the reports arrive with zero human review before they land in your inbox.
The service sits inside what Anthropic calls its Cyber Mission, launched the same day alongside a separate Critical Infrastructure Defense Program. Only core maintainers can enroll, and only for projects Anthropic judges to have “critical impact on infrastructure and user security,” using criteria modeled on Google’s OSS-Fuzz program. Enrollment happens through a pull request to Anthropic’s GitHub repo using a standard template, not a sign-up form.
What the Numbers Actually Say
Anthropic backs the launch with real figures from six months of internal testing, not just a confident pitch. Its models surfaced over 29,000 candidate vulnerabilities in that window. Roughly 6,000 got manual review and triage, and close to 5,000 reports went straight to maintainers, some unvalidated, at the maintainers’ own request. In a tighter validation pass, security experts checked 97 critical and high-severity findings across 48 projects: 85 of them, or 88 percent, met Anthropic’s bar for coordinated disclosure. Of the rest, 11 were real bugs that duplicated something already known, and one was a flat false positive.
Anthropic also points to the CyberGym benchmark, where it says LLMs went from catching under 20 percent of planted vulnerabilities to over 85 percent. That jump is the actual story here, more than the scanner itself: it’s a marker of how fast AI-assisted vulnerability hunting has moved in roughly a year.
The Part Maintainers Should Read Twice
Reports are fully model-generated, and Anthropic says so plainly: no human reviews or triages a finding before it reaches a maintainer’s inbox. Some maintainers who tested it early said severity ratings ran inflated, or that the scanner misjudged their project’s actual threat model. Human-verified findings still route through Anthropic’s existing coordinated disclosure process, which matters most for small projects that have no one available to triage a flood of AI-written reports on their own.
That tradeoff is worth sitting with for a second. A free scanner that finds real bugs is a genuine gift to under-resourced open source maintainers, most of whom are volunteers. But a maintainer with no time to triage 50 AI-generated reports a month isn’t necessarily better off than one with none at all. The value here depends entirely on whether a project has the bandwidth to sort signal from noise, which is exactly the kind of downstream maintenance cost that gets ignored when a new AI tool ships.
Why This Matters Beyond Open Source Maintainers
This is the same pattern we flagged when Google shipped Gemini 4 Argon to cybersecurity defenders before anyone else and when OpenAI’s GPT-6 Astra crossed a critical cybersecurity threshold: the frontier labs are racing to put AI on the defensive side of security work before it gets weaponized on the offensive side. For any business running on open source software, which is effectively everyone, that race is good news, but it’s not a reason to assume your stack is now automatically safer. OSS Scanner only covers projects maintainers choose to enroll, and enrollment is selective.
If your team is weighing where AI genuinely earns its place in a security or development workflow versus where it just adds noise to manage, that’s the exact judgment call we help clients make through our AI development work: integrating AI where it reduces real risk or cost, not bolting it on because it’s available.



