Anthropic Will Scan Your Open-Source Code for Free

Anthropic has launched OSS Scanner, a free service that runs security scans on open-source projects using the company’s most capable AI models. According to The Verge AI, projects that opt in will get “thorough, periodic security scans by our strongest models at no cost.” That includes Claude Mythos, Anthropic’s top-tier model.

There’s a catch, though. Nobody at Anthropic will check the reports before they reach maintainers.

🔍 What OSS Scanner Actually Does

The idea is simple. Open-source maintainers sign their project up, and Anthropic’s models comb through the code on a regular schedule looking for security vulnerabilities. When something turns up, the project gets a report.

Anthropic says the goal is to give open-source projects “the largest defensive advantage” by putting its strongest models on the job. Here’s how it works:

  1. It’s opt-in. Projects choose to join. Anthropic isn’t scanning public repos uninvited and dumping findings on maintainers who never asked for them.
  2. It costs nothing. Running frontier models over large codebases isn’t cheap. Anthropic is covering that compute itself, which matters for volunteer-run projects with no security budget.
  3. Scans repeat over time. This isn’t a one-off audit. Code changes constantly, so periodic scans can catch new bugs as they’re introduced.
  4. The strongest models do the work. Anthropic says reports come from its top models, Claude Mythos included, not from a cheaper, lighter tier.
  5. Every report is machine-generated. This is the big caveat, so it gets its own section below.

⚠️ No Human in the Loop

Anthropic is upfront about the tradeoff. In its words, the outputs “will be fully model-generated, without human review or triage.” The company says this “will enable faster and more frequent scanning, but means that it is possible reports will be incorrect or invalid.”

I’d give Anthropic credit for saying it plainly. But it does put the burden back on maintainers. Someone still has to read each report, try to reproduce the issue, and decide whether it’s real. For a small project run by one or two volunteers, a pile of false positives can eat hours that would’ve gone into actual fixes.

The opt-in design helps here. Maintainers who sign up know what they’re getting, and they can presumably leave if the noise outweighs the value.

🐧 Why the Timing Matters

OSS Scanner lands in the middle of a messy moment for open-source security. The Verge AI points out it’s “far from the first AI bug hunting helper out there.” AI tools have already found serious flaws in recent months, including the “Copy Fail” bug that hit nearly every Linux distribution in May.

That’s the upside. AI can read huge amounts of code and spot patterns human reviewers miss.

The downside is just as real. Some open-source projects are struggling to keep up with a flood of AI-generated bug reports. The Verge AI notes that Linus Torvalds and even Google have been dealing with that problem. Low-quality automated reports waste maintainer time and can bury the real issues.

So Anthropic is stepping into a space where AI bug reports have earned both respect and some well-deserved skepticism.

🧭 How It Stacks Up

What stands out is the opt-in, no-cost setup. A lot of the AI report flood has come from outside researchers and bounty hunters running tools against projects that never agreed to it. OSS Scanner flips that. The maintainer asks for the scan, so reports go to someone expecting them.

Anthropic also has an obvious strategic interest. Showing that its models can find real vulnerabilities is a strong pitch for enterprise security customers. Giving that capability to open source for free builds goodwill and a public track record at the same time.

👀 What to Watch

The real test is accuracy. If OSS Scanner’s reports mostly hold up, it could become a standard part of how open-source projects handle security, especially the under-resourced ones that hold up a lot of modern infrastructure. If the false-positive rate is high, maintainers will drop it fast.

I’d also watch whether Anthropic eventually adds human triage for high-severity findings, or shares data on how many reports turn out to be valid. Numbers like that would tell us a lot more than any launch announcement.

Full details on the launch are in the original report from The Verge AI.

Scroll to Top