Anthropic Launches Free AI-Powered OSS Scanner for Open-Source Security
Anthropic has launched OSS Scanner, an opt-in service that utilizes its frontier AI models—including Claude Mythos—to automatically scan critical open-source software projects for security vulnerabilities free of charge. Maintainers of key infrastructure projects can apply by submitting a pull request to the OSS Scanner GitHub repository. Securing open-source software is essential for global digital infrastructure, but maintainers often lack the time and resources for comprehensive security audits. By providing automated, high-precision AI vulnerability scanning, Anthropic helps protect the software supply chain against potential exploits before attackers can abuse them. The scanner runs entirely automated LLM evaluations without human pre-triage, but empirical testing of 97 severe vulnerabilities across 48 projects showed that 88% met disclosure standards with only a single false positive. Over the past six months, Anthropic's advanced models identified more than 29,000 candidate vulnerabilities across major software projects globally.
## BACKGROUND
Open-source software security relies heavily on automated detection frameworks like Google's OSS-Fuzz, which performs continuous fuzz testing to catch bugs in widely used libraries. Discovered security flaws are typically managed through Coordinated Vulnerability Disclosure (CVD), a process where researchers report issues privately to maintainers so they have adequate time to patch the software before public release.