Anthropic PBC has announced a new service – OSS Scanner – that gives open source projects the ability to receive periodic, in-depth security scans using the company’s most powerful AI models, at no upfront cost. The initiative is part of the broader Anthropic Cyber Mission, which aims to protect both critical infrastructure and the open source ecosystem from the growing threat landscape driven by AI.
The service is designed to automate vulnerability detection and provide direct, fully documented notifications to project maintainers. According to SiliconANGLE, OSS Scanner operates as a live service that any eligible project can purchase by submitting a pull request to Anthropic’s GitHub repository. The evaluation is based on the project’s impact on infrastructure and user security, and projects that don’t have the resources to process raw data will still receive human-verified notifications through the existing disclosure process.
How does OSS Scanner work?

OSS Scanner relies on trusted AI models, including Claude Mythos, to scan codebases and generate a „reproducer“ – a self-contained test that can reproduce the vulnerability. Each report also includes a potential fix and a „bisection“ analysis of the code history, which indicates when the bug was introduced. This information, according to SiliconANGLE, allows maintainers to understand the problem more quickly and take action without additional human verification.
Early testing showed that out of 97 critical and high-risk findings, 85 were confirmed as suitable for disclosure, while the rest were mostly repeats of already known vulnerabilities. WolfSSL Inc. confirmed that out of 74 reports received, 72 were correct, and five of them became CVEs. This data suggests that the accuracy of the model is quite high, although some reports may have inaccurate severity ratings.
Critical Infrastructure Program Context
OSS Scanner is just one of two parts of the Anthropic Cyber Mission. The other, the Critical Infrastructure Defense Program, is designed to help security companies that work with power grids, water systems, and other OT (operational technology) solutions. The program has already attracted 11 partners, including Accenture, Deloitte, CrowdStrike, Palo Alto Networks, Hitachi, and Rockwell Automation. These partners provide consulting, security solutions, and even manufacture and upgrade hardware that often cannot be turned off due to long periods of operation.
Open source community reaction

The new service has attracted a lot of interest from the cryptocurrency and other technology sectors. According to Cointelegraph, Ethereum client developers Nethermind and Bitcoin and Lightning wallet ZEUS have already applied to join the OSS Scanner. These projects hope to receive fast and reliable notifications of potential vulnerabilities so that they can patch them in time and prevent potential attacks. Other candidates – such as VirtEngine, a decentralized cloud computing platform – are also looking to take advantage of the opportunity.
Financing and future prospects
„The Anthropic Cyber Mission relies not only on technological means, but also on financial support. The company has committed $1.4T4 million to various organizations, including OpenSSF and the Apache Software Foundation, and has provided $1.4T100 million in usage credits through Project Glasswing. This investment allows the OSS Scanner to remain free and ensures that projects can receive ongoing scans at no additional cost.
While the service is still in its early stages, early tests suggest that AI models can provide a significant advantage over potential attackers, especially when it comes to OT systems that cannot be shut down due to long service cycles. Anthropic says this approach will help reduce the „vulnerability-to-exploit“ time frame, where a vulnerability is discovered but not yet patched.
Conclusions
Anthropic OSS Scanner is a significant step towards strengthening open source security, giving projects access to cutting-edge AI models at no direct cost. The service’s integration with existing disclosure processes, partnerships with critical infrastructure security leaders, and significant financial backing demonstrate that the company is serious about addressing the cybersecurity challenges associated with AI. If this initiative remains effective, it could become standard practice not only in the open source community but also in the broader technology sector.
Sources
- Biztoc.com - Anthropic launches free AI security scans for open-source projects
- SiliconANGLE News – Anthropic launches critical infrastructure program and free OSS Scanner for open source
- Crypto Briefing – Anthropic launches Cyber Mission to defend power grids and open-source code
- Cointelegraph - Crypto projects apply for Anthropic's new frontier AI security scanner
- Slashdot.org - AI company moves to defend critical infrastructure and open-source projects from AI






