Anthropic launched OSS Scanner on Oct. 8, a free, opt-in service that uses its AI models to search open-source projects for security vulnerabilities, the company said.

Maintainers submit a pull request to the OSS Scanner repository with a Dockerfile and configuration that sets up the project's environment, letting the scanner run audits without internet access, according to The Hacker News. Anthropic said it uses its strongest models, including Claude Mythos, and that reports are fully model-generated with no human review before they reach maintainers.

The service builds on Project Glasswing, a six-month internal effort in which Anthropic's models surfaced more than 29,000 candidate vulnerabilities across widely used software. About 6,000 were reported to maintainers and resulted in 584 published advisories, according to The Hacker News and The Verge.

Anthropic tested an early version by having penetration testers review 97 critical and high-severity findings across 48 projects; 85, or 88%, met the bar for coordinated vulnerability disclosure, the company said, according to The Verge. Anthropic is not applying its standard 90-day disclosure window to OSS Scanner findings, citing the risk of false positives.

Free vulnerability scanning is a good trade for maintainers who cannot pay for a security audit, but reports with no human review before disclosure are exactly the kind of unverified output a maintainer still has to budget time to check.