Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

· Original article ↗

Summary

Anthropic launched an opt-in, free AI scanner that periodically checks selected open-source projects for vulnerabilities. It says the system has identified more than 29,000 candidate flaws, with over 6,000 reported to maintainers.

Key points

  • OSS Scanner offers selected open-source projects free, periodic vulnerability scans using Anthropic’s models.
  • Maintainers can apply through the project’s GitHub repository and provide a YAML configuration, including a Dockerfile for an isolated audit environment.
  • Scanner findings are model-generated and do not require human review or triage; Anthropic cautions that reports may include false positives.
  • Anthropic says it has identified more than 29,000 candidate vulnerabilities and reported slightly over 6,000 to maintainers, resulting in 584 advisories as of October 2, 2026.
  • Anthropic is not applying a fixed 90-day disclosure period to unvalidated scanner reports; its existing coordinated disclosure policy may apply after manual validation.
  • The launch accompanies Anthropic’s Critical Infrastructure Defense Program, intended to support critical infrastructure and open-source security.

Article Details

Event Type
Anthropic launched OSS Scanner, an opt-in AI vulnerability-scanning service for open-source projects, and announced the Critical Infrastructure Defense Program.
Impact
Anthropic said OSS Scanner had identified more than 29,000 candidate vulnerabilities, with a little more than 6,000 reported to maintainers and 584 advisories resulting as of October 2, 2026. The service provides participating projects with periodic scans at no cost; its reports are model-generated and do not require human review or triage.

Vendors

Products

Industries

Related Articles