On October 8, 2026, Anthropic launched a new service called OSS Scanner. It is a free, opt-in service that offers open-source projects periodic vulnerability scanning with the company's most capable models, including Claude Mythos. Claude Mythos ranks among the company's most powerful models. The announcement was published in the company's official research blog; The Verge also covered it — the project is presented as part of the Anthropic Cyber Mission initiative.
Scanning is not a one-off but periodic — projects enrolled in the service are re-checked regularly. The scanner's distinctive trait is that its reports are generated entirely by the model: no human review or triage. This makes checks faster and more frequent, but it is openly acknowledged that some reports may be wrong or useless. That is why the company also published an accuracy figure: the goal is for over 90% of detected findings to be genuine vulnerabilities.
The service is called OSS Scanner. It is aimed at open-source projects, and participation is free. The service is fully opt-in — no project is scanned automatically; enrollment requires submitting a pull request.
How the Service Works
The eligibility terms for OSS Scanner mirror the criteria of Google's OSS-Fuzz: projects critical to infrastructure and user security are accepted. The core of the selection criterion is how important a project is to infrastructure and user security. Core maintainers enroll by submitting a pull request to the project's GitHub repository with a YAML configuration file and a Dockerfile. The service is fully voluntary — each project team decides for itself whether to join. This selection approach mirrors the one in Google's OSS-Fuzz program — in both cases, priority goes to the most important projects.
What a Report Contains
Each report includes: a self-contained reproducer showing how the vulnerability can be exploited; an explanation helping to determine, as precisely as possible, when the vulnerability was introduced — using the bisection method, where the change that introduced the problem is found by progressively narrowing the range — and, if available, a candidate patch. This complete package lets a maintainer quickly reproduce the issue, find the cause, and fix it. The reproducer's job is to show that the vulnerability works in practice, not just in theory. Reports are sent directly to project maintainers. Over the past six months, nearly 5,000 reports in this same format were delivered to maintainers.
Test Results
Before the official launch, the scanner was tested on major projects. Over the past six months, Anthropic's models found more than 29,000 potential vulnerabilities in major software projects; nearly 6,000 of them were manually reviewed and triaged — after which nearly 5,000 were sent directly to maintainers as reports.
During the independent evaluation stage, experienced penetration testing specialists assessed 97 critical and high-severity findings across 48 projects. Of these, 85 (88%) met the coordinated vulnerability disclosure criterion — this assessment is based on the independent specialists' review, not the scanner's own claims; 11 were real but duplicates of already-known issues; only one was a false positive.
Early testers included PostgreSQL, OpenSSL Corporation, wolfSSL, HotCRP, and curl — so the service was tried on projects of different categories. For wolfSSL, 5 of 74 reports received official CVE status — meaning roughly every 15th report earned an official vulnerability identifier.
The scanner found several issues, including one of the most serious curl vulnerabilities in recent years, said the curl project lead (via Anthropic's official blog).
How Far the Models Have Come
According to Anthropic, large language models' score on the academic CyberGym vulnerability-finding benchmark was under 20% at the start of last year — and has risen above 85% this year. The "under 20%" figure refers to the start of last year; the "over 85%" figure to the current year. As The Verge writes, the service is presented within Anthropic's broader Cyber Mission initiative. Against the backdrop of this progress, the company decided to support the open-source ecosystem with a free scanning service. The service launched on October 8, 2026, and projects that want to join can apply via pull request.

