Anthropic's free OSS Scanner skips human review on purpose

Some open-source maintainers told Anthropic they wanted everything its models had found in their code, reviewed or not. Anthropic answered with a free service that sends exactly that, and no human checks the reports before they go out. OSS Scanner is one half of the new Cyber Mission described in Anthropic's announcement. The other half covers the power grids, water systems and transportation networks that run on operational technology.
At a glance
- Anthropic's new Cyber Mission starts with two programs: a Critical Infrastructure Defense Program with eleven founding partners for operational technology, and OSS Scanner, free periodic vulnerability scans for opted-in open-source projects.
- Each scanner report carries a proof of concept, an explanation and a suggested fix where one exists, written by Anthropic's most capable models and sent to maintainers without any human review.
- Anthropic expects a true-positive rate above 90% and warns some reports will contain errors such as a wrong severity rating, so the service targets projects with capacity to keep up.
If you have not been following: according to The Hacker News, Anthropic launched Project Glasswing in April 2026, giving partners a preview of Claude Mythos to find and fix vulnerabilities, backed by up to $100 million in usage credits. Anthropic says Glasswing partners uncovered many vulnerabilities but have not yet achieved a sufficient reduction in cyber risk. Earlier this week, Glasswing was folded into an expanded Cyber Verification Program, which opens Anthropic's most capable models to many more defenders.
OSS Scanner sends unreviewed reports and expects more than 90% of them to be real
Under Glasswing, Anthropic scanned hundreds of widely used open-source projects, had humans triage and review many of the potential vulnerabilities, and privately reported findings through its coordinated vulnerability disclosure process. Some maintainers who could triage at scale asked for everything the models had found, reviewed or not. OSS Scanner is the response: an opt-in service that Anthropic says was inspired by Google's OSS-Fuzz.
Enrolled projects get periodic scans from Anthropic's most capable models, free of charge. Each report includes a proof of concept showing how the bug could be exploited, an explanation, and a suggested fix where one is available. Because nobody reviews the reports first, they reach maintainers faster, and Anthropic admits some will be wrong. Its own example is a mis-rated severity.
Anthropic expects a true-positive rate above 90% and says it will work on both that rate and fix quality over time. Projects without the capacity to keep up are not left out. They continue to receive human-verified disclosures under Anthropic's CVD policy.
Eleven founding partners bring Claude to the providers behind power grids and water systems
Power grids, water utilities, factories and transportation networks run on controllers and industrial networks built to last for decades. This equipment is known as operational technology. It often cannot be taken offline to patch, so known vulnerabilities can stay open for years. Operators rely on a small set of trusted providers to tell them what is exposed and which fixes are safe on a running system.
The Critical Infrastructure Defense Program gives those providers frontier Claude models, on-site engineers and Anthropic's threat research. The founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic says several are already working with Claude to fix vulnerabilities. The first step is to learn from this small cohort which strategies work.
The program builds on a cyber defense program for state, local, tribal and territorial governments that Anthropic launched in June. Since then, Anthropic has offered Claude models and technical support to more than half of all US states and some of the largest public critical infrastructure operators. The support covers code scanning and patching, incident response and red teaming.
The 0xDAF fund, launched in August, keeps OSS Scanner free
On the open-source side, Anthropic has funded the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation. It also supports Akrites and Gold Eagle, which collect and coordinate vulnerability reports from many sources so maintainers are not overwhelmed. The Defender Advantage Fund, or 0xDAF, launched in August. It pays for pilot programs and keeps OSS Scanner free.
Maintainers can also apply to Claude for Open Source for free Claude Max subscriptions. They can apply to the Cyber Verification Program for expanded access to Claude's cyber capabilities for defensive work. For comparison, The Hacker News reports that Glasswing came with $4 million in direct donations to open-source security organizations.
How does a model find bugs that years of fuzzing missed?
According to Anthropic's earlier research on Claude Opus 4.6, the difference is in how the code gets read. A fuzzer throws huge amounts of random input at a program and watches what breaks. The model reasons about the code the way a human researcher would. It checks past fixes for similar bugs that were never patched, spots risky patterns and works out which input would break the logic.
A fuzzer is like someone rattling every door handle in a building. The model reads the floor plan and the repair log first. In that February 2026 work, Anthropic said it found and validated more than 500 high-severity vulnerabilities, including in codebases that had run fuzzers for years.
The 90% figure is an expectation. The announcement does not say how it will be measured or how often a fix is included. Anthropic's own diagnosis is that finding vulnerabilities is easier than ever while verifying, prioritizing and fixing them is not, and an unreviewed scanner hands maintainers more of that work. In our view, keeping the service opt-in and limited to projects with triage capacity is the right call.
Where OSS Scanner goes after the first step
Anthropic calls the scanner a first step and lists three directions. It wants to bring the scanner to more projects while keeping human-verified disclosure, automate triage and patching for projects that want it, and research ways to harden or rewrite code. Companies that build security products for critical infrastructure can register interest. Anthropic says the mission will expand and change as it learns what works. It has given no dates for any of this.
Related stories
- Anthropic adds offensive tiers for verified pentesters
- Testing CIMD across Anthropic's clients against a self-hosted server
- Claude's SDKs run the click loop, but the browser is yours
- Claude flagged a diary entry and a human sent it to police
- Claude's constitution rules out even white lies
- Attackers hit a Mythos-found HFS bug within a day
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
