{"slug": "anthropic-launches-free-ai-vulnerability-scanner-for-open-source-projects", "title": "Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects", "summary": "Anthropic launched OSS Scanner on Thursday, a free, opt-in AI vulnerability scanner that uses its strongest models, including Claude Mythos, to run periodic security scans on open-source projects at no cost. Core maintainers enroll by opening a pull request on the OSS Scanner GitHub repository with a YAML configuration file specifying the git repository link, primary contact email, and a repository-relative path to a Dockerfile that builds the project for an offline agent audit; 116 pull requests have been submitted as of writing. Anthropic said it has identified more than 29,000 candidate vulnerabilities in major software projects, reported a little more than 6,000 flaws to maintainers, and produced 584 advisories as of October 2, 2026, and it does not intend to impose a 90-day disclosure period on OSS Scanner findings given the risk of false positives.", "body_md": "Anthropic on Thursday unveiled [OSS Scanner](https://red.anthropic.com/oss-scanner/) as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI).\n\n“It’s an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing,” Anthropic [said](https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source). “Projects that join will receive thorough, periodic security scans by our strongest models at no cost.”\n\nAnthropic also noted that the outputs of the scanner will be fully model-generated and do not require human review or triage, thereby facilitating faster and more frequent scanning. These reports are expected to be generated by its strongest models, including Claude Mythos.\n\nThe company pointed out that it expects to use a set of criteria similar to Google’s [OSS-Fuzz](https://google.github.io/oss-fuzz/) to pick projects, while emphasizing that the process may evolve over time. Project maintainers are advised to provide a short description  explaining the importance of their project in cases where “it is not already self-evident.”\n\nCore maintainers of a project can enroll by opening a pull request on the [OSS Scanner’s GitHub repository](https://github.com/anthropics/oss-scanner) along with a YAML configuration file that provides the following information –\n\n- Link to the git repository that should be cloned\n- Email address of the primary contact\n- A repository-relative path to the [Dockerfile](https://docs.docker.com/reference/dockerfile/) that sets up the environment, pre-installs all dependencies and builds the project so to help an offline agent conduct its security audit\n\n“The Dockerfile configures the environment that the project will run in and installs all dependencies so that the agent can perform its security audit without any internet access,” Anthropic said. “We recommend verifying that the test cases pass inside of the built container.”\n\nOther optional details that can be added to the YAML file are below –\n\n- Additional email addresses that are to be CC’ed on all reports\n- Project home page\n- GPG public key to encrypt report emails\n- A repository-relative path to a threat model file (“threat_model.md”) that spells out what code should be tested, vulnerability classification, or report formats.\n- Opt out of receiving bug reports by setting “disabled: true”\n\nAs of writing, a total of [116 pull requests](https://github.com/anthropics/oss-scanner/pulls?q=is%3Apr) have been submitted. Unlike other vulnerability reporting programs, Anthropic said it does not intend to impose a 90-day disclosure period on the findings, given the risk that they may contain false positives.\n\n“If we later validate one of these reports manually through our existing CVD program, we may disclose it under our CVD policy starting 90 days from when you are notified that a human has validated this report,” it added. “As we gain greater confidence in OSS Scanner’s performance, we may in the future impose a disclosure period on some high-severity vulnerability reports.”\n\nThe AI company said it has [identified](https://red.anthropic.com/2026/cvd/) more than 29,000 candidate vulnerabilities in some of the world’s most important software projects, out of which a little more than 6,000 flaws have been reported to maintainers. These have resulted in 584 advisories as of October 2, 2026.\n\nThe development comes as Anthropic also unveiled the [Critical Infrastructure Defense Program](https://www.anthropic.com/news/anthropic-cyber-mission) to safeguard critical infrastructure and open-source software as part of its Cyber Mission.\n\nWith AI [increasingly equipping](https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html) bad actors to discover and exploit vulnerabilities, automate various stages of cyber operations, and conduct attacks faster and at scale, the idea behind the initiative is to arm defenders with the right tools to combat the threat, accelerate fixes, and explore new secure architectures and coding practices.\n\n“Our forecast is that in two years, AI will favor defense: it will be easier to catch bugs before they ship, write fundamentally secure software from scratch, and actively defend systems with models,” Anthropic said.", "url": "https://wpnews.pro/news/anthropic-launches-free-ai-vulnerability-scanner-for-open-source-projects", "canonical_source": "https://www.swapupdate.in/anthropic-launches-free-ai-vulnerability-scanner-for-open-source-projects/", "published_at": "2026-10-10 22:17:09+00:00", "updated_at": "2026-10-11 01:21:13.389405+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "ai-tools", "developer-tools"], "entities": ["Anthropic", "OSS Scanner", "Claude Mythos", "Project Glasswing", "OSS-Fuzz", "Google", "Critical Infrastructure Defense Program", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/anthropic-launches-free-ai-vulnerability-scanner-for-open-source-projects", "markdown": "https://wpnews.pro/news/anthropic-launches-free-ai-vulnerability-scanner-for-open-source-projects.md", "text": "https://wpnews.pro/news/anthropic-launches-free-ai-vulnerability-scanner-for-open-source-projects.txt", "jsonld": "https://wpnews.pro/news/anthropic-launches-free-ai-vulnerability-scanner-for-open-source-projects.jsonld"}}