AIToday
AI Safety & AlignmentOpen-Source AIGIGAZINE AIPublished: Oct 9, 2026, 13:00 JST

Anthropic launches free OSS Scanner security audits

Anthropic launches free OSS Scanner security audits

3 Key Points

  1. What happened

    Anthropic launched OSS Scanner, which runs security audits on open source projects using its most capable models including Claude Mythos, free of charge, with no human review. An expert check of 97 vulnerabilities found across 48 projects showed 85 (88%) met cooperative disclosure standards.

  2. Why it matters

    Because the scanning is done entirely by AI with no human review, reports can be wrong or turn out not to be valid issues. Still, initial validation produced hundreds of bug reports, including several chaining multiple vulnerabilities into unauthenticated remote code execution exploits.

WHO IT HITSOpen source maintainers of critical infrastructure projects such as PostgreSQL and OpenSSL, whose workload may shift as AI-generated vulnerability reports arrive, and security researchers who review coordinated vulnerability disclosure findings.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

Anthropic positions OSS Scanner as a specialised counterpart to Claude Security, its general code scan-and-patch product, narrowing the focus to open source projects. Reporting includes reproduction steps and descriptions of weaknesses, and in some cases binary searches to pinpoint when a bug was introduced as well as draft patches.

Anthropic itself says it cannot guarantee OSS Scanner is perfect, and points to maintainer feedback and model improvements as the basis for ongoing refinement. That caveat reflects the trade-off built into a fully automated workflow: it enables fast and frequent scans, but it carries risks of inaccurate or invalid reports.

Early validation drew participation from projects including PostgreSQL and OpenSSL. Noah Misch, a PostgreSQL developer, said an unusually high share of bugs was found, that several reports contained near-ready fixes, and that a fast delivery route allowed the latest issues to be handled before reaching a GA release.

FAQ
How accurate is the scanning?
Of 97 vulnerabilities flagged by OSS Scanner across 48 projects, 85 (88%) met cooperative disclosure standards, 11 were duplicates or already known, and 1 was a false positive.
What did the maintainers say about the reports?
Anthropic says few high or critical severity findings were called invalid by maintainers, though some said severity ratings were overstated or the scanner misunderstood their threat model. Noah Misch of PostgreSQL noted an unusually high rate of findings, some with near-ready fixes.
Who can use OSS Scanner?
It targets open source projects with significant impact on infrastructure or user security, and access is decided individually. Maintainers apply via a pull request to the anthropics/oss-scanner repository.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleOpenAI's $50 billion revenue figure rattles AI stocks