# Anthropic offers free AI security scans for open‑source projects

> The new OSS Scanner uses Anthropic’s Claude Mythos model to give open‑source projects periodic, model‑generated vulnerability reports at no cost.

Oossa · 2026-10-08 · https://oossa.com/en/anthropic-offers-free-ai-security-scans-for-open-source-projects

Anthropic announced a new service called OSS Scanner on Oct 8, 2026. The service scans the source code of any open‑source project that opts in and returns a list of possible security flaws. The scans are performed by the company’s strongest language model, Claude Mythos, and are offered at no charge.

## How OSS Scanner works

The scans are fully automated. Anthropic’s model looks for patterns that indicate bugs, writes a short explanation, and even suggests a patch when possible. Because there is no human reviewer, the reports can be delivered quickly, but they may contain false positives or incomplete fixes.

## Early feedback

Early participants say the reports are useful. A PostgreSQL maintainer noted many defects were found and some patches could be applied almost as‑is. OpenSSL and wolfSSL developers reported that most of the 74 reports they received were valid, with five turning into official CVE entries.

## The facts

- Anthropic launched OSS Scanner on Oct 8, 2026 ("Anthropic launches free AI security scans for open-source projects ... Oct 8, 2026").
- The service uses Anthropic’s strongest models, including Claude Mythos, to generate vulnerability reports.
- Reports are fully model‑generated with no human review, so they can be faster but may include errors.
- Anthropic says it has already discovered over 29,000 candidate vulnerabilities and sent nearly 5,000 reports to maintainers.
- Early users reported high validity: of 74 reports to wolfSSL, all but two were valid and five became CVEs.

## Why it matters

Open‑source maintainers can get security warnings sooner without paying for a commercial scanner. However, because the findings aren’t vetted by humans, developers need to verify each report before trusting a fix.

## Sources & references

1. [Anthropic launches free AI security scans for open-source projects](https://www.theverge.com/ai-artificial-intelligence/1008521/anthropic-open-source-oss-scanner) – The Verge, 2026-10-08

Last updated: 2026-10-08
