Anthropic Offers No-Cost Security Scanning for Open-Source Code

Anthropic introduced OSS Scanner, an optional service that uses AI to find vulnerabilities in open-source projects. Projects that opt in will receive regular scans from the company's most capable models at no charge. The effort draws on Anthropic's experience using Claude during Project Glasswing.
Anthropic has introduced OSS Scanner, an optional offering that applies artificial intelligence to uncover weaknesses in open-source code. Projects that choose to participate would receive recurring scans performed by the company’s most advanced models, with no fee attached. The initiative is informed by Anthropic’s prior use of Claude in Project Glasswing. Because open-source components are widely reused, automated vulnerability detection has become a closely watched area, though the effectiveness and limits of such tools remain open questions.
Open-source maintainers, often volunteers with limited security resources, could benefit from no-cost automated scans, while downstream users and organizations that depend on shared code may see vulnerabilities surfaced earlier. If the scans are accurate, they might reduce the time between flaw introduction and remediation. Yet AI-based findings may also generate false positives or create misplaced confidence, so human review and responsible disclosure practices would remain important. The broader effect may depend on how many projects opt in and how reliably the service performs.