LaunchedEditorial Listing

OSS Scanner

Anthropic · OSS Scanner: Anthropic's Free, Opt-In AI Vulnerability Scanning Service for Critical Open-Source Projects

Open OSS Scanner

OSS Scanner is a free, opt-in service run by Anthropic in which its strongest models, including Claude Mythos, scan enrolled open-source projects for security vulnerabilities and email maintainers model-generated reports with a reproducer, an explanation and, where available, a candidate patch. It is for core maintainers of established, security-critical open-source projects who can already keep up with high and critical vulnerability reports and want findings fast, before human review.

PricingFree
Setupmedium
APINo
Open sourceNo
DocsYes
CategorySecurity
Code SecurityVulnerability RemediationApplication SecurityThreat ModelingAutonomous AgentSandboxEmailAnthropicFree

Best for

Core maintainers of established, security-critical open-source projects, such as libraries that process untrusted input, whose teams can already triage a steady flow of high and critical vulnerability reports and want them as early as possible

Not ideal for

Small or niche projects that would not meet OSS-Fuzz-style criteria, teams already overwhelmed by reports, closed-source or commercial codebases, and anyone who wants to run scans on demand or only receive human-verified findings

Who it's for

Core maintainers and security teams of established, security-critical open-source projects

Capabilities

  • Hosted vulnerability scanning of enrolled open-source projects by Anthropic's strongest models, including Claude Mythos, at no cost to maintainers
  • Enrollment by pull request to the public anthropics/oss-scanner repository, adding projects/<name>/project.yaml, a Dockerfile and an optional threat model
  • Projects are built with network access in an isolated VM, then scanned with Internet access disabled inside a hardened sandbox
  • Pipeline agents double-check bugs, analyze root causes and propose patches before reports go out
  • Each report includes a self-contained reproducer, an explanation (with a bisection to when the bug was introduced, where possible) and a candidate patch when available
  • An initial scan, then periodic rescans for newly introduced vulnerabilities and ones missed earlier
  • Optional threat_model.md to set scope, adversarial inputs, a severity rubric, report and patch format, and deduplication granularity; it can be edited between scans
  • Reports emailed to a primary contact with optional CCs, or PGP-encrypted to the primary contact only
  • Local tools: tools/validate.py checks the config, and tools/check builds the project the way the scanner does and opens an offline shell (with a --qemu option that mirrors the scanner's VM layout)
  • Pause reports with disabled: true or withdraw by deleting the project directory, both via pull request

Limitations

  • Reports are model-generated and not reviewed by a human, so some will be inaccurate; Anthropic's terms say reports may miss vulnerabilities, flag non-issues, misjudge severity, or propose patches that break functionality
  • Only established projects with a critical impact on infrastructure and user security are accepted, decided case by case, and Anthropic may adjust the criteria over time
  • Only core maintainers (or people authorized by the lead maintainer) can enroll, and Anthropic manually verifies this
  • Not a tool you can run yourself: there is no self-hosted option, no documented way to trigger a scan on demand, and Anthropic sets the rescan frequency
  • Requires a Dockerfile that builds the project and fetches everything the build and tests need, because scanning runs with no Internet access
  • Email addresses in project.yaml are public because enrollment happens in a public GitHub repository
  • Reports are Anthropic's confidential material and may be shared only with the project's authorized maintainers, and used only to find and fix issues in the project
  • Reports arrive by email only for now (Anthropic says it may move to a different medium later); no dashboard or issue-tracker integration is documented
  • Anthropic may modify, suspend or end the service, or any enrollment, at any time

Use cases

  • Enrolling a widely used parsing or networking library that handles untrusted input to get periodic deep scans by frontier models
  • Getting raw vulnerability reports with reproducers and candidate patches as soon as they are generated, instead of waiting for Anthropic's human-reviewed disclosure queue
  • Writing a threat model and severity rubric so the scanner focuses on in-scope code and rates issues the way the project does
  • Feeding reports with reproducers into an existing security triage and patch process to fix issues before they reach a release
  • Crediting fixes to the scanner by citing the report ID (for example ANT-2026-ABCD1234) in commit messages, which Anthropic requests but does not require

Our take

OSS Scanner turns frontier-model vulnerability research into something an open-source project can simply sign up for, which matters because the maintainers of critical code often lack the budget for tools like this. The design is honest about its tradeoff: you get reports quickly because no human has checked them, so the value depends on whether your team can triage a stream of plausible but sometimes wrong findings. Investing in a good threat model and severity rubric is the most useful thing a maintainer can do before enrolling. Projects that are already stretched are better off staying with Anthropic's human-reviewed disclosures.

Who should use it

Core maintainers of widely depended-on open-source projects, such as libraries that process untrusted input, who have a security process that can handle a regular volume of high and critical reports and want them before human review.

Who should skip it

Maintainers already struggling with report volume, projects unlikely to meet the critical-impact bar, companies looking to scan proprietary code (Claude Security or similar tools fit better), and teams that want to choose when scans run.

Strengths

  • Free scanning by frontier models, with Anthropic covering the cost
  • Reports come with reproducers and, where available, candidate patches and a bisection to the introducing commit
  • Scans run with Internet access disabled in hardened sandboxes
  • A threat model file lets maintainers steer scope, severity ratings and report format
  • Easy to pause or leave through a pull request

Weaknesses

  • Reports are not human-reviewed and can be wrong, including inflated severity
  • Limited to accepted, security-critical projects, with case-by-case approval
  • Maintainers cannot trigger scans or run the scanner themselves
  • Offline build setup is required, and contact emails become public

OSS Scanner pricing

OSS Scanner

Free

  • Initial scan plus periodic rescans of accepted projects
  • Reports with reproducer, explanation and candidate patch
  • Anthropic covers the full cost

Note: The OSS Scanner terms state the service is provided at no cost. It is available only to accepted open-source projects; Anthropic's commercial code-scanning product for companies is Claude Security, which is separate.

Technical specs

Available models

Anthropic's strongest models, including Claude Mythos

Where OSS Scanner excels

Hardening a widely used library

Periodic offline scans by frontier models, with reproducers attached, can surface vulnerabilities in code that processes untrusted data.

Fixing issues before a release

Fast-track reports arrive as soon as they are generated, so maintainers can patch new issues before they reach a stable release.

Encoding the project's security policy

A threat model and severity rubric shape what the scanner tests and how it rates findings, which can cut out-of-scope noise in later reports.

OSS Scanner vs. competitors

OSS Scanner vs. Google Mantis

Google Mantis is a free, open-source set of skills and a reference harness that you run yourself, with your own coding agent and models, on any codebase whenever you choose. OSS Scanner is a service Anthropic runs for accepted open-source projects on its own infrastructure and models, and you receive the results by email on Anthropic's schedule.

OSS Scanner vs. Codex Security

Codex Security is OpenAI's application security agent that teams run themselves, when and where they choose, through Codex plugins, a CLI and SDK, GitHub pull-request reviews, or a cloud preview. It normally draws on ChatGPT plan usage or API tokens, though OpenAI's Codex for Open Source program offers core maintainers conditional access, reviewed case by case. OSS Scanner costs nothing for accepted projects, but Anthropic runs the scans on its own schedule and maintainers only receive the reports.

OSS Scanner vs. CodeMender

CodeMender is a Google Cloud agent in public preview for select customers that finds, verifies and patches vulnerabilities from a local CLI, billed by token. OSS Scanner requires no cloud account or sales process, but works only for accepted open-source projects and only as a hosted service.

Frequently asked questions

What is OSS Scanner?

OSS Scanner is a free, opt-in service from Anthropic's Frontier Red Team. It scans enrolled open-source projects for security vulnerabilities with Anthropic's strongest models, including Claude Mythos, and emails maintainers reports with a reproducer, an explanation and, where available, a candidate patch.

Which projects are eligible for OSS Scanner?

Anthropic uses criteria similar to OSS-Fuzz: established projects with a critical impact on infrastructure and user security, judged case by case on factors such as exposure to remote attacks and the number of users or dependent projects. Anthropic says it may adjust the criteria depending on how many projects enroll.

How do I enroll a project in OSS Scanner?

A core maintainer opens a pull request to the anthropics/oss-scanner GitHub repository that adds projects/<name>/project.yaml with the repository URL and a primary contact email, plus a Dockerfile that builds the project for offline scanning and, optionally, a threat model. Anthropic verifies that you are a core maintainer before enrolling the project.

Are OSS Scanner reports reviewed by humans?

No. Reports are fully model-generated and sent without human review or triage, which makes them faster but means some may be incorrect. Anthropic continues to send human-verified reports separately through its coordinated vulnerability disclosure (CVD) process.

Does OSS Scanner have a disclosure deadline?

Not for the unvalidated reports. Anthropic places no 90-day disclosure period on them. If Anthropic later validates a report manually through its CVD program, it may disclose it under that policy starting 90 days after notifying you that a human has validated it. Anthropic says it may later apply a disclosure period to some high-severity scanner reports, but only after giving enrolled projects advance notice.

How much does OSS Scanner cost?

Nothing. The terms state the service is provided at no cost, and Anthropic says it covers the full cost of scanning.

How is OSS Scanner different from Claude Security?

Claude Security is Anthropic's commercial product for companies to find and fix vulnerabilities in their own code. OSS Scanner is a free service for accepted open-source projects, where Anthropic runs the scans and also applies extra token-intensive and experimental harnesses.

Can I pause or leave OSS Scanner?

Yes. Set disabled: true in your project.yaml with a pull request to pause reports, or delete your projects/<name>/ directory to withdraw. You then go back to receiving only Anthropic's standard human-reviewed CVD reports.

Integrations & fit

GitHubGitDockerEmailOpenPGPQEMU
Good fit forSolo / individual, Startup / small team, Enterprise
Pricing modelFree· No cost to start
See pricing on OSS Scanner →

Alternatives to consider

About OSS Scanner

OSS Scanner is a hosted service, not a tool you install. Anthropic's Frontier Red Team runs the pipeline on its own infrastructure, and maintainers interact with it through a pull request and email. It launched on October 8, 2026, as part of the Anthropic Cyber Mission, and is inspired by Google's OSS-Fuzz, whose eligibility criteria it borrows. To enroll, a core maintainer opens a pull request to the public anthropics/oss-scanner GitHub repository that adds a projects/<name>/project.yaml (the git repository to clone, which does not have to be on GitHub, plus a primary contact email), a Dockerfile that installs every dependency and builds the project, and optionally a threat_model.md. Anthropic manually confirms that the person is a core maintainer and accepts projects case by case, using OSS-Fuzz-style criteria: critical impact on infrastructure and user security, exposure to remote attacks (for example, libraries that process untrusted input), and the number of users and dependent projects. After the merge, the scanner builds the project with network access in an isolated VM, then cuts off Internet access and scans it. Agents in the pipeline double-check bugs, analyze root causes and propose patches. Each report includes a self-contained reproducer, an explanation of the vulnerability (with a bisection to find when the bug was introduced, where possible) and a candidate patch when one is available. The first scan is followed by periodic rescans, whose frequency may depend on how many projects are enrolled, how widely a project is used and other factors. The threat model file is the main control maintainers have: it can define what is in scope, which inputs are adversarial, a severity rubric, report and patch style, and deduplication granularity. The key tradeoff is speed against verification. Anthropic already sends human-reviewed reports through its coordinated vulnerability disclosure (CVD) process, but that review is slow. OSS Scanner is the fast track: reports are fully model-generated and sent without human triage, so some will be wrong, for example with an inflated severity rating or a misread threat model. In Anthropic's own validation of an early version, its penetration testers found that 85 of 97 critical and high-severity findings, across 48 projects, met the bar for its CVD process. Because findings are unvalidated, Anthropic places no 90-day disclosure deadline on them; if it later validates a report manually through its CVD program, it may disclose that vulnerability 90 days after notifying the maintainer. It is free, and Anthropic says it covers the full cost. It suits teams that can triage at volume, not projects already overwhelmed by reports.

Updates from OSS Scanner

LaunchAnthropic launches OSS Scanner as part of the Anthropic Cyber Mission

Anthropic opened enrollment in OSS Scanner, a free opt-in service that sends maintainers of critical open-source projects model-generated vulnerability reports with reproducers and candidate patches, through the anthropics/oss-scanner GitHub repository.

Are you the founder? Claim this listing →