Anthropic launched a new service, OSS Scanner, on October 8, 2026. It is an opt-in, free vulnerability-finding service for open-source projects: registered projects are regularly scanned by the company's most powerful large language models, including Claude Mythos. The announcement appeared on Anthropic's official blog, and The Verge covered the news.

Why the service appeared

The scanner's arrival is no accident. Over the past six months, Anthropic's models identified more than 29,000 potential vulnerability candidates in large software projects. The problem is that the company could not keep up with reviewing this volume manually — only about 6,000 findings were checked and triaged by specialists. In other words, most of the vulnerabilities found never received a human look, and valuable findings may have been lost.

Another pattern was observed over the same period: project maintainers who asked to "send all reports" received nearly 5,000 unreviewed reports directly. That practice became the foundation of OSS Scanner: what the model finds is delivered directly, without human intervention. Now this process runs as an official service based on the open consent of project owners — anyone who does not want reports simply does not register and receives nothing.

How the service works

Open-source projects registered with OSS Scanner receive periodic scanning from Anthropic's most powerful models. Reports are fully generated by the model — no human reviews or filters them in advance. This approach makes scanning faster and more frequent, but it also has a downside: some reports may be incorrect or unusable.

Anthropic said it expects its true-positive rate to exceed 90%. That means more than nine out of ten reports are expected to be genuine vulnerabilities — the rest may be false, and project owners accept this in advance. The service is opt-in and free: project owners register, consent to receive scan results, and get reports directly.

Accuracy test: 97 findings passed independent review

To evaluate the scanner's reliability, Anthropic brought in independent experts — penetration testers. They checked 97 critical and high-severity findings across 48 projects one by one. The results broke down as follows: 85 (88%) were deemed significant enough to fit the company's coordinated vulnerability disclosure process — that is, their severity allowed them to be delivered to project owners through the official disclosure procedure. Another 11 were genuine vulnerabilities but turned out to be duplicates of already known issues. Only one was a false positive.

"Reports are fully generated by the model, with no human review or filtering — this allows faster and more frequent scanning, but some reports may be incorrect or unusable," Anthropic's official announcement says. The company expects its true-positive rate to exceed 90%.

This test result supports the service's main claim: even without human review, most of the model's reports have practical value and are worthy of the official disclosure process.

What each report contains and what early users say

According to Anthropic, each report consists of several mandatory parts: an independent reproducer or proof of concept, a comment with a bisection analysis showing when the bug was introduced (where possible), and — where available — a candidate patch. This structure lets a project maintainer reproduce the issue, understand its origin, and evaluate the fix. It was also noted that some bugs found in the initial scans could be chained into an exploit for unauthenticated remote code execution — meaning there are serious security threats among the findings.

The projects that first tried the service expressed satisfaction with the results. wolfSSL representative Todd Ouska said that of the 74 reports he received, all but two were usable, and five of them gained CVE status. Noah Misch of PostgreSQL noted that several reports arrived with nearly ready-made fixes — his team could apply them with almost no changes. Anton Arapov of OpenSSL emphasized that the model's raw output is at the level of human-written reports, sometimes even better.

OSS Scanner currently operates on an opt-in basis and is provided to open-source projects for free. Anthropic presents it as its contribution to the security of the open-source ecosystem — a practical example of directing powerful models to the benefit of the broader community.