iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Anthropic has launched OSS Scanner, an opt-in vulnerability scanning service that gives eligible open-source projects periodic scans by its strongest models at no cost. Anthropic announced it on October 8, 2026. Enrollment is case by case, so being eligible to apply is not the same as being accepted, and every report the service sends is a lead for your team to check, not a confirmed bug.
What OSS Scanner is
OSS Scanner is a free, opt-in service for open-source projects. Enrolled projects receive periodic scans run by Anthropic’s strongest models. Anthropic presents the service as part of its broader Cyber Mission, which also addresses defense of critical infrastructure. The announcement names Google’s OSS-Fuzz as an inspiration. OSS-Fuzz scans open-source software with fuzzers, and Anthropic uses it only as context. It does not claim that OSS Scanner works the same way.
Who can enroll and how to apply
The service targets eligible open-source projects with critical impact on infrastructure and user security. Anthropic says only core maintainers can enroll, and it reviews each request individually. The application is a pull request, not a web form.
- Confirm that you are a core maintainer of an open-source project. Anthropic restricts enrollment to core maintainers.
- Assess your project against the criterion Anthropic names: critical impact on infrastructure and user security. Projects that protect widely deployed software or sensitive user data are the clearest fit.
- Open a pull request to the GitHub repository Anthropic designates for OSS Scanner enrollment, using the standard project template. The repository location is given in Anthropic’s October 8, 2026 announcement.
- Wait for Anthropic’s case-by-case decision. Anthropic does not describe the review timeline in its announcement.
What a report contains
Anthropic says each finding can arrive with the following parts:
#1 Best Overall
- A self-contained reproducer that demonstrates the issue without requiring the maintainer to reconstruct the scenario.
- An explanation of the vulnerability describing what goes wrong and why.
- A bisection of when the bug was introduced, where the service can determine it. This tells you which commit to examine and which released versions may be affected.
- A candidate patch, when one is available.
Treat every report as a lead to verify
OSS Scanner sends model-generated findings without human review or triage. Anthropic says this allows faster and more frequent scans, but it also warns that findings may be incorrect or invalid. The service is intended for projects that have the capacity to keep up with findings. For projects without that capacity, Anthropic says it will continue running human-verified coordinated vulnerability disclosures.
A practical triage sequence for a new report looks like this:
- Run the reproducer in an isolated environment and record whether it triggers the described behavior.
- Confirm the affected code path and the versions the bisection points to.
- Search your issue tracker and security advisories for duplicates or overlapping reports.
- Review any candidate patch as you would an external contribution. Run your test suite and check that it does not change behavior beyond the fix.
- Decide the disclosure route. Confirmed issues should go through your normal coordinated disclosure process, not into public issues.
What Anthropic has published about results
Anthropic has released figures from its own evaluation. They describe its work, not independent audits, so attribute them to Anthropic and read them within the scope given below.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Scale of findings
Anthropic reports more than 29,000 candidate vulnerabilities found across the projects it scanned over six months. About 6,000 of those had been manually reviewed and triaged. Nearly 5,000 unverified reports had been sent directly to maintainers who asked to receive all findings. Most of the candidates were therefore never reviewed by a person before they reached a maintainer.
Validation of an early version
Anthropic had expert penetration testers review 97 critical and high-severity findings from 48 projects. Of these, 85 met Anthropic’s coordinated disclosure bar. Of the remaining 12, 11 were real but were duplicates or otherwise overlapping, and one was invalid. This is Anthropic’s reported validation of an early version of the service, not an assessment of all future reports.
Expected true-positive rate
Anthropic’s Cyber Mission announcement says it expects a true-positive rate above 90% and intends to improve both the true-positive rate and fix quality. This is an expectation Anthropic states, not a measured result for the service as it runs today.
A figure from a different product
Anthropic has also cited more than 500 vulnerabilities found in production open-source codebases using Claude Opus 4.6. That figure comes from its February 20, 2026 Claude Code Security announcement. It does not describe OSS Scanner’s October results.
What early participating projects said
Anthropic’s October 8 post quotes four maintainers. These are testimonials from early participants, and they do not replace independent measurement of how the service performs over time.
Rank #3
Noah Misch, PostgreSQL: “An unusually high fraction of OSS Scanner’s findings uncovered PostgreSQL defects. Several reports came with fixes we can use nearly as-is, and fast-track access let us address the newest issues before they reached a GA release.”
Anton Arapov, OpenSSL Corporation: “Early AI reports about 18 months ago, before Project Glasswing, were appalling. The reports we received from Anthropic, raw model output included, were as good and sometimes better than what we get from people. Particularly when a report comes with a real exploit attached, that’s basically job done for an engineer as you can verify it right away”
Todd Ouska, wolfSSL: “We found the signal from these reports high: of the 74 reports we received, all but two were valid, and five became CVEs. With patches attached, the reports slotted right into our existing process to verify and fix issues. We’d love more.”
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Eddie Kohler, HotCRP: “The bug reports were thorough and clear, with a strong understanding of HotCRP’s complex permission model and good bug prioritization.”
How OSS Scanner differs from Anthropic’s other security products
Anthropic offers several security products, and they serve different audiences. The table below compares the three that appear in its announcements.
| Product | Status and audience | Human review before findings reach you |
|---|---|---|
| OSS Scanner (announced October 8, 2026) | Free, opt-in periodic scanning for eligible open-source projects, enrolled case by case | None. Reports are model-generated and sent without human review or triage |
| Claude Code Security (announced February 20, 2026) | Limited research preview for Enterprise and Team customers, with expedited access for open-source maintainers | The tool re-examines findings and suggests patches; developers decide whether to approve fixes |
| Claude Security | General-access code scanning and patching product for enterprises defending their own systems | Not stated in Anthropic’s announcements |
Claude Code Security and OSS Scanner should not be confused. The first includes developer approval of fixes; the second does not include human review before delivery.
Related programs for maintainers
Two other Anthropic programs may matter to open-source maintainers. Neither one enrolls you in OSS Scanner automatically.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall- Claude for Open Source lets maintainers apply for free Claude Max subscriptions to help remediate vulnerabilities and improve their projects.
- Cyber Verification Program lets qualifying security professionals apply for expanded access to defensive cyber capabilities.
How to compare OSS Scanner with other vulnerability tools
Anthropic’s announcements do not include a feature-by-feature comparison with other scanners. If you are weighing OSS Scanner against another tool, these are the questions that separate them:
Best Value
- Is the service free or paid, and does the price cover periodic scanning or single runs?
- Which projects or codebases qualify, and who decides?
- Is scanning opt-in, and how often does it run?
- Does a person review findings before you receive them?
- What evidence comes with each finding, such as a reproducer, a bisection, or a patch?
- Does your team have the staff to validate and fix what arrives?
For OSS Scanner, the first, third, and fifth answers are documented by Anthropic. The fourth answer is no, and the last answer depends on your project.
What remains unestablished
Anthropic’s announcements do not specify several details maintainers will want to know:
- How often enrolled projects are scanned. Anthropic says only that scans are periodic.
- How long an enrollment decision takes.
- Which programming languages are supported.
- Any repository size limits.
- Whether there are geographic restrictions on enrollment.
- Independent measurements of accuracy or fix quality for the service as it runs now.
Until Anthropic publishes these details, check its announcement and the enrollment repository before planning around any of them.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

