Anthropic launches OSS Scanner, a free, opt-in service that periodically uses its frontier AI models to examine enrolled open-source codebases for potential security vulnerabilities. Anthropic provides maintainers with model-generated reports that are intended to be self-contained, often including a reproducer, an explanation, a possible bisect to identify where the issue was introduced, and sometimes a suggested patch. SiliconANGLE and The Verge both frame the initiative as part of broader AI security efforts.

Enrolment is limited to eligible projects, with core maintainers applying via a GitHub-based process and Anthropic assessing submissions case by case, focusing on projects with critical infrastructure or security implications. Multiple outlets note that the service is designed to add recurring candidate findings rather than replace existing security tooling, maintainer review, or responsible disclosure.

A key difference highlighted across reporting is the trust model: Anthropic says OSS Scanner reports are fully model-generated with no human triage or verification before delivery, so findings may be wrong or severity may be misassigned. Anthropic says it will continue using Coordinated Vulnerability Disclosure for projects that require or prefer human-verified reports, and it positions OSS Scanner as an input to maintainers’ verification and patching processes rather than an automated decision system.