
OSS Scanner offers free AI audits without human validation
Anthropic's OSS Scanner offers free security checks for open-source projects, but its AI-generated findings may be false positives and need verification.
Anthropic has introduced OSS Scanner, a free, opt-in service that uses artificial intelligence (AI) to examine open-source software, whose source code is available for others to inspect. Participating projects will receive recurring security scans from the company's most capable models. The important qualification for maintainers is that reports are generated entirely by models, without a required human check before delivery, and may flag problems that are not real vulnerabilities.
Anthropic announced the service on Thursday and said its design draws on Project Glasswing, its work using Claude to identify software weaknesses. Models expected to produce the reports include Claude Mythos. The company presents the absence of mandatory human review and triage, the process of checking and prioritising findings, as a way to scan more frequently and deliver results faster. That makes a report a starting point for investigation, rather than proof that a project contains an exploitable flaw.
Admission will not necessarily follow automatically from applying. Anthropic expects to assess projects using criteria resembling those of Google's OSS-Fuzz, a service that tests open-source software for defects, although it says its selection process could change. Maintainers should explain briefly why their project matters when that importance is not obvious. The source report recorded 116 submitted pull requests at the time of writing, a count of applications rather than confirmed participating projects.
Core maintainers apply through a pull request, a proposed repository change, on the OSS Scanner GitHub repository, where the service's project files are stored. The submission must include a YAML configuration file, a text file containing structured settings. Required entries are the address of the git repository to copy for analysis, a primary contact email address and the location within the repository of a Dockerfile. That file provides instructions for assembling the software environment in which the audit will run.
The Dockerfile must prepare the environment, install dependencies, meaning the other software the project needs, and build the project. This preparation allows the automated auditing agent to examine the code without internet access. Anthropic recommends checking that the project's tests succeed inside the resulting container, the packaged environment used to run the software. For applicants, supplying a reproducible working environment is therefore part of enrolling, not an optional step after a scan begins.
Maintainers can also provide additional email recipients, a project home page and a GPG public key, an encryption key that can be used to protect emailed reports. Another optional setting identifies the location of threat_model.md within the repository. This threat model file can describe which code to inspect, how to classify vulnerabilities or how reports should be formatted. Setting disabled: true lets a project opt out of receiving bug reports.
OSS Scanner will not initially attach a standard 90-day disclosure deadline to its findings. Anthropic says that decision reflects the possibility of false positives, reports that identify a problem where no genuine vulnerability exists. This distinction matters to teams receiving automated results: a finding should not be treated as a confirmed security advisory simply because a model generated it.
A separate route applies if Anthropic later validates a report manually through its existing coordinated vulnerability disclosure (CVD) programme, the process of notifying affected maintainers before publishing details. In that case, the company may disclose the issue under its CVD policy, with the 90-day period starting when the maintainer is told that a human has validated the report. Anthropic also leaves open the possibility of future disclosure deadlines for some high-severity findings if confidence in OSS Scanner improves. Neither possibility is an unconditional deadline on every automated report today.
Anthropic says it has identified more than 29,000 candidate vulnerabilities in major software projects and reported a little more than 6,000 flaws to maintainers. That work had resulted in 584 advisories as of October 2, 2026. These are company-reported figures, not independently verified measurements in the supplied account, and the newly announced scanner should not be credited with all those results. Candidate findings, reports to maintainers and published advisories represent different stages of investigation and disclosure.
Alongside the scanner, Anthropic introduced the Critical Infrastructure Defense Program as part of its Cyber Mission, covering critical infrastructure and open-source software. The company describes the initiative as a response to AI helping attackers find and exploit flaws and automate attacks at greater speed and scale. Its stated goals include equipping defenders, speeding up fixes and exploring safer software designs and coding practices. Anthropic predicts that within two years AI will favour defence by helping teams catch defects before release, develop more secure software and actively defend systems. That is the company's forecast, not an established outcome.
For website owners and IT teams, the immediate relevance is the security of the open-source components their services rely on. OSS Scanner enrolment is a task for core project maintainers, not a substitute for installing verified updates or checking a supplier's security notices. AEU-I's security-first IT, infrastructure and consulting services are relevant to businesses seeking support with those wider security responsibilities, separately from Anthropic's scanning programme.
The practical distinction is between receiving more potential findings and establishing which ones require a fix. OSS Scanner offers maintainers another source of security leads at no cost, while its disclosure policy explicitly recognises that automated output can be wrong.
How to Protect Yourself
- Ask your website provider which open-source software your site uses and where its official security notices are published.
- Install security updates for your website software when its official maintainers release them.
- If someone sends you an OSS Scanner finding about your site, ask your developer to verify it before making changes.
- If you maintain an open-source project, check the OSS Scanner enrolment instructions and choose a contact email address you monitor regularly.
Terms Explained
- open-source software Software whose underlying code is available for people to examine.
- pull request A proposal to add or change files in a shared software project.
- Dockerfile A file of instructions for creating the environment needed to run a piece of software.
- dependencies Other software that a project needs in order to work.
- false positives Results that incorrectly identify something as a genuine problem.
- coordinated vulnerability disclosure A process for informing software maintainers about a security flaw before sharing its details publicly.