SafetyRisk, alignment & guardrails
Anthropic launches OSS Scanner, a free AI vulnerability-scanning service for critical open-source projects
Anthropic's opt-in OSS Scanner uses its strongest models, including the restricted Claude Mythos, to send critical open-source projects free bug reports with reproducers and candidate patches. It arrives as maintainers and Google's bug bounty struggle with floods of automated reports.

OSS Scanner launched on 8 October 2026 as part of the Anthropic Cyber Mission. It is free, opt-in and limited to established, critical projects judged by OSS-Fuzz-style criteria. Projects enroll through a GitHub pull request that includes a Dockerfile and an optional threat model. Reports go to maintainers without a human check first. [1] [2] [8] [9]
Anthropic reports more than 29,000 candidate vulnerabilities so far. In its validation test, 85 of 97 sampled critical or high findings met coordinated-disclosure standards. Its expectation that over 90% of reports will be real is its own projection, and no independent evaluation of the service exists yet. [2] [6]
The launch comes amid strain on maintainers. Linus Torvalds said AI-generated reports had swamped the Linux kernel security list, and Google paused its open-source bug bounty after a rise in mostly invalid automated submissions. Anthropic itself said in May that only 75 of 530 disclosed high or critical Glasswing bugs had been patched. [4] [5] [6] [7]
Unvalidated findings carry no 90-day embargo, so they are effectively public once delivered. Maintainers can use a threat-model file to set scope and severity rules, and the service is aimed at projects that already have capacity to handle verified reports. [9]
The reported figures show bug discovery outpacing repair. For teams that depend on critical open source, this likely means more advisories and faster patch cycles. Precision, deduplication and patch quality may matter more than raw finding counts.
Executive brief
Anthropic says it will scan important open-source projects for security bugs at no cost, and the reports will reach maintainers with no human check first. The service is called OSS Scanner and was announced on 8 October 2026. It runs on Anthropic's "strongest models," including the restricted Claude Mythos (The Verge). Anthropic says it has already found more than 29,000 candidate vulnerabilities and expects more than 90% of reports to be real (Anthropic). The launch came three days after Google paused its open-source bug bounty because of a flood of mostly invalid automated reports.
What changed and event timeline
Mythos goes to defenders only
Anthropic launched Project Glasswing, which gives partners controlled access to Claude Mythos Preview for defensive work and keeps the model out of general release ().
Torvalds calls the kernel security list unmanageable
He said AI-generated reports, many of them duplicates, had swamped the list. Kernel documentation was updated to treat AI-found bugs as effectively public (;).
First Glasswing numbers
Anthropic reported 23,019 findings across more than 1,000 open-source projects. It also said maintainers were having trouble keeping up with patches ().
Google pauses its open-source bug bounty
Google stopped taking product submissions to its OSS VRP after a rise in mostly invalid automated reports. It plans an update in Q1 2027 ().
OSS Scanner launches
It was announced as part of the new Anthropic Cyber Mission, alongside a Critical Infrastructure Defense Program with 11 founding partners (;).
Capabilities and access
- Models: "our strongest models, including Claude Mythos." Anthropic does not give exact versions (Anthropic; OSS Scanner page).
- Report contents: a self-contained reproducer, an explanation (with bisection where possible), root-cause analysis and a candidate patch.
- Who can join: opt-in only, free, and limited to established, critical projects judged by OSS-Fuzz-style criteria.
Read the full section
- Models: "our strongest models, including Claude Mythos." Anthropic does not give exact versions (Anthropic; OSS Scanner page).
- Report contents: a self-contained reproducer, an explanation (with bisection where possible), root-cause analysis and a candidate patch.
- Who can join: opt-in only, free, and limited to established, critical projects judged by OSS-Fuzz-style criteria. Anthropic checks core maintainers by hand.
- How to enroll: open a GitHub pull request that adds a
project.yamlfile with a repo link, contact, Dockerfile path and an optional threat model (OSS Scanner page). - Scan frequency: "periodic," depending on pipeline capacity.
Technical analysis
- Build and threat model: projects must supply a Dockerfile, which implies agents build and run the code to produce reproducers.
- Isolation: scanning agents run in hardened sandboxes with internet access turned off. Reports are kept in isolated infrastructure.
- Disclosure: unvalidated findings carry no 90-day embargo.
Read the full section
- Build and threat model: projects must supply a Dockerfile, which implies agents build and run the code to produce reproducers. A threat-model file lets maintainers set scope and severity rules (OSS Scanner page).
- Isolation: scanning agents run in hardened sandboxes with internet access turned off. Reports are kept in isolated infrastructure.
- Disclosure: unvalidated findings carry no 90-day embargo. If Anthropic later validates a finding through its normal coordinated disclosure process (CVD), the 90-day clock starts then.
- Reproducibility: Anthropic has not published the agent harness, prompts or a benchmark, so outsiders cannot reproduce its accuracy figures.
Claims and evidence
- More than 29,000 candidate vulnerabilities, about 6,000 triaged by hand (Anthropic).
- Validation test: 85 of 97 critical or high findings (88%) met CVD standards.
- wolfSSL: 72 of 74 reports were valid and 5 became CVEs. This comes from Anthropic's account, not wolfSSL's.
Read the full section
- More than 29,000 candidate vulnerabilities, about 6,000 triaged by hand (Anthropic).
- Validation test: 85 of 97 critical or high findings (88%) met CVD standards. One was a false positive and 11 were real but duplicates (same source).
- wolfSSL: 72 of 74 reports were valid and 5 became CVEs. This comes from Anthropic's account, not wolfSSL's.
- Glasswing sample: 90.6% of 1,752 sampled findings were real, but only 62.4% held their high or critical severity rating. The reviewers were a mix of six outside firms and Anthropic staff (Anthropic).
- The ">90% expected" rate is Anthropic's own projection. No independent evaluation of OSS Scanner exists yet.
Context and prior work
- Other AI bug hunters: Copy Fail (CVE-2026-31431) is a Linux root-escalation bug reportedly found by the Xint Code AI scanner in about an hour (Thrive).
- Precedent for eligibility rules: OSS Scanner borrows Google OSS-Fuzz's criteria for which projects qualify.
- Related programs: Anthropic has also funded OpenSSF, Alpha-Omega, the Python Software Foundation (PSF) and the Apache Software Foundation (ASF).
Read the full section
- Other AI bug hunters: Copy Fail (CVE-2026-31431) is a Linux root-escalation bug reportedly found by the Xint Code AI scanner in about an hour (Thrive). The sources disagree on when it was disclosed. Thrive says 7 April; The Verge places its impact in May.
- Precedent for eligibility rules: OSS Scanner borrows Google OSS-Fuzz's criteria for which projects qualify.
- Related programs: Anthropic has also funded OpenSSF, Alpha-Omega, the Python Software Foundation (PSF) and the Apache Software Foundation (ASF). It created the Defender Advantage Fund in August 2026, which helps keep OSS Scanner free (Anthropic).
Limitations, safety and contested findings
- Possible wrong reports: Anthropic says reports may be wrong and severity may be inflated or not match a project's threat model (Anthropic).
- Maintainer capacity: in May, Anthropic said only 75 of 530 disclosed high or critical bugs had been patched, and some maintainers asked it to slow down (Anthropic).
- Not for overloaded projects: the service is aimed at projects that already handle verified reports, not ones that are already swamped (OSS Scanner page).
Read the full section
- Possible wrong reports: Anthropic says reports may be wrong and severity may be inflated or not match a project's threat model (Anthropic). The Glasswing severity figure (62.4% confirmed) supports that warning.
- Maintainer capacity: in May, Anthropic said only 75 of 530 disclosed high or critical bugs had been patched, and some maintainers asked it to slow down (Anthropic).
- Not for overloaded projects: the service is aimed at projects that already handle verified reports, not ones that are already swamped (OSS Scanner page).
- Report floods elsewhere: Torvalds and Google both describe being overwhelmed by AI reports (LWN; BleepingComputer).
Business and practitioner implications
- Patching is now the bottleneck: finding bugs has become cheap, and teams that depend on critical open source should expect more advisories and faster patch cycles.
- Maintainers should write a threat model before enrolling, to filter out-of-scope or inflated findings.
- No embargo: unvalidated findings are effectively public once delivered, so maintainers should plan triage capacity before they opt in.
Read the full section
- Patching is now the bottleneck: finding bugs has become cheap, and teams that depend on critical open source should expect more advisories and faster patch cycles.
- Maintainers should write a threat model before enrolling, to filter out-of-scope or inflated findings.
- No embargo: unvalidated findings are effectively public once delivered, so maintainers should plan triage capacity before they opt in.
- Vendors' pitch shifts: AI security vendors now compete with a free offering. Precision, deduplication and patch quality matter more than raw finding counts.
The source trail.
Sources (10)
Anthropic launches free AI security scans for open-source projects
Article text retrieved; extracted text may omit tables or interactive elements.
theverge.com