Anthropic is offering open-source software projects free, recurring security scans generated by its artificial intelligence models. Engadget reported on October 9 that the company’s new OSS Scanner will examine participating projects for vulnerabilities and send findings to their maintainers. The service is opt-in, and Anthropic says projects that join will be scanned periodically by its strongest models without charge.

The proposal could give maintainers earlier warnings about weaknesses in widely used code, but it comes with a significant qualification. According to Anthropic’s announcement as quoted by Engadget, the scanner’s reports will be produced entirely by models, with no human review or triage before delivery. Anthropic acknowledged that some reports may therefore be incorrect or invalid. Maintainers will still need to evaluate the findings rather than treat every alert as a confirmed vulnerability.

Automated security alerts reach a maintainer without passing through human review.
The scanner’s reports will be entirely model-generated, so maintainers must account for possible incorrect or invalid findings.

Anthropic says the automated approach is intended to make scanning faster and more frequent. The company also said the reports will use its strongest models, including Claude Mythos, in an effort to give open-source projects a defensive advantage. Engadget noted that recent demonstrations have shown AI models can find vulnerabilities and can also be used to exploit them, placing tools of this kind on both sides of the security contest.

The OSS Scanner follows an earlier model for supporting open-source security. Anthropic said its service was inspired by OSS-Fuzz, a scanner created by Google and the Open Source Security Foundation that has been available since 2016. Engadget also contrasted the new offering with Claude Security, Anthropic’s paid product for broader code scanning and patching. The OSS Scanner is described as performing similar security audits for qualifying open-source projects at no cost.

An AI sentinel scans the open-source foundations supporting a large digital infrastructure.
Open-source components can underpin millions of systems, making vulnerabilities in foundational projects unusually consequential.

The free service also reflects how dependent technology companies are on open-source infrastructure. Engadget observed that both Anthropic and Google rely heavily on public software projects that support internet services and are often maintained by unpaid contributors. A flaw in one of those foundational components can spread risk far beyond the original project, making early discovery valuable to companies and users throughout the software supply chain.

As an example of the stakes, Engadget cited the XZ Utils backdoor, which could have exposed millions of systems to administrative takeover. The article did not claim that Anthropic’s scanner would have prevented that episode, and the company’s warning about false or invalid reports makes the limits clear. The service is a new source of automated evidence for maintainers, not a substitute for verification, remediation work or experienced security judgment.

The practical test will be whether the scanner can produce findings that are useful often enough to justify the attention required to investigate them. The report provides no performance figures, enrollment numbers or independent assessment of the service, so its accuracy and impact remain uncertain. What Anthropic is offering is narrower but tangible: recurring access to high-end model scanning for open-source teams that opt in, paired with an explicit warning that the results arrive unreviewed.