Anthropic has launched OSS Scanner, a free, opt-in service that sends open-source maintainers model-generated vulnerability reports. Its central trade-off is explicit: projects can receive findings sooner and more often, but the reports arrive without human review or triage.
The OSS Scanner announcement says the service uses Anthropic's strongest models, including Claude Mythos. It targets maintainers with the capacity to investigate incoming reports. Anthropic says it will continue its coordinated vulnerability disclosure process for human-verified findings, particularly for projects that lack resources to handle a larger unverified stream.
The bottleneck moves from finding bugs to validating them
Anthropic reports more than 29,000 candidate vulnerabilities from six months of scans, with approximately 6,000 manually reviewed and triaged. The word candidate is important: the larger number does not establish that every item is a distinct, confirmed defect.
The company says some maintainers receiving initial reports asked for all remaining findings, even without validation. It reports sending nearly 5,000 such reports after those requests. OSS Scanner formalizes that optional faster route, rather than replacing human-verified disclosure for every project.
For a maintainer, receiving a report quickly is useful only if the team can establish what it means for the project. A scanner's severity assessment can differ from the project's threat model. Anthropic acknowledges that maintainers have sometimes flagged inflated ratings or misunderstandings of the threat model.
Reports include evidence and possible fixes
The service is intended to deliver a self-contained reproducer and an explanation of the vulnerability. Reports can include bisection to identify when a bug entered the codebase, where possible, and a candidate patch when one is available. Those conditions matter: the announcement does not promise a usable patch or complete historical analysis for every finding.
Anthropic says it tested early pipeline versions with dozens of projects. Its cited validation sample involved 97 critical or high-severity findings across 48 projects, checked by penetration testers who review its coordinated disclosures. Of those, 85 met the bar for that disclosure process.
The remaining twelve included eleven real issues that duplicated known bugs or other scan findings, plus one invalid report. That breakdown is more informative than treating every report outside the disclosure bar as a false positive. It also remains a selected early sample, not a guarantee of identical quality across all future scans or all severity levels.
The announcement includes feedback from PostgreSQL, OpenSSL, wolfSSL and HotCRP representatives. These are named participants' experiences supplied by Anthropic. They support the account of early use but do not replace an independent evaluation of the complete service.
Enrollment is for qualifying projects, not arbitrary targets
Core maintainers can seek enrollment through the project's specified GitHub submission process. Anthropic describes eligibility using criteria similar to OSS-Fuzz, including critical impact on infrastructure and user security, with decisions made case by case. The captured source does not establish automatic acceptance for every open-source repository.
The company distinguishes OSS Scanner from Claude Security, its enterprise scanning and patching product. It also mentions Claude for Open Source subscriptions and the Cyber Verification Program as separate support routes. Being eligible for one programme should not be assumed to confer access to another.
The useful decision for a project is whether it can keep up with incoming findings while preserving its existing review process. Reproducers and proposed patches may reduce investigation work, but someone must still verify the issue, judge priority and decide whether the change is correct. The service offers a faster supply of evidence, with those responsibilities remaining visible.