Anthropic has introduced OSS Scanner, a free service that checks critical open-source repositories for security vulnerabilities and sends findings directly to project maintainers.

The opt-in program uses the company’s strongest AI models to run repeated scans, giving developers a faster route to potential flaws without waiting for human review.

According to Anthropic’s service overview, OSS Scanner builds on its work with Project Glasswing. The company says it had reviewed more than 6,000 vulnerability reports by October 2026 through its existing disclosure process. The new service offers a separate path for projects willing to assess AI-generated reports.

Anthropic OSS Scanner

According to the GitHub repository, the scanner first builds an enrolled project inside an isolated virtual machine with network access enabled. This stage installs dependencies and prepares the software for testing.

Anthropic then removes Internet access before the security audit begins, allowing scanning agents to examine the project within a restricted environment.

Reports arrive by email with steps to reproduce the suspected issue and a proposed patch where available. Anthropic says its pipeline includes agents that double-check bugs and examine their root causes.

However, these checks are automated. A human does not review the findings before maintainers receive them. After the first scan, the service checks projects again for newly introduced vulnerabilities and issues missed earlier. Scan frequency depends on factors such as demand and project usage.

This extends Anthropic’s wider push into security research, including earlier work in which Claude uncovered 22 Firefox vulnerabilities.

Core maintainers apply through the official GitHub repository by opening a pull request that adds a directory under projects/. Each submission needs a project.yaml configuration containing the repository address and a primary contact email. Anthropic manually checks that applicants are core maintainers before accepting a project.

Eligibility focuses on established projects with broad use, exposure to remote attacks, and significant infrastructure security impact.

A Dockerfile must explain how to install dependencies and build the software. Developers can keep it in their own repository or beside project.yaml in the enrollment repository. Everything needed for building and testing must be downloaded during setup because the later audit cannot access the Internet.

An optional threat_model.md file helps guide the scan. Maintainers can describe where untrusted input enters, which components are outside scope, and how they rate severity.

They can also explain preferred report formats and patch requirements, reducing the need for the scanner to guess project-specific security expectations.

Before applying, developers can use tools/validate.py to check their configuration and tools/check to test the build. The checking tool runs with network access, so Anthropic warns users to test only trusted projects or use a separate machine.

Configuration email addresses are public, making a dedicated security alias useful. Maintainers can add an OpenPGP public key for encrypted reports, but encrypted messages go only to the primary contact and cannot include additional recipients.

Anthropic does not impose a 90-day disclosure deadline on unvalidated findings. However, a report later confirmed through its human-reviewed program may enter that disclosure process.

This safeguard matters amid concerns about AI-generated vulnerability reports wasting maintainers’ time. Project owners still need to reproduce suspected flaws and test suggested fixes before treating them as confirmed vulnerabilities. Reports can be paused with disabled: true, while deleting the enrollment directory withdraws the project entirely