Skip to content
Five.Reviews
Menu

AI Tools & Comparisons

Anthropic OSS Scanner: How AI-Powered Code Security Works

Laptop displaying code on a desk used to represent tool setup and technical review work
Free browser-based audio. No tracking or paid API required.

Open-source software runs under a large share of modern applications, from web servers to cryptographic libraries. The maintainers who keep these projects healthy often have limited time to find, verify, and patch security flaws. Anthropic OSS Scanner is a new opt-in service that uses Anthropic’s strongest models to scan eligible open-source projects for vulnerabilities at no cost.

The service launched on October 8, 2026. Anthropic says its models have found far more candidate vulnerabilities than its human reviewers can triage, so it added an optional fast track for maintainers who want reports before human review.

This guide covers how the scanner works, what its reports contain, what Anthropic has reported about accuracy, who can enroll, how to set up a project, and where the service’s limits lie.

Quick Summary: What You Need to Know

What Is Anthropic OSS Scanner?

Anthropic OSS Scanner is an opt-in vulnerability-scanning service for open-source software. Enrolled projects receive thorough, periodic security scans from Anthropic’s strongest models at no cost. The service draws on Anthropic’s experience using Claude to find vulnerabilities during Project Glasswing, its broader cybersecurity initiative.

Anthropic describes the service as inspired by Google’s OSS-Fuzz, which uses fuzzers to scan open-source code. OSS Scanner relies on language-model agents instead. It is not a code editor or an AI coding assistant. Its purpose is to surface security issues before attackers find them.

The fast track responds to a bottleneck Anthropic describes. Over six months, its models produced more than 29,000 candidate vulnerabilities, but its team had manually reviewed and triaged about 6,000. Some maintainers asked for unverified reports directly, so Anthropic created an optional path for them. Its standard coordinated vulnerability disclosure (CVD) process, which relies on human-verified reports, continues alongside it.

How Does Anthropic OSS Scanner Work?

Anthropic describes a multi-stage pipeline. The steps below follow its published documentation.

1. Project Enrollment and Configuration

A core maintainer opens a pull request to Anthropic’s oss-scanner repository that adds a configuration file at projects/<project>/project.yaml. Anthropic manually verifies each applicant before enrolling a project.

2. Build Environment Preparation

The project’s Dockerfile installs dependencies and builds the software before the audit begins. The Dockerfile itself is built with network access, but the audit runs without internet access. Anthropic recommends confirming that the project’s tests pass inside the built container.

3. AI-Powered Vulnerability Detection

Anthropic’s strongest models, including Claude Mythos, inspect the code as agents running in hardened sandboxes with internet access disabled. Anthropic says it uses a variety of harnesses and techniques, including more resource-intensive experimental ones for deeper bugs. It has not published detailed implementation specifics, so those should not be assumed.

4. Cross-Checking and Root-Cause Analysis

According to Anthropic, the pipeline includes agents that double-check suspected bugs, propose patches, and perform root-cause analysis. Where possible, reports also identify when a bug was introduced. This checking is automated. It does not mean a person has reviewed the finding.

5. Vulnerability Reports and Candidate Patches

Maintainers receive a bundle of bug reports by email. According to Anthropic, each report contains an explanation of the vulnerability, a self-contained reproducer, an introduction-point analysis where available, and a candidate patch when one is available. A candidate patch is a proposal, not a verified or production-ready fix. Anthropic says the delivery format may change later.

6. Periodic Rescanning

After the first scan, Anthropic regularly rescans enrolled projects for newly introduced vulnerabilities and issues earlier scans may have missed. It does not publish a fixed interval, saying frequency may depend on pipeline capacity, how widely a project is used, and other factors.

The workflow runs as follows: Enroll project, prepare build environment, run AI security audit, generate findings, deliver reports, verify and remediate. Anthropic’s pipeline ends at delivery. Verification and remediation remain the maintainer’s responsibility.

How Accurate Is Anthropic OSS Scanner?

Anthropic’s Initial Validation Results

Anthropic evaluated an early version of the scanner. Expert penetration testers who review its CVD findings checked 97 critical- and high-severity vulnerabilities across 48 projects. Of these, 85 (about 88%) met the bar for Anthropic’s CVD process. Of the remaining 12, 11 were real but duplicated known issues or other findings from the same scan, and one was a false positive.

Anthropic also reports that maintainers have seldom described high or critical findings as invalid. Some said severity ratings were inflated or that the scanner misread their threat model.

What the 88% Result Actually Means

This figure comes from one company-run evaluation of an early version. It covers a selected set of critical and high-severity findings. It is not an independent benchmark, a universal accuracy rate, or a guarantee of future performance. Anthropic itself says it cannot guarantee the scanner will be perfect.

Maintainer feedback in the launch post is also self-reported. One maintainer, quoted by Anthropic, said that 74 reports were received, all but two were valid, and five became CVEs.

What Maintainers Should Verify

Maintainers should reproduce the reported behavior in a controlled environment and confirm that it affects their actual version and configuration. They should assess exploitability and severity against their own threat model, check for duplicates and existing fixes, and review any candidate patch with regression tests before merging. A well-written report is not proof of a vulnerability, so engineering judgment still applies.

Who Can Use Anthropic OSS Scanner?

Anthropic says it uses criteria similar to OSS-Fuzz’s. The service is intended for established projects with critical impact on infrastructure and user security. Its FAQ highlights two factors: exposure to remote attacks, such as libraries that process untrusted input, and the number of users and projects that depend on the software. Each application is reviewed case by case, and Anthropic may adjust the criteria over time.

Enrollment is not guaranteed. Anthropic encourages applicants to explain in a short sentence why their project matters if that is not already obvious.

The service is not suited to every project. Anthropic says it is built for projects that can already keep up with verified high and critical vulnerability reports and want additional coverage. Maintainers who are already overwhelmed may prefer human-verified CVD reports.

Best for: established, security-critical projects with active core maintainers and a workable triage process.
Less suitable for: projects that cannot review incoming findings promptly or do not meet the eligibility criteria.

How to Set Up Anthropic OSS Scanner

These steps follow Anthropic’s current repository template and FAQ. Check both before submitting.

Step 1: Review the repository. Start at github.com/anthropics/oss-scanner and copy the template at templates/project.yaml to projects/<project>/project.yaml.

Step 2: Complete the required fields. The repo field is the git repository to clone, optionally pinned to a branch or tag. The primary_contact field is the email address that receives reports and project communication. The dockerfile field gives the repository-relative path to your Dockerfile. You can omit this field and instead place a Dockerfile next to your project.yaml in the OSS Scanner repository. The template uses the lowercase key dockerfile, while the FAQ prose writes “Dockerfile,” so use the key exactly as the template shows it and confirm it with the validation script.

Step 3: Add optional fields as needed. These include auto_ccs for additional recipients, homepage, pgp for encrypted report emails (which cannot be combined with auto_ccs), and disabled. Anthropic strongly recommends a threat model file, which has no required format. It can describe the code in scope, which inputs are adversarial, what to ignore, a severity rubric, report formatting, patch preferences, and deduplication guidance.

Step 4: Prepare and test the build. Write the Dockerfile so it installs all dependencies and builds the project. Confirm the test suite passes inside the container.

Step 5: Validate and submit. Run the tools/validate.py script on your configuration, build the Dockerfile locally, and open the pull request. Anthropic verifies core maintainer status, decides on enrollment, and attempts its own build after acceptance. It will email if the build fails.

Step 6: Manage participation. Reply to report emails to give feedback, or email [email protected] if you are not enrolled. To pause reports, submit a pull request adding disabled: true. To leave entirely, submit a pull request deleting your projects/<project>/ directory. Anthropic also invites a commit-message credit with the report ID, though it is not required.

Signing up means agreeing to Anthropic’s OSS Scanner terms and conditions, which you should read before enrolling. The official FAQ is at red.anthropic.com/oss-scanner.

Anthropic OSS Scanner vs. Claude Security vs. OSS-Fuzz

FeatureAnthropic OSS ScannerClaude SecurityOSS-Fuzz
Primary purposeAI-based vulnerability scanning for enrolled open-source projectsFinding and fixing vulnerabilities in source codeAutomated fuzz testing for open-source software
Main audienceEligible open-source core maintainersEnterprise usersEligible open-source projects
CostFree for accepted projectsCommercial product; check current termsVerify current terms with the project
Main approachModel-based agents producing reports and candidate patchesAI-assisted discovery and remediationFuzzing
Human reviewReports delivered without human review or triageNot specified in the sources reviewedProject maintainers triage findings

These approaches complement one another and are not interchangeable. AI analysis does not replace fuzz testing, manual security review, or a coordinated disclosure process.

Benefits and Limitations of Anthropic OSS Scanner

Potential benefits: no-cost scanning for accepted projects, access to advanced Claude-based vulnerability research, reports with reproducers and sometimes candidate patches, faster access to findings, and periodic rescanning.

Important limitations: reports are not reviewed by humans before delivery, false positives and duplicates remain possible, severity ratings can be wrong, maintainers need capacity to investigate and fix issues, eligibility is selective, candidate patches require testing, and future service details may change. The scanner should complement a broader security program, not replace it.

Security and Disclosure Considerations

Unreviewed reports differ from Anthropic’s standard CVD process, where findings are human-verified before disclosure. Anthropic states that it will not apply a 90-day coordinated disclosure period to unvalidated OSS Scanner findings. If a finding is later validated through its CVD program, disclosure may follow that program’s timeline, starting 90 days after the maintainer is notified that a human has validated the report. Anthropic says it may impose disclosure periods on some high-severity reports in the future, with notice and an opt-out option.

Anthropic states that reports are held in an isolated, locked-down cloud project accessible only to security staff who need it, and that scanning agents run only in sandboxes with internet access disabled. Its documentation does not address other questions about data use, so review the terms before enrolling. Teams should limit access to vulnerability details and test any patch before deployment.

Best Practices for Using AI-Generated Vulnerability Reports

  1. Assign a security contact to receive and triage reports.
  2. Prioritize critical and high-severity findings, but validate their impact independently.
  3. Reproduce issues in a controlled development environment.
  4. Review candidate patches rather than merging them automatically.
  5. Run regression and relevant security tests.
  6. Track duplicates and confirmed findings in your issue or vulnerability system.
  7. Document remediation decisions and communicate responsibly with affected users.
  8. Keep complementary controls such as code review, dependency updates, and fuzz testing.

Consider a hypothetical maintainer who receives a report about a possible input-validation flaw in a parser. The maintainer reproduces the input in a test build, confirms that it crashes the affected version but not the latest release, checks the candidate patch against the existing test suite, and adds a regression test before releasing a fix. This scenario is illustrative, not a real OSS Scanner finding.

Final Verdict

Anthropic OSS Scanner offers free, periodic AI-driven security scans for established open-source projects that meet its criteria. Its reports can include reproducers and candidate patches, which can speed up investigation. Its reports are unreviewed, however, so maintainers must reproduce, verify, and test every finding before acting. Maintainers with active triage capacity and security-critical projects are best positioned to benefit. Before enrolling, read the official FAQ, the eligibility criteria, the terms and conditions, and the repository template.

Frequently Asked Questions

What is Anthropic OSS Scanner?

Anthropic OSS Scanner is an opt-in service that scans enrolled open-source projects for security vulnerabilities using Anthropic’s strongest models. Accepted projects receive periodic scans and reports at no cost. Reports are generated without human triage before delivery.

Is Anthropic OSS Scanner free?

Yes, for accepted projects. Anthropic says it covers the full cost. Enrollment is selective and decided case by case.

How does Anthropic OSS Scanner work?

Maintainers enroll through a pull request, and Anthropic prepares the project’s build environment. Model-based agents then audit the code offline, cross-check suspected bugs, and deliver reports with reproducers and sometimes candidate patches.

How can I enroll a project in Anthropic OSS Scanner?

Core maintainers open a pull request to Anthropic’s oss-scanner repository adding a project.YAML file based on the template. The file requires a repository, a primary contact, and a Dockerfile path. Anthropic verifies maintainer status before accepting.

Which Claude models power OSS Scanner?

Anthropic says the service uses its strongest models, and that its reports are generated by them, including Claude Mythos. Anthropic does not publish a more specific model breakdown.

Does Anthropic OSS Scanner automatically fix vulnerabilities?

No. It can provide candidate patches, but those are proposals. Maintainers must review, test, and decide whether to merge them.

Are Anthropic OSS Scanner reports reviewed by humans?

No. Anthropic states that the outputs are fully model-generated and delivered without human review or triage. Maintainers must validate every report before acting on it.

How often does Anthropic OSS Scanner scan a project?

After the first scan, Anthropic rescans projects periodically. It does not publish a fixed interval, and frequency may depend on pipeline capacity and other factors.

Can every open-source project use Anthropic OSS Scanner?

No. Projects must be established, have critical impact on infrastructure or user security, and have a core maintainer who is verified. Anthropic decides each application case by case.

How is OSS Scanner different from Claude Security and OSS-Fuzz?

OSS Scanner is a free, model-based scanning service for eligible open-source projects. Claude Security is a commercial enterprise product for finding and fixing code vulnerabilities. OSS-Fuzz is Google’s fuzz-testing project for open-source software.