Anthropic OSS Scanner offers free AI bug scans to projects
Anthropic has launched OSS Scanner, a free service that points the company's most capable AI models at open-source code to look for security vulnerabilities. Maintainers who sign up get periodic scans and reports describing suspected flaws, how to reproduce them and, where possible, how to fix them.
The service grows out of Project Glasswing, an earlier Anthropic effort that used Claude to hunt for software vulnerabilities. It follows a broader push by the company into security work, including its recent move to expand the Claude cyber program into three tiers.
Skipping the human review step
The most notable design choice is what OSS Scanner leaves out. According to Anthropic, human validation has become a bottleneck in its vulnerability research. The new service therefore sends AI-generated findings straight to project teams, with no human review in between.
This makes reporting faster. It also moves the work of checking each finding, and deciding which fixes come first, onto the maintainers themselves.
Anthropic is open about the risks. "We can't guarantee the scanner will be perfect," the company said. It acknowledged that reports may overstate how severe a bug is, or misread the security assumptions a project is built on.
Early results from penetration testers
Anthropic shared figures from an early version of the scanner. Penetration testers reviewed 97 findings rated high or critical severity, spread across 48 projects.
Of those, Anthropic said 85 met the criteria of its coordinated disclosure process. Another 11 were real issues but duplicated known bugs or other findings. Only one was invalid.
At least one maintainer says the quality has changed sharply. Anton Arapov of OpenSSL Corporation described early AI-generated reports from roughly 18 months ago, before Project Glasswing, as "appalling."
"The reports we received from Anthropic, raw model output included, were as good and sometimes better than what we get from people. Particularly when a report comes with a real exploit attached, that's basically job done for an engineer as you can verify it right away," Arapov said.
How the scans work
Projects that enroll first receive an initial scan, followed by a bundle of reports sent by email. Later scans look for newly introduced vulnerabilities, as well as issues that earlier checks missed. How often a project is scanned will depend on several factors, including demand and how widely the software is used.
Maintainers can steer the process. They can tell Anthropic what to test, which inputs should be treated as potentially malicious, how severity should be rated, and what kind of proposed patches they would find useful.
Anthropic says the service is not meant for every project. It is aimed at teams that already keep up with verified high and critical severity reports and still have capacity to look into more findings.
Who can apply
Core maintainers can apply through the OSS Scanner GitHub repository. Each application is assessed individually. Eligibility focuses on established projects that matter for infrastructure and user security.
Disclosure rules differ from a typical bug report. Unvalidated findings sent through the scanner do not come with a mandatory 90-day disclosure deadline. If Anthropic later validates a report through its existing coordinated disclosure program, a 90-day period may start once maintainers are told about that validation.
Projects are not locked in. They can pause the automated reports, or opt out entirely and go back to receiving only reports handled under Anthropic's standard disclosure process.
Our take
OSS Scanner lands at a moment when open-source teams are already struggling with AI-generated bug reports. Google recently paused its OSS bug bounty over exactly that problem. Anthropic's answer appears to be quality rather than volume, and the penetration test numbers, if they hold up at scale, suggest the output is far better than the low-effort submissions maintainers have learned to dread.
Still, removing human review is a real trade-off. It shifts triage work onto volunteers and small teams, which is why Anthropic limits the service to projects that can already handle verified reports. Whether that filter works in practice is worth watching.
The bigger concern is speed on both sides. A recent case where a Rejetto HFS flaw found by AI was later exploited shows that AI-discovered bugs can turn into live attacks. If tools like OSS Scanner surface flaws faster than maintainers can patch them, the absence of a fixed disclosure deadline for unvalidated findings may become an important detail. It will be worth tracking how many reports lead to fixes, and how quickly.
