Particle.news

Anthropic Launches Free AI Scanner for Open-Source Projects

The opt-in service uses Anthropic’s strongest models to send fully model-generated vulnerability reports that maintainers must triage.

Overview

  • Anthropic publicly rolled out OSS Scanner in early October 2026 as a free, opt-in vulnerability scanning service for open-source repositories.
  • Projects enroll by opening a pull request on the OSS Scanner GitHub repository and supplying a YAML file plus a repository-relative Dockerfile so the scanner can run an offline, reproducible build.
  • The scanner runs on Anthropic’s top models, including Claude Mythos, and delivers reports produced entirely by the models without human review, which speeds detection but raises the risk of false positives and overstated severities.
  • Anthropic said its prior work identified more than 29,000 candidate issues, reported about 6,000 flaws that led to 584 advisories as of October 2, 2026, and early tests showed 97 high or critical findings across 48 projects with 85 meeting coordinated-disclosure criteria.
  • Maintainers have already submitted interest—about 116 pull requests—and Anthropic lets projects pause or opt out of automated reports while it ties OSS Scanner to a wider Critical Infrastructure Defense Program and reserves the right to change its disclosure rules after further validation.