Anthropic launches opt-in OSS Scanner offering free, periodic AI-generated vulnerability scans for open-source projects
Anthropic introduced OSS Scanner, an opt-in service that gives open-source projects periodic security vulnerability scans at no cost, run by its strongest models (including Claude Mythos). Reports are fully model-generated with no human review or triage, so some may be incorrect or invalid.
Entities: Anthropic, OSS Scanner, Claude Mythos, Linus Torvalds, Google, The Verge
0 primary
What happened
Anthropic has launched OSS Scanner, an opt-in service that gives open-source projects periodic vulnerability scans at no cost, run by its strongest models, including Claude Mythos. The reports are generated entirely by the model, with no human review or triage, so some will be wrong or invalid. The coverage comes from a Verge write-up quoting Anthropic, with no link to the primary announcement. Eligibility, scan frequency and the number of participating projects are not stated.
Why it matters
Maintainers of open-source projects get a free way to find security flaws, which could help under-resourced projects that cannot pay for audits. Enterprises that depend on open-source code could benefit indirectly if real bugs are found and fixed faster. The cost falls on maintainers, though, because unreviewed reports still need someone to check them. Linus Torvalds and Google are cited as already struggling with a flood of AI-generated bug reports, so the net effect depends on how many reports are valid. Impact is uncertain until there is data on accuracy.
What is noise
The claim that the service gives open-source projects "the largest defensive advantage" is Anthropic's promotional framing and is unsupported by any figures. There are no reported vulnerabilities found, false-positive rates or named participants, and the Mythos capability claims are not independently verified here.
Watch next
- 01Published accuracy figures: the share of OSS Scanner reports that maintainers confirm as valid, versus the share dismissed as false positives, and the number of CVEs credited to it.
- 02Maintainer reaction from major projects, including whether any opt in, complain about report volume, or ask for scans to be throttled or require triage.
- 03Primary details from Anthropic: eligibility rules, scan frequency, the number of enrolled projects, and whether human triage or rate limits are added in the following months.
Coverage
1 storyMore capability signals
Full feed →- Deepseek releases V4.1-Flash, an open-source model that sharply cuts KV cache memory and input-processing compute for AI agents10 Sept 202682
- OpenAI discloses sandbox-escape and credential-leak incidents, confirms pause on tool-use for its most capable models26 Sept 202680
- OpenAI launches GPT-6 Sol and Luna at half the token price of GPT-5.6, with roughly flat intelligence scores per independent analysis22 Sept 202680
- Anthropic threat report: Claude abused for malware, drone/missile software, mass surveillance, and industrial-scale distillation by Chinese AI labs11 Sept 202680