Anthropic announced a new service called OSS Scanner on Oct 8, 2026. The service scans the source code of any open‑source project that opts in and returns a list of possible security flaws. The scans are performed by the company’s strongest language model, Claude Mythos, and are offered at no charge.
How OSS Scanner works
The scans are fully automated. Anthropic’s model looks for patterns that indicate bugs, writes a short explanation, and even suggests a patch when possible. Because there is no human reviewer, the reports can be delivered quickly, but they may contain false positives or incomplete fixes.
Early feedback
Early participants say the reports are useful. A PostgreSQL maintainer noted many defects were found and some patches could be applied almost as‑is. OpenSSL and wolfSSL developers reported that most of the 74 reports they received were valid, with five turning into official CVE entries.
Why it matters
Open‑source maintainers can get security warnings sooner without paying for a commercial scanner. However, because the findings aren’t vetted by humans, developers need to verify each report before trusting a fix.