explainx.ai0k
TrendingAI News TodayPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

follow on google

Add explainx.ai as a preferred source

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

community

Join the community

learn

mind: share how you thinkpathways — start freeworkshopsbootcampscoursescompare Explainxcertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsmdx readeragentsllmsdesignsdictionarypeopleagi trackerfelony benchranks

company

aboutvisionmissionteaminstructorsteach on explainxpartnershipscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

explainx.ai

On this page

  • OSS Scanner at a glance
  • Why Anthropic built it
  • How enrollment works
  • Why the threat model file matters
  • The trade-offs: unreviewed reports and no disclosure clock
  • Should you enroll? A quick decision guide
  • How it differs from Claude Security and from fuzzing
  • Security of the pipeline itself
  • Why this matters beyond Anthropic
  • What we could not verify
  • Related reading
← Back to blog

explainx / blog

Anthropic OSS Scanner: Free AI Vulnerability Scans for Open-Source Projects

Anthropic, Cybersecurity, Open Source, AI Security, Claude

Anthropic OSS Scanner gives open-source maintainers free, unreviewed vulnerability reports from its strongest models. How to enroll, the catches, and FAQ.

Oct 8, 2026·9 min read·Yash Thakker
add explainx.ai
go deep
Anthropic OSS Scanner: Free AI Vulnerability Scans for Open-Source Projects

Anthropic has launched OSS Scanner, a free, opt-in service that scans open-source repositories for security vulnerabilities with its strongest models and emails the findings straight to maintainers. The service is described on Anthropic's red team page and runs through a new anthropics/oss-scanner GitHub repository, where projects enroll by pull request. The notable design choices: the reports skip human review, there is no 90-day public disclosure clock, and Anthropic pays the compute bill.

If you maintain a widely used library, that is a real offer: a deep scan by a frontier model, with a reproducer and often a patch, for the price of writing a Dockerfile. If you maintain a small project already drowning in AI-generated reports, the fine print matters. This guide covers both sides.

OSS Scanner at a glance

table · 2 cols
QuestionAnswer
What is it?A free service that scans open-source repos for vulnerabilities with Anthropic's strongest models
Who runs it?Anthropic, informed by its experience finding bugs during Project Glasswing
What does it cost?Nothing; Anthropic says it covers the full cost
Are reports human-reviewed?No, model-generated and unreviewed
Is there a 90-day disclosure deadline?No, not on these unvalidated findings, and they will not be made public
How do I join?Open a PR adding projects/NAME/project.yaml to the anthropics/oss-scanner repo
Who can join?Core maintainers of established, high-impact projects (OSS-Fuzz-like criteria)
How are reports delivered?By email to the primary contact, optionally PGP-encrypted

Why Anthropic built it

Anthropic already runs a coordinated vulnerability disclosure (CVD) program: it scans open-source software, has humans validate the bugs, and then reports them to maintainers. According to the OSS Scanner page, the company had reviewed over 6,000 such reports by October 2026. The catch is speed. Manual review takes time, so valid findings can sit before they reach the people who can fix them.

OSS Scanner is the optional fast track. Projects that enroll get reports "as soon as they're scanned," directly from the model. Anthropic frames it as a trade: you accept the possibility of false positives, and in return you get findings earlier and on your own terms.

This follows a pattern we have tracked all year. Anthropic's Mythos-class models proved good at finding security bugs, which is why Claude Mythos Preview and Project Glasswing existed in the first place, and why the company later built a tiered access scheme in its Cyber Verification Program. The government's reaction to those capabilities is covered in our posts on Fable 5 and Mythos 5 and the US export-control action. OSS Scanner is the defender-side release of the same capability, pointed at the commons.

Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

How enrollment works

According to the repository README and the OSS Scanner page, the process is a pull request:

  1. Add a directory. Create projects/NAME/ in the anthropics/oss-scanner repository.
  2. Write project.yaml. Two fields are required: repo (the git URL, optionally with a branch after a hash sign) and primary_contact (one email address). Optional fields include auto_ccs, homepage, threat_model, pgp, and disabled.
  3. Provide a Dockerfile. It must set up the environment, install every dependency, and build the project. Setup runs with network access; the security audit afterward runs with no internet at all, so anything the build or tests need must be fetched during setup. Anthropic recommends verifying that your tests pass inside the built image.
  4. Optionally add threat_model.md. This is where you tell the scanner what your project defends, which inputs are adversarial, what is out of scope, and how you rate severity.
  5. Validate locally. Run tools/validate.py before opening the PR.
  6. Get verified. Anthropic manually confirms you are a core maintainer before enrolling the project, and may contact you through other channels if unsure.

The Dockerfile can live in your own repo (the preferred option, since you can update it without another PR) or next to project.yaml in the Anthropic repo. A starting template sits in the repo's templates folder.

One detail to note: the email addresses in project.yaml are public, since the file is committed to a public repository. Use a security alias you are happy to see published. For encrypted reports, add an armored OpenPGP public key; in that case reports go to the primary contact only and cannot be combined with auto_ccs.

Why the threat model file matters

The README says the threat model is optional but "strongly recommended," and the advice behind it is practical. Scanners find many things; maintainers only care about some of them. Telling the model your severity rubric avoids a flood of low-value findings. Anthropic's examples: do you treat post-authentication SQL injection as high or critical? Are buffer overflows without a demonstrated exploit capped at high? When is stored XSS medium, high, or critical?

You can also tell the scanner what the project does, where untrusted input enters, which components matter, and how you want reports and patches formatted. If you have ever triaged a noisy automated report, this is the lever that makes the output usable.

The trade-offs: unreviewed reports and no disclosure clock

Two policies set OSS Scanner apart from the standard disclosure norm.

No human review. Reports are model-generated and, as the README puts it, not reviewed by a human. Anthropic warns that they may contain false positives. Each report is supposed to carry a reproducer, which is the maintainer's fastest way to check a claim, plus a proposed patch where one exists.

No 90-day deadline. The industry norm is a 90-day window after which the reporter may publish. Anthropic says it will not impose that on unvalidated findings, because it is "not comfortable forcing maintainers to carefully read each finding" it has not read itself. Findings will not be made public. If a report is later validated through the standard CVD program, a 90-day period can start from the date the maintainer is notified of human validation. Anthropic also says it may, in the future, impose disclosure periods on some high-severity reports as confidence grows, with notice and an opt-out.

That second policy is generous, and also a sign of how seriously the company takes the maintainer-burnout problem. The service page states plainly that it is built for projects "already able to keep up with verified high/critical vulnerability reports." If your queue is already overflowing, wait.

Should you enroll? A quick decision guide

table · 2 cols
If you are...Consider
A maintainer of a critical, widely used library with a security processEnroll; the cost is a Dockerfile
A small hobby project with no security contactProbably wait; you may not meet the eligibility bar
A project already swamped by automated reportsWait or enroll and set disabled: true until ready
Running a security team inside a company with proprietary codeLook at Claude Security instead; OSS Scanner is for open source
A researcher wanting early, public findingsThis service does not publish reports

You can pause at any time by adding disabled: true in a PR, or remove your project by deleting its directory. After opting out you return to the standard CVD process.

How it differs from Claude Security and from fuzzing

Anthropic distinguishes the service from Claude Security, its commercial offering for enterprises to find and fix vulnerabilities in their own code with Claude Mythos. OSS Scanner is aimed at open-source maintainers, applies "additional token-hungry and experimental harnesses" to look for deeper bugs, and covers the cost.

It also is not a replacement for fuzzing. The eligibility test is modeled on OSS-Fuzz, which accepts established projects with critical impact on infrastructure and user security, weighted by exposure to remote attacks and by dependent users. Fuzzing and model-driven code review find different bugs: fuzzers hammer input handling and need a harness; a model can read code, reason about logic flaws and authorization mistakes, and write a patch. Used together they cover more ground. For another example of agentic bug-hunting that maintainers can run themselves, see the open-source security audit skill from Cloudflare.

Security of the pipeline itself

Maintainers will reasonably ask where their vulnerabilities go. Anthropic says reports are held in an isolated, locked-down cloud project available only to security staff who need access to run the program, using the same practices as its standard CVD process. Scanning agents run only after internet access is fully disabled inside hardened sandboxes. That last point is also the reason the Dockerfile must pre-fetch everything: the agent cannot download anything during the audit.

The sandbox detail connects to a broader concern in the field. Isolation is only as good as the layer below it, a lesson from the Vercel KVM zero-day that escaped agent sandboxes. If your Dockerfile runs untrusted build steps, review them as you would any CI job.

Why this matters beyond Anthropic

Three trends meet in this launch:

  • AI-found bugs are now routine. Model-driven discovery has moved from demo to service. The question for maintainers is no longer whether AI will find bugs in their code, but who gets the findings first.
  • Attackers have the same tools. Our coverage of AI-linked bank breaches in South Korea shows the offensive side; a free defensive scan for critical libraries narrows the gap.
  • Disclosure norms are bending. A 90-day clock was designed for human-discovered bugs and human reviewers. When a model produces dozens of candidate findings, forcing maintainers onto a deadline is a recipe for burnout. Anthropic's choice to drop it for unvalidated reports may become a template.

What we could not verify

Anthropic's launch post reports that it checked 97 critical and high-severity findings across 48 projects: 85 (88%) met the bar for its disclosure process, 11 were real but duplicated known issues or other scan findings, and one was a false positive. Anthropic says it cannot guarantee the scanner will be perfect. That is the company's own sample, not an independent audit. We do not know how many projects have enrolled or which models are used beyond "our strongest models." Maintainer reports from the field will be the real test of signal versus noise, so check the repository for updates to the terms.

Details are accurate as of October 8, 2026; Anthropic says it may adjust acceptance criteria and policies as the service evolves.

Related reading

  • Claude Mythos Preview and Project Glasswing
  • Anthropic Cyber Verification Program: three tiers
  • Claude Fable 5 and Mythos 5 launch
  • Cloudflare's open-source security audit skill
  • Vercel KVM zero-day and agent sandboxes
  • South Korea AI bank hacks
  • Anthropic Cyber Mission and the Critical Infrastructure Defense Program
Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

View Yash Thakker in People in AI →

Related posts

Oct 8, 2026

Anthropic Cyber Mission: Critical Infrastructure Defense Program Explained

On October 8, 2026 Anthropic announced the Cyber Mission, a long-term defender-first effort that starts with a Critical Infrastructure Defense Program for operational technology and the free OSS Scanner for open source. explainx.ai breaks down who is in, what they get, and what is still unknown.

Oct 7, 2026

Anthropic Expands Its Cyber Verification Program Into Three Tiers

On October 6, 2026 Anthropic announced an expanded Cyber Verification Program with Defense, Red Team and Specialized tiers, and folded Project Glasswing into it. This post explains who qualifies, what each tier relaxes, what stays blocked, and what security teams should prepare before applying.

Sep 11, 2026

Anthropic Threat Intelligence Report: Claude Misuse Across Cyber, Weapons, Bio, and Distillation

On September 10, 2026 Anthropic published its most detailed Threat Intelligence report yet — case studies of Claude misuse disrupted between December 2025 and August 2026 across seven harm areas. explainx.ai separates what is in the primary report (including China-linked anti-torpedo work and Alibaba's 151M+ distillation campaign) from claims circulating on X and prediction markets.