A scanner with no editor

Enrollment is deliberately low-ceremony. A core maintainer opens a pull request on the OSS Scanner GitHub repo with a YAML file: repo link, contact email, and a Dockerfile path so an offline agent can build the project and audit it without internet access. Optional extras: CC emails, a GPG key to encrypt reports, a threat_model.md describing what should be tested.

Once in, projects get periodic scans and a report per suspected flaw: an explanation, a proof-of-concept exploit, and a suggested fix where one exists. Anthropic picks projects using criteria similar to Google's OSS-Fuzz, favoring critical infrastructure and security-relevant software. Within a day of launch, 116 pull requests had come in.

Check the math

Anthropic says it expects a true-positive rate above 90%. Read that carefully: it is a target, not a measured fleet-wide result. The closest published validation is a pen-tester review of 97 high and critical findings from an early version of the scanner: 85 met the bar for coordinated disclosure, 11 were genuine but duplicated known issues, one was invalid. A strong sample, but 97 severity-filtered findings from an early build.

The more honest numbers are the pilot ones. Over six months, Anthropic's models surfaced 29,000 candidate vulnerabilities across some of the most important software projects in the world. Humans managed to review and report about 6,000. The scanner exists precisely because the bottleneck is people, not models. Anthropic's own forecast: AI will favor defense in about two years, but right now the cost of finding bugs has dropped while verifying and patching them still runs on human time. OpenSSL's experience hints at the workload: 74 reports, 5 official CVEs — worth it, but someone had to read all 74.

The missing disclosure clock

One policy detail tells you how Anthropic thinks about its own accuracy. Unlike the usual industry norms, OSS Scanner findings carry no 90-day disclosure deadline — because they might be wrong. If a human later validates a report through the existing coordinated disclosure program, the 90-day clock starts then. Reports 'can overstate severity or misunderstand a project's security assumptions,' the company says. That is a refreshingly direct way to say: false positives are part of the price.

What to do with it

If you maintain open source: this is genuinely useful if your project can absorb the triage load. Anthropic says the service is meant for projects that can keep up; everyone else continues through the human-verified disclosure channel. The Dockerfile requirement is the practical hurdle — the agent builds and audits offline, so your build has to work inside a container.

If you just depend on open source: expect the volume of disclosed vulnerabilities to rise. Anthropic is not the only lab doing this. When discovery is cheap for defenders, it is cheap for attackers too, and the advantage goes to whoever patches fastest.

Sources

  1. [1] The Hacker News — Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects (Oct 9, 2026)Read source
  2. [2] SecurityWeek — Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers (Oct 9, 2026)Read source
  3. [3] Help Net Security — Anthropic offers free AI security scans to open-source maintainers (Oct 9, 2026)Read source