product updateAnthropic

Anthropic launches OSS Scanner: free, model-generated security scans for opt-in open-source projects

TL;DR

Anthropic has launched OSS Scanner, an opt-in service that gives open-source projects periodic vulnerability scans at no cost, run by its strongest models including Claude Mythos. Reports are fully model-generated with no human review or triage, so Anthropic warns some may be incorrect or invalid.

2 min read
0

Anthropic has launched OSS Scanner, a service that gives open-source projects free, periodic security scans run by its most capable models, including Claude Mythos. Projects must opt in. The reports are fully model-generated, with no human review or triage.

What Anthropic announced

According to Anthropic, participating open-source projects will receive "thorough, periodic security scans by our strongest models at no cost." The company says the reports will be generated by "our strongest models (including Claude Mythos) to give open-source projects the largest defensive advantage."

The service was first reported by The Verge on October 8, 2026.

The key trade-off: no human review

Anthropic is explicit about the limitation. In its own words, the outputs "will be fully model-generated, without human review or triage." The company says this allows faster and more frequent scanning, but acknowledges "it is possible reports will be incorrect or invalid."

That matters for maintainers. Each report will need to be validated by the receiving project before anyone acts on it.

What has not been disclosed

The source material does not specify:

  • Scan frequency or cadence
  • Eligibility criteria or application process
  • Supported languages or repository sizes
  • Rate limits or usage caps
  • How reports are delivered, or how findings are disclosed
  • Which Claude models beyond Mythos are used
  • Whether the free tier has an end date

Pricing is listed only as "no cost" for opted-in open-source projects. No per-token or per-scan figures have been disclosed.

Context: AI bug hunting is already in use

OSS Scanner is not the first AI-assisted vulnerability discovery effort. AI tools have helped surface significant flaws in open-source software in recent months. One example is the "Copy Fail" bug, which The Verge reports affected nearly every Linux distribution in May.

The same trend has created friction. Some open-source projects, including the Linux kernel's Linus Torvalds and Google, are reportedly struggling with a surge of AI-generated bug reports.

What this means

OSS Scanner is a product and service launch, not a new model release. It applies existing frontier capability to a defensive use case, and it is opt-in, which gives maintainers control over whether they receive reports at all.

The unreviewed output is the central risk. Maintainers are already stretched by low-quality AI-generated reports, and a vendor-run scanner that skips human triage could add to that load if its false-positive rate is high. Anthropic has not published accuracy figures, so the real signal-to-noise ratio is unknown.

The opt-in design and the free price may partly offset this. Projects can decide whether the scans are worth the review time. The first useful evidence will be false-positive rates and confirmed findings from participating projects. Until Anthropic or maintainers publish those, the claim of a "largest defensive advantage" remains an Anthropic assertion, not a measured result.

Related Articles

product update

Anthropic adds Dashboards and Motion betas to Claude; Docs, Slides and Design exit beta for all plans

Anthropic launched two beta features for Claude: Dashboards, which builds auto-updating dashboards from connected data sources, and Motion, which generates animated explainer videos exportable as MP4. Docs, Slides and Design leave beta and now work on every plan, including free accounts.

product update

Anthropic launches Claude for Google Workspace add-on in public beta, adding sidebars to Docs, Sheets and Slides

Anthropic has released the Claude for Google Workspace add-on in public beta, placing a Claude sidebar inside Google Docs, Sheets, and Slides. It is available to all paid Claude users through the Google Workspace Marketplace, and includes an "ask before edits" preview mode.

model release

Claude Haiku 5.5 arrives on Amazon Bedrock; Anthropic claims ~75% lower cost than Haiku 4.5

Claude Haiku 5.5 is available on Amazon Bedrock and Claude Platform on AWS. According to Anthropic, it is the fastest and most efficient model in the Claude 5.5 family and costs around 75% less than Claude Haiku 4.5 for most tasks. It is the first Haiku model with effort controls.

model release

Anthropic releases Claude Haiku 5.5, claims ~75% lower running cost than Haiku 4.5

Anthropic released Claude Haiku 5.5 on October 7, 2026. The company claims it costs around 75% less to run than Haiku 4.5 and is its fastest model to date. Anthropic also halved Claude Sonnet 5.5's cache read pricing and added a monthly API credit for Max and Team subscribers.

Comments

Loading...