we_are_coded.by CODE · The world, decoded
БГ
Anthropic

Anthropic launches a free scanner for open source with reports no human reviews, and of more than 29,000 findings it has triaged about 6,000

Anthropic · event date: 8 October 2026Builders

OSS Scanner, announced on 8 October, periodically scans open-source projects with Anthropic’s strongest models, including Mythos, and sends the reports without human review. Enrollment is by request, with criteria like OSS-Fuzz. The numbers are Anthropic’s.

In short
  • 8 October 2026: Anthropic launches OSS Scanner, an opt-in and free service that periodically scans open-source projects with its strongest models, including Claude Mythos.
  • The reports are fully model-generated, without human review; each carries a reproducer, an explanation and a candidate patch where available. Anthropic admits some of them will contain inaccuracies.
  • According to Anthropic: over 29,000 candidate vulnerabilities in six months, about 6,000 reviewed by hand, nearly 5,000 unverified reports sent to maintainers who asked for them. A test: 85 of 97 critical and high findings clear the bar (88%).
Checked on9 October 2026Responsible editorCvetelin IvanovHow we workMethod · Corrections

Over 29,000 candidate vulnerabilities, about 6,000 reviewed by hand. The numbers are Anthropic’s, and with them it explains why it is launching a scanner whose reports no human reads before they reach the maintainer.

The facts: on 8 October 2026 Anthropic announced OSS Scanner, an opt-in vulnerability scanner for open-source software, part of its new Anthropic Cyber Mission. Projects that enroll receive periodic scans at no cost by its strongest models, including Claude Mythos. The reports are fully model-generated, without human review or triage, so they may be incorrect; each contains a self-contained reproducer, an explanation (including when the bug was introduced, where it can be determined) and a candidate patch where available. Core maintainers of eligible projects enroll by submitting a pull request to a GitHub repository following a template; the criteria are like Google’s OSS-Fuzz, the project should have a “critical impact on infrastructure and user security”, and decisions are made case by case. The numbers are Anthropic’s: over the last six months its models discovered over 29,000 candidate vulnerabilities, about 6,000 of which have been manually reviewed and triaged; nearly 5,000 unverified reports were sent directly to maintainers who asked for everything it had. In a test by the expert penetration testers Anthropic uses to check its disclosures, on 97 critical and high-severity findings from the scanner across 48 projects, 85 (88%) met the bar for its coordinated disclosure process, 11 of the remaining 12 were real but duplicated known issues or other findings, and one was invalid. On the academic benchmark CyberGym, language models in general went from finding under 20% of vulnerabilities at the beginning of last year to over 85% this year. Anthropic quotes maintainers from the early testing: wolfSSL, which received 74 reports, all but two valid, five of which became CVEs; Daniel Stenberg of curl says the scanner helped find “one of the worst curl vulnerabilities reported in the last few years”.

By Anthropic's own account, what holds it back is human capacity: the models find more than its people can validate. So it sends the raw output, with a proposed fix, to maintainers who asked, and leaves them to decide.

Finding holes is no longer the bottleneck. Checking them is.

I have seen this at a door: however fast the ticket scanner is, someone still stands there and looks at what it shows. Here that someone becomes the maintainer. The service is for projects with the capacity to keep up with the findings; for the rest Anthropic promises to continue with manually verified disclosures.

The most concrete number is the test: 85 of 97 pass, one is a false alarm. It was measured by the experts Anthropic uses to check its own disclosures, and only on critical and high findings. Some maintainers, Anthropic writes, have said severity ratings can be inflated or that the scanner misunderstood the project’s threat model.

For maintainers, enrollment is a pull request following a template in an Anthropic GitHub repository. It is not for everyone: the criteria are like OSS-Fuzz, and the decision is case by case. It stays free, Anthropic says, thanks to the Defender Advantage Fund (0xDAF), launched in August.

How many reports will be true is a forecast for now: over 90%, according to Anthropic in the Cyber Mission announcement. The test in its research post gives 88%, but it measures something else, the share that cleared the disclosure bar. The real number will come from the maintainers.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Anthropic - Launching an opt-in vulnerability-finding service for open-source software, 08.10.2026→Anthropic - Introducing the Anthropic Cyber Mission, 08.10.2026
Original: https://wearecoded.com/en/articles/anthropic-oss-scanner-bezplatno-za-open-source.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news