Trending: On-device modelsSearch
iHeartGeek
iTECH

Anthropic launches free AI security scans for open-source projects

Anthropic’s opt-in OSS Scanner promises periodic vulnerability reports from its strongest models, without human triage.

Abstract editorial illustration of a secure open-source code archive being scanned by protective beams in a server room.

Anthropic has launched OSS Scanner, an opt-in service that gives open-source projects periodic security scans from its strongest models at no cost. The service is designed to find vulnerabilities earlier, but its reports are fully model-generated and do not receive human review or triage before they reach maintainers.

What OSS Scanner does

Projects that sign up will receive recurring vulnerability reports based on Anthropic's experience using Claude during Project Glasswing. Anthropic says the scans can use its strongest models, including Claude Mythos, and are intended to give maintainers a larger defensive advantage as automated bug-finding improves.

Speed comes with a warning

The service's central trade-off is explicit: reports arrive faster and more frequently, but nobody at Anthropic is checking every finding before it is sent. A report can therefore be incorrect, invalid or based on a false positive. That matters for maintainers already dealing with a growing stream of AI-generated bug reports, where separating a useful disclosure from noise can consume almost as much time as fixing the underlying code.

Our opinion

OSS Scanner is a sensible experiment, provided everyone treats its output as a lead rather than a verdict. Open-source maintainers rarely have enough security capacity, and an automated second pair of eyes can find issues that would otherwise sit unnoticed. The absence of human triage is not a footnote, though: it shifts the cost of verification on to the projects Anthropic is trying to help. The service will be valuable if its reports are technically detailed, reproducible and easy to dismiss when they are wrong. If they arrive as a pile of plausible-looking guesses, it will add to the AI security-reporting problem rather than solve it. Anthropic is right to be transparent about that boundary; the maintainers who opt in should be just as clear-eyed.