Anthropic OSS Scanner Sends Free Unreviewed Vuln Reports After 85 of 97 Early High Findings Met CVD Bar Across 48 Projects
Anthropic launched OSS Scanner on Oct 8, 2026: free opt-in vulnerability scans by its strongest models, including Claude Mythos, with no human triage. Early tests cleared 85 of 97 high findings across 48 projects.

Anthropic launched OSS Scanner on October 8, 2026: a free, opt-in service that runs its strongest models, including Claude Mythos, against enrolled open-source projects and emails maintainers raw findings with no human review or triage.
The company says the pipeline grew out of Project Glasswing, where Claude was used to hunt vulnerabilities at scale. Over the last six months Anthropic reports more than 29,000 candidate vulnerabilities and human triage of only about 6,000. Maintainers who asked for everything anyway have already received nearly 5,000 unvalidated reports with proposed patches.
That bottleneck is the product pitch. OSS Scanner is the fast track for projects that can absorb model-generated noise. It is not Claude Security, Anthropic’s paid enterprise scanner, and it is not a guarantee that every critical label is real.
What Anthropic says OSS Scanner does
On the OSS Scanner program page, Anthropic frames the service as an optional alternative to its existing coordinated vulnerability disclosure (CVD) path. CVD reports still get human review. Enrolled projects get model output as soon as scans finish.
The company explicitly compares the idea to Google’s OSS-Fuzz, which fuzzes open-source code for free when projects meet impact criteria. Here the “fuzzer” is a language model stack plus harnesses, including what Anthropic calls token-hungry and experimental setups meant to dig deeper than a casual code chat.
Each report, Anthropic says, is meant to include a self-contained reproducer, an explanation (with bisection of when the bug landed when possible), and a candidate patch when one is available. After the first bundle, projects get periodic rescans for new and previously missed issues. Frequency will depend on demand, how widely a project is used, and other capacity limits Anthropic has not hard-coded in public docs.
Early validation numbers, not marketing fluff
Anthropic asked the same expert penetration testers who review its CVD queue to check 97 critical and high-severity findings from an early scanner build across 48 projects. The published scorecard:
| Outcome | Count | Share of 97 |
|---|---|---|
| Met Anthropic CVD bar | 85 | 88% |
| Real but duplicate of known issues or other scan findings | 11 | 11% |
| Invalid (false positive) | 1 | 1% |
That is a strong early signal for high and critical labels, and still not a blank check. Anthropic itself says some maintainers report inflated severity or a misunderstood threat model. Help Net Security repeated the same 97 / 85 / 11 / 1 split and the “we can’t guarantee the scanner will be perfect” caveat.
Named early feedback includes PostgreSQL (Noah Misch), OpenSSL (Anton Arapov), wolfSSL (Todd Ouska: 74 reports, all but two valid, five CVEs), HotCRP (Eddie Kohler), and curl (Daniel Stenberg). Those are testimonials, not independent lab audits.
Confirmed vs still fuzzy
| Claim | Status | Source |
|---|---|---|
| Free opt-in scans by strongest models including Claude Mythos | Confirmed | Anthropic Oct 8 research post; OSS Scanner FAQ |
| No human review or triage on OSS Scanner report emails | Confirmed | Anthropic launch post |
| 29,000+ candidates in six months; ~6,000 human-reviewed; ~5,000 bulk reports sent on request | Confirmed (company figures) | Anthropic Oct 8 |
| 97 high/critical findings across 48 projects; 85 CVD-ready; 11 duplicates; 1 invalid | Confirmed | Anthropic Oct 8; Help Net Security |
| Eligibility roughly like OSS-Fuzz (critical infrastructure / user security impact) | Confirmed | OSS Scanner FAQ; case-by-case |
| Audit agents run offline after Dockerfile setup downloads deps | Confirmed | OSS Scanner FAQ |
| No mandatory 90-day disclosure on unvalidated findings | Confirmed | OSS Scanner FAQ |
| If Anthropic later validates via CVD, 90-day clock can start from human-validation notice | Confirmed | OSS Scanner FAQ |
| Free Claude Max 20x via Claude for OSS to help remediate | Confirmed (company offer) | Launch post; FAQ |
| Exact scan cadence per project after enrollment | Unstated | Capacity-dependent |
| Public acceptance rate or queue length for PRs | Unstated | Case-by-case enrollment |
How maintainers enroll (and what they must ship)
Core maintainers open a pull request on github.com/anthropics/oss-scanner that adds projects/<name>/project.yaml. Required fields cover the git repo URL, a primary contact email, and a Dockerfile path (or a Dockerfile sitting next to the yaml). Optional fields include extra CC emails, homepage, a threat model path, a GPG key for encrypted mail, and a disabled: true flag to pause later.
The Dockerfile is the hard part. Anthropic builds it with network access so dependencies can download. Everything after that, the security audit itself, runs without internet inside hardened sandboxes. Maintainers are told to make tests pass in the built container and to run tools/validate.py before opening the PR. Anthropic says it will manually confirm you are a core maintainer before accepting a project.
A threat_model.md file (default path .oss-scanner/threat_model.md, or beside the yaml) is optional but important. You can spell out adversarial inputs, out-of-scope areas, severity rubrics, patch style, and dedup rules. Without it, the models guess. That is how you get “critical” labels that feel wrong to your team.
Disclosure rules maintainers should not miss
Unvalidated OSS Scanner findings do not carry a forced 90-day public disclosure deadline. Anthropic’s stated reason is blunt: it will not force maintainers to treat every model email like a human-verified CVE when Anthropic has not read it either.
If Anthropic later validates the same finding through CVD, a 90-day disclosure period can begin from the day you are told a human signed off. The FAQ also warns that as confidence grows, Anthropic may later impose disclosure windows on some high-severity scanner reports, with notice and an opt-out option. Pause with disabled: true or delete your project directory via PR if the volume is too high. Opting out returns you to CVD-only reports.
Attribution is requested, not required: a commit note naming the report ID (example format ANT-2026-ABCD1234) helps Anthropic track what got patched.
OSS Scanner vs Claude Security vs CVD
| Program | Who pays | Human triage | Audience |
|---|---|---|---|
| OSS Scanner | Anthropic (free for enrolled OSS) | No on scanner emails | Eligible open-source maintainers |
| Standard CVD disclosures | Anthropic research process | Yes | Projects Anthropic chooses to report to |
| Claude Security | Enterprise customers | Product workflow (commercial) | Companies securing their own codebases |
Anthropic also points maintainers at Claude for OSS (free Claude Max 20x for remediation help) and at its Cyber Verification Program for qualifying security professionals who need advanced cyber capabilities and reduced blocking classifiers. Those are adjacent offers, not the scanner itself.
What it means for Indian developers
If you maintain widely used libraries, language runtimes, crypto, parsers that touch untrusted input, or infrastructure packages with Indian or global dependents, eligibility is the first filter. Anthropic will decide case by case using OSS-Fuzz-like impact tests, not a India-specific queue. There is no per-scan fee; the cost is maintainer time to build an offline Dockerfile and triage model reports.
Indian product teams that ship agents or consume Claude should keep this launch separate from Anthropic’s other October news. The same week brought a transparency report on unintended agent actions during evals (our coverage of Claude agents cutting live internet after real-site misuse) and a Nov 12 effective Claude usage policy update. Free vuln mail is not a policy exemption.
For startups that depend on curl, OpenSSL, or Postgres, OSS Scanner is upstream insurance you do not control. Do not assume “Anthropic scanned it” means your production build is clean.
Skeptical read for security leads
The 88% CVD-ready rate on 97 early high/critical samples is impressive and narrow. It does not measure medium or low noise, does not publish a full false-positive rate across all severities, and does not say how often severity is dialed down after maintainer pushback. Anthropic openly says it remains bottlenecked on humans for the broader 29,000-candidate pile. OSS Scanner exports that triage burden to maintainers who opt in.
That trade may still be rational. Attackers also have models, and Anthropic’s launch post stresses that exploits can be built in minutes. Getting a reproducer and a draft patch early can beat waiting months for a human CVD ticket. Just staff the inbox. Model confidence is not a fix schedule.
Also watch sandbox claims. Anthropic says scanning agents run only after internet access is disabled in hardened sandboxes, with reports held in an isolated cloud project. Those are company claims without independent verification in the launch materials. For parallel caution, see our note that nine of ten coding agent setups wiped their own logs under pressure, and the agent-sandbox push around NVIDIA OpenShell.
FAQ
Is OSS Scanner free?
Yes for enrolled open-source projects that Anthropic accepts. Anthropic covers the scan cost. Maintainers still pay in engineering time to enroll, keep Dockerfiles building, and triage reports.
Do humans review OSS Scanner emails before they send?
No. Anthropic states that OSS Scanner outputs are fully model-generated without human review or triage. Human-reviewed findings continue on the separate CVD track.
What are the early accuracy numbers?
Penetration testers checked 97 critical and high findings across 48 projects. Anthropic says 85 (88%) met its CVD bar, 11 were real duplicates, and one was invalid.
Is there a 90-day disclosure clock on scanner findings?
Not on unvalidated scanner reports. If Anthropic later validates a finding through CVD, a 90-day period may start from the human-validation notice. Future policy changes are possible with notice and opt-out language in the FAQ.
How is this different from Claude Security?
Claude Security is the commercial product for enterprises securing their own code. OSS Scanner is a free, Anthropic-run opt-in program for eligible open-source projects, with deeper experimental harnesses and Anthropic paying the bill.