Anthropic Opens Free AI Vulnerability Scanner For Open Source
Anthropic is offering open-source projects free AI security scans, with model-generated reports that may speed vulnerability checks but arrive without human triage.

Anthropic is making its AI vulnerability scanning available at no cost to open-source projects, Engadget reports, adding a defensive service that trades human triage for speed and repeated checks.
The new OSS Scanner gives participating projects periodic reviews by the company's strongest models.
Anthropic framed the program as a free route for maintainers to surface possible security flaws before attackers can use them, a practical concern for codebases that may be widely deployed but maintained by small or unpaid teams.
The control path is deliberately narrower than a full managed security engagement.
Scanner outputs are model-generated, with no human review or triage before the reports reach projects.
That design could increase scanning frequency, but it also means maintainers may have to sort through incorrect or invalid findings alongside useful warnings.
Anthropic's announcement names Claude Mythos among the models behind the service.
The company already sells Claude Security for broader code scanning and patching, while OSS Scanner applies similar audit capability to open-source projects without charging them for access.
The comparison point is Google's OSS-Fuzz, the OpenSSF-backed scanner that has been available since 2016.
Both programs sit around the same operational problem: open-source components support large parts of the internet, yet the people maintaining them often lack the same security budgets as commercial software vendors.
That imbalance can turn a flaw in a small project into infrastructure risk.
The XZ Utils backdoor showed how a compromise in widely used open-source code could have given attackers administrative control over millions of systems.
The material unknown is therefore not whether AI can find software weaknesses; recent examples have already shown that it can.
The harder question is how open-source teams will handle a stream of unreviewed model findings, separating defensive leads from false alarms without adding another unsupported workload.




















