Announced 8 Oct 2026 · Sources checked
What did Anthropic launch on 8 October?
The research post “Launching an opt-in vulnerability-finding service for open-source software,” dated 8 October 2026, says OSS Scanner is informed by Anthropic’s use of Claude during Project Glasswing. Projects that join “will receive thorough, periodic security scans by our strongest models at no cost.” The outputs “will be fully model-generated, without human review or triage,” including work from Claude Mythos.
Anthropic says language models on the CyberGym vulnerability-finding benchmark moved from under 20% of vulnerabilities at the beginning of last year to over 85% this year. Over the last six months it used its latest models on “some of the world’s most important software projects,” found more than 29,000 candidate vulnerabilities, and manually reviewed about 6,000. Nearly 5,000 reports went to maintainers who asked for the unverified remainder. Those counts are Anthropic’s.
The company will keep sending human-verified reports through coordinated vulnerability disclosure, “especially for projects without the resourcing to triage reports themselves.” The optional scanner is the fast track. That is a different product from Claude Security, which the post calls the general-access enterprise scanner, and from the Cyber Verification Program’s three access tiers, which lower blocking classifiers for qualifying security professionals.
How do maintainers enroll, and what do they receive?
The GitHub repository anthropics/oss-scanner was created at 17:25 UTC on 8 October 2026. The GitHub API lists Apache-2.0. The README says enrollment is a pull request that adds projects/<name>/ with a project.yaml. Required fields are the git repository to clone and a primary_contact email. A Dockerfile must either live in the target repository (preferred) or sit next to project.yaml. Optional fields include auto_ccs, homepage, a threat model, an OpenPGP key, and disabled: true to pause mail.
Anthropic’s FAQ at red.anthropic.com/oss-scanner repeats those fields and the eligibility test: established projects with a critical impact on infrastructure and user security, judged case by case, with remote-attack exposure and dependent-user counts as examples. “For security, we will manually validate you are a core maintainer before enrolling each project.” Email addresses in project.yaml are public.
After a merge, the README says the scanner imports the project, builds it online in an isolated VM, then moves that VM onto a network with no internet for the audit. Findings go to primary_contact, each with a reproducer and a proposed patch where available. Later scans look for new and previously missed bugs; frequency “may depend on the number of projects in our pipeline.” tools/validate.py checks the config; tools/check builds the image the way the scanner will and can drop you into an offline shell. tools/check installs Claude Code in that image. Those tools are Anthropic’s; we did not run them. The offline VM is a vendor description of agent sandboxing, not a setup we inspected.
What validation and legal terms sit behind the mail?
The launch post says Anthropic spent several weeks with dozens of projects and that early disclosures included “multiple vulnerabilities that we were able to chain to unauthenticated remote code execution exploits.” Named quotes: Noah Misch of PostgreSQL; Anton Arapov of OpenSSL Corporation; Todd Ouska of wolfSSL, who is quoted as saying 72 of 74 reports were valid and five became CVEs; Eddie Kohler of HotCRP. We did not independently count those reports.
To check an early pipeline, Anthropic asked the expert testers who review CVD findings to look at 97 critical and high-severity scanner results across 48 projects. Eighty-five (88%) met the CVD bar. Of the other 12, 11 were real but duplicated known issues or other findings from the same scan, and one was invalid. Some maintainers later said severity can be inflated or the threat model misunderstood. That is the same caution we applied to Anthropic’s October disclosure-dashboard totals: a candidate is not a patched install.
The OSS Scanner Agreement, signed on the page as Anthropic Frontier Red Team, says reports are confidential Anthropic material, provided as-is, and may be incomplete or wrong, including bad patches. Participants may use reports only to identify, assess and fix bugs in the enrolled project, and may share them with authorized maintainers. There is no fee. Anthropic’s total liability “will not exceed $1,000.” Anthropic may approve, withdraw, modify, suspend or end a project or the service at any time.
What is the public disclosure policy?
Unvalidated scanner findings have no 90-day coordinated-disclosure period. The FAQ says Anthropic does not want to force maintainers to read every finding it has not read. If Anthropic later validates a report through CVD, the 90-day clock starts from the notice that a human has validated it. Anthropic may later impose a disclosure period on some high-severity scanner reports, with notice and an opt-out.
A project can pause with disabled: true or withdraw by deleting its directory. Questions from non-enrolled people go to oss-scanner-questions@anthropic.com. Attribution, if a maintainer wants it, is a commit line such as “Discovered by Anthropic's OSS Scanner, as vulnerability ANT-2026-ABCD1234.” Reports are said to live in an isolated locked-down cloud project limited to Anthropic security staff who need them.
What should readers not assume?
OSS Scanner is not Claude Security, not a public scoreboard, and not a promise that Mythos-class output is free of false positives. The 88% figure is Anthropic’s review of 97 already-severe findings, not a rate across all mail you will receive. We have not opened an enrollment pull request, built a sample Dockerfile, or verified any quoted CVE. Treat an emailed reproducer as a hypothesis until a human on your project runs it.
Common questions
Does enrolling replace Anthropic’s usual CVD mail?
No. The FAQ says you keep receiving human-reviewed CVD reports. The scanner adds unreviewed model reports. Pausing or leaving the scanner returns you to CVD only.
Will Anthropic publish the unreviewed findings?
The README says Anthropic will not make these unvalidated findings public and will not place a 90-day clock on them. A later human CVD validation can start a 90-day clock from that notice.
Is every open-source repository eligible?
No. Anthropic uses OSS-Fuzz-like “critical impact on infrastructure and user security” language and decides case by case. It also checks that the person opening the pull request is a core maintainer.
What to remember
Use OSS Scanner if your project already handles verified high-severity mail and wants faster, unreviewed model reports under Anthropic’s as-is terms. Stay on human CVD if you cannot triage slop. Do not file a CVE from a scanner email until someone on the project has reproduced it.
Sources & further reading
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





