Anthropic Launches OSS Scanner to Proactively Find Vulnerabilities in Open-Source Projects
Anthropic introduces OSS Scanner, a free AI-powered tool designed to automatically identify and report security vulnerabilities in critical open-source software repositories.

Anthropic has unveiled OSS Scanner, a new, free service aimed at bolstering the security of open-source software by proactively identifying vulnerabilities. This AI-powered tool scans critical open-source repositories, sending detailed findings and potential patches directly to project maintainers. The initiative represents a significant step in Anthropic's ongoing commitment to enhancing software security through advanced AI capabilities.
The OSS Scanner operates by first building an enrolled project within an isolated virtual machine, complete with network access to install dependencies. Once the environment is prepared, internet access is disabled to ensure a secure and controlled scanning process. This isolated approach allows Anthropic's scanning agents to examine the project for flaws without external interference. The service leverages Anthropic's most advanced AI models, building upon previous security research and vulnerability disclosure efforts, including work on Project Glasswing.
Upon completion of a scan, maintainers receive detailed reports via email. These reports include steps to reproduce the suspected vulnerability and, where possible, a proposed code patch. Anthropic states that its internal pipeline includes agents designed to double-check bugs and analyze their root causes. However, it's important to note that these checks are automated, and human review is not performed before findings are sent to maintainers. The service is designed to continuously scan projects for newly introduced vulnerabilities or issues that may have been missed in earlier assessments.
Eligibility for the OSS Scanner program is focused on established open-source projects that have broad usage, are exposed to remote attacks, and have a significant impact on infrastructure security. To enroll, core maintainers must submit a pull request to the official GitHub repository, adding a project directory with a configuration file detailing the repository address and a primary contact email. Anthropic manually verifies that applicants are indeed core maintainers before accepting a project into the program.
Project maintainers can enhance the scanning process by providing an optional threat_model.md file. This file can guide the AI by specifying areas where untrusted input is processed, components that are out of scope, and the perceived severity of potential issues. Maintainers can also outline preferred report formats and specific patching requirements, helping the scanner to better align with project-specific security expectations and reducing the likelihood of irrelevant findings.
Anthropic emphasizes that while the AI-generated reports aim to accelerate vulnerability discovery, project owners are still responsible for reproducing the suspected flaws and testing any suggested fixes. This ensures that vulnerabilities are confirmed and addressed appropriately before being treated as definitive. Maintainers have the ability to pause scans by setting disabled: true in their configuration or to withdraw their project entirely by deleting the enrollment directory.
The OSS Scanner initiative is part of a broader trend of AI being increasingly utilized in cybersecurity for vulnerability discovery. While AI offers the potential for rapid and large-scale analysis, human oversight remains crucial for validation and remediation. Anthropic's approach seeks to balance the speed of AI with the necessary diligence required for robust security practices in the open-source ecosystem.
This new tool aims to significantly reduce the time it takes to identify and fix vulnerabilities in the open-source software that underpins much of the digital infrastructure. By providing maintainers with early, AI-generated insights, Anthropic hopes to foster a more secure software supply chain and mitigate potential risks before they can be exploited.
This update highlights Anthropic's expansion of its AI security offerings by making the OSS Scanner freely available to open-source maintainers. The service now leverages Anthropic's most advanced AI models to proactively identify vulnerabilities, offering detailed reports with reproduction steps and potential fixes, building on previous work with Project Glasswing.