OSS Scanner, launched by Anthropic on October 8, 2026, is an opt-in vulnerability scanning service for open-source software. Projects that join receive periodic scans by Anthropic's strongest models at no cost, and the reports they get are entirely model-generated, sent to maintainers without human review or triage. In its official research post, Anthropic positions the service as a fast track that runs alongside its existing coordinated disclosure process, where findings are verified by people before they are shared.
Why skip the human review step at all
Over the past six months, Anthropic used its latest models to scan a set of important open-source projects and surfaced more than 29,000 candidate vulnerabilities, while its team managed to review and triage only about 6,000 of them. The bottleneck is not finding bugs; it is human review capacity. At the same time, more maintainers started asking to receive the unverified reports in bulk anyway, and nearly 5,000 such reports have already been sent on request. The reasoning is blunt: working exploit code can now be produced in minutes, so defenders who receive a lead late carry more risk of being beaten to it. Projects without the staff to triage raw reports can still use the existing human-verified disclosure channel, which remains in place.
Trial numbers: 88 percent cleared the bar, one true false positive
Before launch, Anthropic piloted the scanner with dozens of open-source projects over several weeks, including findings that could be chained into unauthenticated remote code execution. Each report carries a self-contained reproducer, an explanation of the flaw (with a bisection to the change that introduced it where possible) and a candidate patch. The penetration testers who normally review Anthropic's human-verified disclosures sampled 97 critical and high-severity findings across 48 projects: 85 met the bar for that process, 11 of the remaining 12 were real but duplicated known issues, and only one was invalid. The wolfSSL team reported that of 74 reports it received, all but two were valid and five became CVEs. Maintainers from PostgreSQL and OpenSSL also responded positively. Anthropic concedes the limits itself: severity ratings can be inflated, and the scanner may misunderstand a project's threat model.
Who can join, and who carries the cost
Core maintainers of eligible projects can apply by submitting a pull request to the GitHub repository Anthropic designates, under criteria similar to Google's OSS-Fuzz, weighted toward projects with critical impact on infrastructure and user security, decided case by case. Speed is the entire point of the service, and the trade-off is equally clear: triage effort moves from Anthropic's reviewers onto the maintainers. Teams able to verify reports quickly gain real time; small projects already short on hands may not be able to absorb an unfiltered report stream and may be better served by the human-verified channel. The first question for a project is not how strong the model is, but whether anyone on the team can keep up with what it sends.