Anthropic offers free vulnerability scanning for open-source code

Anthropic has launched OSS Scanner, a free service that periodically scans opted-in open-source projects for vulnerabilities using its most capable models. The reports are generated entirely by AI without human review, so they may contain errors. This comes as AI tools have uncovered significant open-source flaws, while maintainers face a surge of AI-generated bug reports.
Anthropic's OSS Scanner is an opt-in program for open-source maintainers. It promises recurring security checks powered by the company's most advanced models, including Claude Mythos, at no charge. Because no people review or sort the findings, the service can scan more often but may produce false or unusable alerts.
The launch follows recent AI-assisted discoveries of serious open-source security problems, such as the "Copy Fail" flaw that affected almost all Linux distributions in May. Yet maintainers, among them Linus Torvalds and Google, have also had to handle a growing volume of AI-generated bug reports.
Open-source maintainers and downstream users could be affected. Free scans may surface overlooked flaws sooner, potentially reducing risk for businesses and individuals relying on shared code. However, unreviewed AI reports may add noise, consuming volunteer time and delaying real fixes. The broader software ecosystem may need clearer ways to validate automated findings, balancing faster detection with maintainer capacity.