Anthropic Unveils AI-Driven Security Tool
On Thursday, Anthropic introduced a new AI-powered tool, the OSS Scanner, designed to enhance security across the open-source ecosystem. This opt-in service aims to identify vulnerabilities using advanced artificial intelligence techniques, informed by Anthropic’s previous work on Project Glasswing.
Efficient and Autonomous Scanning
The OSS Scanner is built to operate autonomously, generating comprehensive security reports without the need for manual review. These reports will leverage Anthropic’s most advanced models, such as Claude Mythos, ensuring thorough and frequent security assessments. The company plans to select projects using criteria akin to Google’s OSS-Fuzz, although this process may adapt over time.
Enrolling in the OSS Scanner Program
Project maintainers interested in enrolling must submit a pull request via the OSS Scanner’s GitHub repository. This request should include a YAML configuration file with essential details like the repository link, contact email, and a Dockerfile path. This setup allows the offline agent to perform security audits without internet access.
Additional optional information can be included, such as extra email contacts, the project homepage, a GPG public key for email encryption, and a threat model file path. Maintainers can also choose to opt out of receiving bug reports.
Current Participation and Disclosure Policies
Currently, 116 pull requests have been submitted for the OSS Scanner. Unlike other programs, Anthropic does not enforce a 90-day disclosure period for vulnerability reports due to potential false positives. However, if a report is manually verified through Anthropic’s Coordinated Vulnerability Disclosure (CVD) program, it may be disclosed after 90 days.
Anthropic has already identified over 29,000 potential vulnerabilities, with more than 6,000 reported to maintainers, resulting in 584 advisories as of early October 2026.
Wider Implications and Future Outlook
Anthropic’s initiative is part of its broader Cyber Mission, which includes the Critical Infrastructure Defense Program. This effort aims to protect vital infrastructure and open-source software from increasingly sophisticated cyber threats.
As AI continues to assist malicious actors in exploiting vulnerabilities, the goal is to equip defenders with tools to swiftly address these threats and explore secure coding practices. Anthropic anticipates that within two years, AI will significantly enhance defensive capabilities, making it easier to detect and fix vulnerabilities before they are exploited.
