Anthropic OSS Scanner: Free AI Security Scans for Open Source (How to Enroll)

TL;DR
Anthropic launched OSS Scanner on October 8: opt-in, unreviewed vulnerability reports from its strongest models, free for eligible open-source projects. What the enrollment PR needs, what you receive, and the triage cost nobody is pricing in.
Anthropic launched OSS Scanner on October 8: an opt-in service where maintainers of eligible open-source projects get periodic vulnerability reports straight from Anthropic's strongest models, with no human review in between and no charge. It arrived inside a bigger announcement, the Anthropic Cyber Mission, but OSS Scanner is the part a maintainer can act on today.
The mechanism is deliberately small: you open a pull request that adds a config file to a public repo. The interesting question is not how to enroll. It is whether your project can absorb what comes back.
What Anthropic announced#
The Anthropic Cyber Mission has two starting areas. The first is critical infrastructure: a Critical Infrastructure Defense Program that puts frontier models, on-site engineers and threat research behind providers who secure power grids, water systems and transport. Named founding partners include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. The second is open source, where OSS Scanner is the first product.
Two context points from the announcement. Anthropic says it merged Project Glasswing into an expanded Cyber Verification Program earlier this week, and it says plainly that the Glasswing partners "uncovered many vulnerabilities, but we haven't yet achieved a sufficient reduction in cyber risk." Finding bugs got cheap. Verifying and fixing them did not.
The numbers behind OSS Scanner#
From the launch post from Anthropic's Frontier Red Team (all figures are vendor-reported):
- Over six months of scanning, Anthropic found more than 29,000 candidate vulnerabilities and has manually reviewed roughly 6,000 of them.
- It has already sent nearly 5,000 reports to maintainers who asked for everything, validated or not. OSS Scanner formalizes that request.
- To validate an early version, penetration testers checked 97 critical and high-severity findings across 48 projects. 85 (88%) met the bar for Anthropic's disclosure process. Of the other 12, 11 were real but duplicates, and one was a false positive.
- Anthropic expects a true-positive rate above 90 percent, and warns that some reports will carry errors such as a wrong severity rating.
- On the CyberGym benchmark, it says LLMs went from finding under 20 percent of vulnerabilities early last year to over 85 percent now.
Maintainer quotes Anthropic published are positive. wolfSSL's Todd Ouska says all but two of 74 reports were valid and five became CVEs. These are testimonials selected by the vendor, so weigh them accordingly.
How enrollment works#
Per the OSS Scanner FAQ, core maintainers enroll by opening a PR to anthropics/oss-scanner that adds projects/<project>/project.yaml. The project template defines the fields:
repo: https://github.com/example/project#main
primary_contact: security@example.org
auto_ccs:
- maintainer@example.org
homepage: https://example.org
disabled: false
dockerfile: .oss-scanner/Dockerfile
threat_model: .oss-scanner/threat_model.md
What matters in practice:
- The Dockerfile is the real work. It must build the project and pre-install every dependency, because the scanning agent runs with no internet access after the build. Anthropic recommends confirming your tests pass inside the built container.
- The threat model file is optional but "strongly recommended." It is where you tell the scanner which inputs are adversarial, what is out of scope, how to rate severity, and whether you want minimal proof-of-concept patches or merge-ready ones. Without it the scanner guesses at corner cases.
- PGP is supported but exclusive. Set
pgpand reports are encrypted to the primary contact only, so you cannot also useauto_ccs. - Pausing is a one-line PR. Set
disabled: true, or delete your project directory to leave. You then revert to the normal human-reviewed disclosure process. - Eligibility follows OSS-Fuzz criteria: critical impact on infrastructure and user security, remote-attack exposure such as parsing untrusted input, and how many projects depend on you. Anthropic says it will verify you are a core maintainer before enrolling.
One catch in the docs themselves: the FAQ names the field Dockerfile while the template uses lowercase dockerfile. Run tools/validate.py from the repo before you open the PR, as Anthropic suggests.
What changes for a maintainer#
Reports arrive by email as a bundle: a self-contained reproducer, an explanation, a bisection to the commit that introduced the bug where possible, and a candidate patch when available. After the first scan, Anthropic rescans periodically for new bugs and ones it missed. There is no 90-day disclosure clock on unvalidated findings, so you are not forced to read them on a deadline. If Anthropic later validates one manually, a 90-day clock can start from the day you are told.
If you patch a bug the scanner found, Anthropic asks for a credit line with the report ID, like ANT-2026-ABCD1234, in your commit message. Optional, but it helps them track what they got right.
The angle: free scanning moves the cost to triage#
This is the same bottleneck we covered when AI scanners first moved the problem to triage. Anthropic's own numbers show it: 29,000 candidates, 6,000 reviewed by humans. OSS Scanner does not fix that bottleneck. It hands it to you, deliberately, for projects that asked.
Who wins: well-staffed projects with a security team, a good test suite and a CI that can validate a patch in minutes. For them, a reproducer plus candidate patch is a gift. PostgreSQL's Noah Misch is quoted saying fast-track access let the project address the newest issues before a general-availability release.
Who loses: small projects that enroll for the free scan and then cannot keep up with a high-severity inbox. Anthropic says as much: the service is for projects "able to keep up with verified high/critical vulnerability reports." The practical Monday move is to write the threat model file first. It is the cheapest lever you have over report quality, and it costs nothing.
The second-order effect is on the rest of the field. Google's OSS-Fuzz set the template, and OpenAI's Codex Security and its gated GPT-5.6-Cyber already target the same defenders. Expect competing free-scan programs, and expect maintainers to compare reproducer quality, not model names. The reason Anthropic is moving now is spelled out in its recent GLM-5.3 cyber report: if capable open-weight models can build exploits, the bug-finding advantage is only temporary.
What people are actually saying#
The OSS Scanner launch is under a day old and we found no dedicated Hacker News or Reddit thread yet. The nearest signal is the older Glasswing and Mythos discussion, which shows the arguments this launch will meet:
- In the Project Glasswing update thread, maintainers said they had applied to AI-lab open-source programs without hearing back, and that the burden of handling a flood of AI-found findings falls on unpaid volunteers who never asked for it. Others argued the real bottleneck is human capacity to triage, verify and patch, and that cost per scan was out of reach for small projects.
- In the thread on vulnerability spikes after the Mythos Preview release, supporters said more reports are good because they force overdue cleanup, while skeptics described a torrent of unverified reports and suggested that similar results are possible with other models given a big enough token budget.
- A recent r/linux commenter, in a thread on X.Org Server vulnerabilities, called the AI-lab push "a PR campaign masking a bug bounty program." That is one commenter's view, summarized from a search excerpt, and not a measured one.
The counter-case worth taking seriously: OSS Scanner is opt-in, free, and cancellable with a one-line PR. That is a real improvement over unsolicited reports.
FAQ#
What is Anthropic OSS Scanner?#
An opt-in service that scans open-source projects with Anthropic's strongest models, including Claude Mythos, and emails vulnerability reports directly to maintainers without human review. It is free for accepted projects.
How do I enroll my project in OSS Scanner?#
Core maintainers open a PR to anthropics/oss-scanner adding projects/<project>/project.yaml, plus a Dockerfile that builds the project offline-ready. A threat_model.md is optional but recommended.
Which projects are eligible?#
Anthropic uses criteria similar to OSS-Fuzz: established projects with critical impact on infrastructure and user security, judged case by case. It verifies that the requester is a core maintainer.
How is OSS Scanner different from Claude Security?#
Claude Security is Anthropic's commercial code scanning and patching product for enterprises. OSS Scanner is a free service for open-source maintainers that Anthropic says also uses additional, token-hungry experimental harnesses.
Sources#
- Introducing the Anthropic Cyber Mission - Anthropic, October 8, 2026
- An opt-in vulnerability-finding service for open-source software - Anthropic Frontier Red Team, October 8, 2026
- OSS Scanner FAQ and terms - Anthropic Frontier Red Team
- anthropics/oss-scanner project template - GitHub
- Hacker News: Project Glasswing: An Initial Update - 561 points, accessed October 9, 2026
- Hacker News: New serious vulnerabilities spiked around release of Claude Mythos Preview - 156 points, accessed October 9, 2026
- Reddit r/linux: Another Dozen Vulnerabilities Found In The X.Org Server & XWayland - accessed October 9, 2026
Continue Reading#
- AI Security Scanners Move the Bottleneck to Triage - why finding bugs got cheap and fixing them did not
- Anthropic's GLM-5.3 Cyber Report - the open-weight exploit numbers behind the urgency
- Claude Mythos Preview Explained - the gated model behind the scans
- Codex Security Preview - OpenAI's AppSec agent for real repos
- OpenAI Ships GPT-5.6-Cyber Through Daybreak Red - the gated competitor
Get the next deep dive like this in your inbox
One email a week on News and the rest of the AI dev stack. Free.
Read next on Claude Code
AI Security Scanners Move the Bottleneck to Triage
Anthropic's Project Glasswing update is a useful signal for developer teams: AI can find vulnerability candidates faster than humans can verify, disclose, patch, and ship them.
8 min readAnthropic's GLM-5.3 Cyber Report: The Numbers, the Backlash, and What Developers Should Take From It
Anthropic's Frontier Red Team says GLM-5.3 builds working exploits at rates close to Claude Mythos Preview, and that its safeguards can be stripped in days. Here are the verified numbers, the community backlash, and the practical read for developers.
6 min readClaude Mythos Preview Explained: Anthropic's Gated Frontier Model and Project Glasswing
Claude Mythos Preview is the model that found thousands of zero-days, and you could not buy it. Here is what it is, who got access through Project Glasswing, what it actually found, and where the model line went after it retired.
7 min readTechnical content at the intersection of AI and development. Building with AI agents, Claude Code, and modern dev tools - then showing you exactly how it works.







