A security report that no human has ever laid eyes on, delivered straight to the maintainers of an open-source project—that's how Anthropic's new service OSS Scanner works, and it's what sets it apart most from traditional security audits.
Anthropic announced that open-source projects joining the service will receive "regular, full security scans from our most capable model, completely free." Behind that statement lies a clear trade-off: the scan reports aren't reviewed or triaged by humans—they come straight from the model. Anthropic explains that this design allows for faster, more frequent scanning, but the cost is that "reports may be inaccurate or invalid." The models responsible for producing these reports include the company's most powerful model, Claude Mythos, with the goal of giving open-source projects "the maximum defensive advantage."
This isn't Anthropic's first foray into code security. The company already offers a paid product, Claude Security, providing general-purpose code scanning and patching services. What sets OSS Scanner apart is that it targets open-source projects specifically—and it's free.
Anthropic says the service was inspired by OSS-Fuzz, the scanning tool that Google and the Open Source Security Foundation (OpenSSF) have provided since 2016. The logic behind both is similar: major tech companies rely heavily on open-source code to support their infrastructure, yet this code is often maintained by unpaid contributors—meaning a single vulnerability can have an outsized impact. The 2024 XZ Utils backdoor incident is a case in point, where the flaw could have given hackers administrative access to millions of systems worldwide.
Anthropic has not yet disclosed the specific process for open-source projects to apply for OSS Scanner, nor details about how often scans will run.