Anthropic says its AI models flagged more than 29,000 possible software vulnerabilities over six months. Its human reviewers could examine only about 6,000. On October 8, the company launched Anthropic OSS Scanner, a free service designed to send eligible open-source maintainers security findings before a human at Anthropic checks them.
The offer could shorten the time between discovering a dangerous bug and telling the people who can fix it. It also moves a difficult job onto projects that may already be stretched thin: deciding which machine-generated warnings deserve urgent attention.
What Anthropic OSS Scanner actually delivers
Accepted projects receive periodic scans from Anthropic’s strongest models, including Claude Mythos. According to the service FAQ, reports arrive by email with a description, a way to reproduce the suspected issue and a proposed patch when available. They are not human-reviewed before delivery. The scan schedule is not guaranteed.
Enrollment is not open to every developer seeking a free code audit. Core maintainers must submit a configuration through the project’s repository and pass eligibility checks focused on software with substantial infrastructure or user-security impact. Anthropic says it verifies maintainer status.
The accuracy numbers need context
In an early test, Anthropic’s reviewers examined 97 selected high- or critical-severity findings across 48 projects. The company says 85 met its coordinated-disclosure standard; 11 others were genuine but duplicated known or separately reported problems, and one was invalid. Those figures describe a selected, company-run evaluation—not a measured accuracy rate for every future report.
As The Verge notes, open-source maintainers are already grappling with floods of AI-generated bug reports. Faster detection is useful only if teams can reproduce, prioritize and patch findings safely. SiliconANGLE likewise points to the gap between finding a flaw and repairing it.
Who carries the risk?
Anthropic’s published policy imposes no automatic 90-day public-disclosure deadline on these unvalidated reports. Its separate, human-reviewed disclosure process remains in place. That gives maintainers room to investigate uncertain findings, but the new fast track does not guarantee that a warning is real, correctly rated or fixed.
The shift matters beyond security teams. Much of the software people use depends on open-source libraries maintained by small groups. If AI can discover suspected weaknesses faster than humans can verify them, the scarce resource is no longer just detection. It is the judgment—and time—needed to turn an alert into a reliable fix.





