'Projects that join will receive thorough, periodic security scans by our strongest models at no cost.'
Michael M. Santiago/Getty Images
Anthropic is offering open-source projects a new way to check for vulnerabilities with its OSS Scanner. "Projects that join will receive thorough, periodic security scans by our strongest models at no cost," the company announced.
As they've shown recently, AI models are excellent at finding (and exploiting) vulnerabilities. The new scanner could give open-source coders early alerts about potential security issues for free, albeit with the tradeoff that reports won't be reviewed by humans.
"The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage," Anthropic explained. "This will enable faster and more frequent scanning, but means that it is possible reports will be incorrect or invalid. These reports will be generated by our strongest models (including Claude Mythos) to give open-source projects the largest defensive advantage."
As Anthropic mentions, it was inspired by OSS-Fuzz open-source software scanner created by Google and the OpenSSF (Open Source Security Foundation) that has been available since 2016. Anthropic already has a paid product called Claude Security that can perform general-access code scanning and patching, but OSS Scanner performs similar security audits at no cost.
Google and Anthropic aren't necessarily providing these products out of altruism. Both companies rely heavily on open-source code projects that underpin the internet, often run by unpaid workers. Security vulnerabilities in such code are highly dangerous, with a recent example of that being the XZ Utils backdoor that could have handed hackers administrative control over millions of systems around the world.

By Engadget | Created at 2026-10-09 11:35:19 | Updated at 2026-10-09 12:36:49
1 hour ago








