MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-09 · via Help Net Security

Anthropic rolls out no-cost OSS Scanner to flag flaws in open-source code

Image via Help Net Security
Image via Help Net Security

Anthropic introduced OSS Scanner, a no-cost service that applies its most capable AI models to hunt for vulnerabilities in open-source projects. Maintainers who sign up receive recurring reports describing suspected flaws, ways to reproduce them, and fixes when possible, with findings sent without prior human review. An early version of the scanner produced 97 high- or critical-severity findings across 48 projects; 85 met coordinated disclosure criteria, 11 were duplicates or known issues, and one was invalid.

Expanded Detail

Anthropic's OSS Scanner is a free offering that applies the company's most advanced models to inspect open-source software for security weaknesses. It follows earlier work under Project Glasswing, where Claude was used for vulnerability discovery. Maintainers who enroll get initial scans and emailed report bundles, then later scans that target new flaws and gaps from prior checks. Scan frequency may vary with demand and project usage.

An early scanner version yielded 97 high- or critical-severity findings across 48 projects. Of these, 85 satisfied coordinated disclosure criteria, 11 were real but already known or duplicated, and one was invalid. Anthropic notes reports may overstate severity or misread project security assumptions. Findings go to teams without human validation, so maintainers must verify and prioritize them.

Count words. First para: Anthropic's(1) OSS(2) Scanner(3) is(4) a(5) free(6) offering(7) that(8) applies(9) the(10) company's(11) most(12) advanced(13) models(14) to(15) inspect(16) open-source(17) software(18) for(19) security(20) weaknesses(21). It(22) follows(23) earlier(24) work(25) under(26) Project(27) Glasswing(28), where(29) Claude(30) was(31) used(32) for(33) vulnerability(34) discovery(35). Maintainers(36) who(37) enroll(38) get(39) initial(40) scans(41) and(42) emailed(43) report(44) bundles(45), then(46) later(47) scans(48) that(49) target(50) new(51) flaws(52) and(53) gaps(54) from(55) prior(56) checks(57). Scan(58) frequency(59) may(60) va

Context

... No markdown? Plain text. Good. Need maybe "under 120 words total" for EXPANDED. We have 116. Good. CONTEXT under 90. Good. Need ensure no copying source phrasing. Let's review exact source phrases: "free service" we changed "free tool" "uses the company’s strongest AI models" we "applies its most capable AI models" "find security vulnerabilities in open-source software" we "inspect open-source code for security weaknesses" "Maintainers who opt in receive periodic scans and reports explaining suspected flaws, how to reproduce them and, when available, how to fix them." We "Enrolled maintainers get initial scans and emailed reports, then later scans..." okay. "Project Glass

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Help Net Security →
Related stories
Anthropic Offers No-Cost Security Scanning for Open-Source Code · Cybersecurity
Anthropic debuts free AI-powered vulnerability scans for open-source code · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Anthropic offers free AI security scans to open-source maintainers.” Browse more stories.