OSS Scanner by Anthropic Anthropic launched OSS Scanner, an opt-in service that uses its strongest Claude models to run periodic security scans on open-source repositories at no cost, with reports delivered directly from the models before human review. Anthropic said that by October 2026 it had reviewed over 6,000 vulnerability reports through its coordinated vulnerability disclosure process, and that OSS Scanner offers a fast track for projects willing to receive unreviewed reports. Core maintainers enroll by opening a pull request at github.com/anthropics/oss-scanner that adds a project.yaml config file specifying the repo, primary contact, and a Dockerfile for an offline agent audit. OSS Scanner OSS Scanner is a service by Anthropic to scan open-source repositories for security vulnerabilities. It’s an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing https://www.anthropic.com/glasswing . Projects that join will receive thorough, periodic security scans by our strongest models at no cost. We regularly scan open source software for vulnerabilities and send reports after they have undergone human review as part of our coordinated vulnerability disclosure CVD process https://red.anthropic.com/2026/cvd/ . By October 2026, we had reviewed over 6,000 such reports. This helps many projects secure their code without being overwhelmed by false positives. However, these manual review steps take time, so we're not always able to share vulnerabilities as quickly as we would like. OSS Scanner provides an optional fast track. Projects that enroll will receive reports as soon as they’re scanned directly from our strongest models. If your project would like to receive reports that have not undergone human review, you can enroll by submitting a PR to add your project per the instructions below. Learn more about this project in our launch post http://anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source . We aim to continue to improve this service particularly as models improve. FAQ What projects are eligible? We will accept projects using a similar set of criteria to OSS-Fuzz, which states: We accept established projects that have a critical impact on infrastructure and user security. We will consider each request on a case-by-case basis, but some things we keep in mind are: 1 Exposure to remote attacks e.g. libraries that are used to process untrusted input ; and 2 Number of users/other projects depending on this project. Eventually we hope to be able to standardize this process. Because we are not sure how many projects will enroll, we may adjust the acceptance criteria over time. We encourage maintainers to write a short sentence explaining the importance of their project in cases where it is not already self-evident. For security, we will manually validate you are a core maintainer before enrolling each project. In cases where we are uncertain, we may reach out to the project through other means to confirm. While there is little downside to signing up if you’re eligible, we recognize that many projects are already overwhelmed by the number of reports they’re receiving. This service is built for projects that are already able to keep up with verified high/critical vulnerability reports and are now looking to further secure their code. I’m a maintainer. How do I sign up? The core maintainers of a project can enroll by opening a PR at https://github.com/anthropics/oss-scanner https://github.com/anthropics/oss-scanner that adds a config file at projects/