Anthropic launches OSS Scanner for open-source vulnerability detection

Anthropic announced OSS Scanner on October 8, a free vulnerability-finding service for open-source projects. Participants will receive periodic scans and reports generated by Claude models without prior human review.
Reports are intended to describe suspected vulnerabilities, demonstrate possible exploitation and suggest a fix where available. Participation is voluntary, with applications submitted by a project's core maintainers. The service is aimed at teams able to assess the incoming reports themselves.
Anthropic warns that automated findings may be wrong, including in their severity assessments. Removing human review allows results to reach maintainers sooner but leaves them responsible for validating those results.
The company explicitly says it covers scanning costs. That clarifies the account of Axios carried by RIA Novosti, which described funding as unclear. Free reports do not remove the need to check findings and test proposed fixes.
Founded in 2021 and based in San Francisco, Anthropic develops the Claude family of language models. OSS Scanner is a separate, voluntary channel for receiving automated findings rather than a guarantee that code is free of vulnerabilities.
