Anthropic launches free OSS scanner, skips human review

Anthropic launched OSS Scanner on October 8, offering free vulnerability scanning to open source projects that choose to opt in. The scanning is done by the company's own models, including Claude Mythos, and the resulting reports go straight to maintainers — with no human review or triage step in between.

Each report comes with a standalone reproduction program and a description of the flaw. When the scanner can pinpoint it, the report also includes the commit that introduced the bug, found through binary search, along with a proposed fix where possible. Anthropic's announcement notes that the reports may contain errors or turn out to be invalid.

Who can apply

Eligibility follows roughly the same bar as Google's OSS-Fuzz: a project must have a "critical impact" on infrastructure or user security, judged case by case. A project's core maintainers apply by submitting a pull request to the anthropics/oss-scanner repository on GitHub and filling out a template with project details.

The announcement doesn't say how often a given project gets scanned, or what the process looks like if a maintainer wants to withdraw midway. Disclosure follows a coordinated vulnerability disclosure (CVD) process, though the announcement doesn't spell out a specific timeline.

Numbers from the six-month trial run

Anthropic says that over the past six months, it used its models to scan open source code and surfaced more than 29,000 candidate vulnerabilities, of which humans reviewed roughly 6,000. An early testing phase identified 97 bugs judged high or critical severity across 48 projects; 85 of those met its disclosure process requirements, a rate of about 88%.

A separate set of numbers comes from the reports already sent out: close to 5,000 reports have gone to maintainers so far. In a sample of 74 that the company cited, maintainers confirmed 72 as valid, and 5 earned CVE numbers. Projects named in the announcement include PostgreSQL, OpenSSL, wolfSSL, HotCRP, and Linux.

"The reports we received from Anthropic, raw model output included, were as good and sometimes better than what we get from people."

Why drop the human step

Anthropic's stated reason is to make scanning "faster and more frequent." Its own numbers suggest human capacity couldn't keep up: out of 29,000 candidates, people reviewed only about a fifth. Once scanning scaled up, the review step shifted onto maintainers, and the time cost of triage shifted along with it.

Where it sits next to peers

Anthropic says the service was inspired by OSS-Fuzz, the project Google launched in 2016 that runs continuous fuzz testing on open source code and automatically notifies maintainers when it finds a crash. OSS Scanner swaps that approach for a language model that reads code and writes reproductions, with the bar still set at "critical projects."

This site has previously covered a few related threads. Google was flooded with AI-generated vulnerability reports and stopped accepting them for some open source products; SoftBank and OpenAI partnered on an automated bug-patching service aimed at enterprise customers. The three are positioned differently: Google is holding back the volume of incoming reports, OpenAI's line is an enterprise business, and Anthropic this time is going free for open source maintainers, bundling in reproduction programs and patches, betting on report quality to make its case.

For maintainers, whether to opt in comes down to their own capacity to handle the reports. The announcement doesn't disclose how many of the nearly 5,000 reports have been fixed, or the average turnaround time; whether unreviewed reports become a burden again as more projects join will only become clear once the list of participants is made public.

Sources: Anthropic official announcement (candidate vulnerabilities, human review, disclosure rate and report counts), anthropics/oss-scanner application guidelines, CocoLoop; Anthropic's announcement cross-checked for eligibility criteria and report composition.