OSS Scanner, announced on 8 October, periodically scans open-source projects with Anthropic’s strongest models, including Mythos, and sends the reports without human review. Enrollment is by request, with criteria like OSS-Fuzz. The numbers are Anthropic’s.
- 8 October 2026: Anthropic launches OSS Scanner, an opt-in and free service that periodically scans open-source projects with its strongest models, including Claude Mythos.
- The reports are fully model-generated, without human review; each carries a reproducer, an explanation and a candidate patch where available. Anthropic admits some of them will contain inaccuracies.
- According to Anthropic: over 29,000 candidate vulnerabilities in six months, about 6,000 reviewed by hand, nearly 5,000 unverified reports sent to maintainers who asked for them. A test: 85 of 97 critical and high findings clear the bar (88%).
Over 29,000 candidate vulnerabilities, about 6,000 reviewed by hand. The numbers are Anthropic’s, and with them it explains why it is launching a scanner whose reports no human reads before they reach the maintainer.
By Anthropic's own account, what holds it back is human capacity: the models find more than its people can validate. So it sends the raw output, with a proposed fix, to maintainers who asked, and leaves them to decide.
I have seen this at a door: however fast the ticket scanner is, someone still stands there and looks at what it shows. Here that someone becomes the maintainer. The service is for projects with the capacity to keep up with the findings; for the rest Anthropic promises to continue with manually verified disclosures.
The most concrete number is the test: 85 of 97 pass, one is a false alarm. It was measured by the experts Anthropic uses to check its own disclosures, and only on critical and high findings. Some maintainers, Anthropic writes, have said severity ratings can be inflated or that the scanner misunderstood the project’s threat model.
For maintainers, enrollment is a pull request following a template in an Anthropic GitHub repository. It is not for everyone: the criteria are like OSS-Fuzz, and the decision is case by case. It stays free, Anthropic says, thanks to the Defender Advantage Fund (0xDAF), launched in August.
How many reports will be true is a forecast for now: over 90%, according to Anthropic in the Cyber Mission announcement. The test in its research post gives 88%, but it measures something else, the share that cleared the disclosure bar. The real number will come from the maintainers.