Open-source maintainers receive automated AI vulnerability reports from Anthropic's new free scanner
The AI firm offers opt-in vulnerability scans for open-source code, delivering automated reports generated by its strongest models without human review.

Key points
- Anthropic launched OSS Scanner on Thursday as a free service for the open-source ecosystem.
- The tool uses artificial intelligence to identify vulnerabilities, informed by the company's prior experience.
- Security reports are generated automatically and sent to project maintainers without human verification.
Anthropic has introduced a new security tool designed to strengthen the open-source software landscape. The company launched OSS Scanner on Thursday, offering free, periodic security audits for projects that choose to participate. According to The Hacker News, the service is opt-in, meaning maintainers must actively agree to have their code scanned. The initiative aims to leverage artificial intelligence to detect security flaws that might otherwise go unnoticed in widely used libraries and frameworks.
How it unfolded
- Anthropic announced the launch of OSS Scanner on Thursday.
- The company stated the tool is informed by its internal experience using its Claude model to find vulnerabilities during a previous initiative called Project Glasswing.
- Anthropic confirmed that projects joining the service will receive thorough scans conducted by its strongest AI models at no cost.
Who is affected
The primary beneficiaries are maintainers of critical open-source projects. These individuals and teams often face significant pressure to secure their codebases while managing limited resources. By providing free scans, Anthropic aims to reduce the burden on these developers. However, the service is strictly opt-in, so only projects that explicitly join the programme will receive these automated audits. Organisations relying on open-source software may indirectly benefit if the projects they depend on choose to participate, leading to more secure upstream code.
The fix
This announcement details the launch of a new security service rather than a patch for a specific vulnerability. There is no immediate fix required for users or developers, as OSS Scanner is an optional tool for proactive security auditing. Project maintainers who wish to utilise the service can opt in to receive regular scans. Those who do not participate will continue to rely on existing security practices and manual code reviews. No specific software updates or patches were mentioned in relation to this launch.
What to do and how to stay safe: Anthropic
- Review your organisation's open-source dependencies to identify critical components that would benefit from additional security auditing.
- If you maintain open-source projects, consider opting in to automated scanning services to detect potential vulnerabilities earlier in the development lifecycle.
- Monitor official channels from open-source project maintainers for updates on their security practices and participation in external audit programmes.
- Ensure your internal processes allow for the integration of automated security findings into your regular development and maintenance workflows.
Step-by-step guide: Patch Management: Eight Questions Answered for Stability
General security guidance from the Malware Brief newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
Is OSS Scanner available to all open-source projects?
Yes, but it is an opt-in service, meaning project maintainers must choose to participate to receive scans.
Do human experts review the vulnerability reports generated by OSS Scanner?
No, Anthropic states that the AI-generated reports are sent without human review.
What is the cost of using OSS Scanner?
The service is free for projects that join the programme.



