Anthropic has launched OSS Scanner, an opt-in service that scans open-source projects for vulnerabilities with its strongest models at no cost to maintainers, according to its Oct. 8 announcement. Core maintainers of eligible projects enroll by submitting a pull request to a GitHub repository. Anthropic says eligibility follows criteria similar to Google’s OSS-Fuzz, meaning projects with “critical impact on infrastructure and user security”, decided case by case.

The scanner’s output is fully model-generated and goes out without human review or triage. Anthropic says that allows faster and more frequent scans, but means some reports may be incorrect or invalid. Each report includes a self-contained reproducer, an explanation, and a candidate patch when one is available.

The company gives the reason for the design. Over six months it found more than 29,000 candidate vulnerabilities but could manually review about 6,000, so human validation is the bottleneck. It has already sent nearly 5,000 reports to maintainers who asked for everything, validated or not. In a check of 97 critical and high-severity findings across 48 projects, expert testers judged 85 (88 percent) good enough for its coordinated disclosure process. Of the other 12, 11 were real but duplicates, and one was a false positive.

Maintainers quoted by Anthropic give mixed detail. Todd Ouska of wolfSSL said of 74 reports received, “all but two were valid, and five became CVEs.” Anthropic also notes that some maintainers say severity ratings can be inflated.

In our reading, the extra work lands on the receiving end. If scanners find bugs faster than maintainers can fix them, downstream users should expect a higher volume of patch releases from open-source dependencies, and shorter gaps between a fix landing and attackers studying it. Teams that track dependencies should check that their update pipeline can absorb more frequent releases. This follows Anthropic’s expansion of its Cyber Verification Program and sits alongside Microsoft’s report on AI compressing attack timelines.

Source: Anthropic, “Launching an opt-in vulnerability-finding service for open-source software”