Skip to content
InYourGeek
visiteur@inyourgeek — shell
↹ compléter↑↓ historique⏎ ouvrirhelp
FR
AI· 3 min read

Anthropic launches OSS Scanner: free AI security audits for open source

Anthropic is offering opt-in open source projects free, regular security scans run by its most powerful models. No human reviews the reports before they go out, so sorting them is the maintainers' job.

A robot scanning lines of open source code with a magnifying glass while a tired maintainer sorts a growing pile of security alerts

On 8 October 2026, Anthropic announced OSS Scanner, a security analysis service for open source projects. The Verge reported on it that same evening, working from the overview Anthropic had published. The idea is simple: projects that sign up get free, in-depth scans of their code at regular intervals, run by Anthropic’s best models.

What OSS Scanner promises

Anthropic is putting its most powerful models on the job, including Claude Mythos. It says it wants to give open source projects the biggest defensive advantage it can. For a project, the benefit is hearing about a possible vulnerability sooner, ideally before someone else finds it and exploits it.

Anthropic is upfront about the catch. The reports will be written entirely by the model, and no human will review or filter them. The company says that is what lets it scan faster and more often. It also admits that some reports may be wrong or irrelevant. So you get a machine’s speed, plus the confidence of a star intern who has never been wrong. Or at least, never been wrong in their own opinion.

How to sign up

The service is opt-in. Only projects that ask for it get scanned, and no repository is analysed without its maintainers’ agreement. The source doesn’t say how you sign up, which projects qualify, or how often the scans actually run. Read Anthropic’s overview before you sign up. Don’t assume a three-file repo and a ten-year-old monorepo will get the same treatment.

What it changes for maintainers

OSS Scanner is far from the first AI bug hunter. The Verge notes that tools like this have helped find serious flaws in open source software over the past few months. One example is the “Copy Fail” vulnerability, which hit almost every Linux distribution in May.

Anyone who maintains a popular project knows the downside. AI-generated bug reports are pouring in, and some projects can’t keep up. The Verge’s examples include Linus Torvalds and even Google. If a company that size says it’s struggling with the pile, the volunteer maintainer going through issues on a Sunday night may feel a little less alone.

What sets OSS Scanner apart is that it’s opt-in. Maintainers aren’t buried in these reports without asking. They choose to receive them, and they know where they come from. The work is still there, though. Every alert still has to be reproduced, then confirmed or dismissed. That is exactly the step Anthropic chose to skip.

The sorting still has to be done

If your project has a security team, a steady stream of free scans from a cutting-edge model is worth a look. If it’s run by two people in their spare time, the question is more practical: how many false positives will you have to clear for every real vulnerability? Anthropic hasn’t given a figure. Yet that is the number that will decide whether signing up is worth it.

Anthropic is giving away the smoke alarm for free. But checking whether there’s a real fire, or just burnt toast, is still the volunteer maintainer’s job.

Sources (1)

Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.