Anthropic’s New OSS Scanner Identifies Open-Source Vulnerabilities
Key Takeaways Anthropic has launched OSS Scanner, an AI-powered service designed to automatically identify security vulnerabilities in critical open-source projects. The opt-in program scans enrolled...
Key Takeaways
- Anthropic has launched OSS Scanner, an AI-powered service designed to automatically identify security vulnerabilities in critical open-source projects.
- The opt-in program scans enrolled projects within isolated virtual environments, generating automated reports and proposed patches for maintainers.
- Eligibility prioritizes widely used projects with significant infrastructure impact and exposure to remote attacks.
- The service builds on Anthropic’s established security research, including previous successes in discovering Firefox vulnerabilities using AI.
Anthropic, a prominent AI research company, has unveiled OSS Scanner, a complimentary service aimed at proactively detecting security flaws within critical open-source repositories. This initiative is designed to streamline the vulnerability discovery process by directly notifying project maintainers of potential issues.
Table Of Content
The opt-in program leverages Anthropic’s advanced AI models to conduct continuous, automated scans. This approach offers developers a more rapid method for identifying potential vulnerabilities, bypassing the delays typically associated with manual security reviews.
OSS Scanner represents an expansion of Anthropic’s existing security efforts, particularly its work with Project Glasswing. According to the company’s service overview, Project Glasswing had processed over 6,000 vulnerability reports by October 2026 through its established disclosure framework. The new OSS Scanner provides a distinct pathway for projects willing to evaluate AI-generated security assessments.
Anthropic OSS Scanner Operations
As detailed in its GitHub repository, the scanning process begins by building an enrolled project within an isolated virtual machine. This initial phase, conducted with network access enabled, focuses on installing necessary dependencies and preparing the software for subsequent analysis.
Once the setup is complete, Anthropic severs Internet connectivity to the virtual machine before the security audit commences. This ensures that scanning agents examine the project within a secure, restricted environment, preventing any external communication during the vulnerability assessment.
Maintainers receive vulnerability reports via email, which include detailed steps to reproduce the suspected issue. Where feasible, the reports also propose a patch to address the flaw. Anthropic states that its pipeline incorporates AI agents that rigorously double-check identified bugs and investigate their underlying causes.
It is important to note that these checks are entirely automated; human review of findings does not occur before maintainers receive the reports. Following the initial scan, the service regularly re-evaluates projects for any newly introduced vulnerabilities or issues that may have been overlooked previously. The frequency of these subsequent scans is determined by factors such as demand and the project’s usage.
This initiative underscores Anthropic’s broader commitment to security research, building on earlier achievements where its AI model, Claude, successfully uncovered 22 vulnerabilities in Firefox.
Enrollment and Eligibility
Core maintainers interested in enrolling their projects must apply through the official GitHub repository. The application process involves opening a pull request to add a new directory under projects/<name>. Each submission requires a project.yaml configuration file, which must contain the repository address and a primary contact email. Anthropic manually verifies that applicants are indeed core maintainers before accepting a project into the program.
Eligibility criteria for OSS Scanner focus on established projects that demonstrate broad adoption, significant exposure to remote attack vectors, and a substantial impact on infrastructure security.
A Dockerfile is mandatory, detailing how to install dependencies and build the software. This file can reside either within the project’s own repository or alongside project.yaml in the enrollment repository. All components required for building and testing must be downloadable during the setup phase, as the subsequent audit environment will lack Internet access.
Maintainers have the option to include a threat_model.md file, which serves to guide the scanner. This file allows developers to specify where untrusted input enters the system, delineate components that are out of scope, and articulate their preferred severity ratings for vulnerabilities.
Furthermore, maintainers can use this file to explain desired report formats and patch requirements, thereby reducing the need for the scanner to infer project-specific security expectations.
Before submitting an application, developers can utilize tools/validate.py to verify their configuration and tools/check <name> to test the build process. Anthropic advises users that the checking tool operates with network access, so it should only be used with trusted projects or within a dedicated, isolated machine.
It is important to be aware that email addresses provided in the configuration are publicly visible. Therefore, using a dedicated security alias is recommended. Maintainers can also provide an OpenPGP public key for encrypted reports; however, encrypted messages are sent exclusively to the primary contact and cannot include additional recipients.
Anthropic does not enforce a 90-day disclosure deadline for unvalidated findings identified through OSS Scanner. Nevertheless, a report that is subsequently confirmed via Anthropic’s human-reviewed disclosure program may then fall under that program’s disclosure timeline. This provision is a crucial safeguard, addressing concerns that AI-generated vulnerability reports could potentially consume maintainers’ time without yielding actionable intelligence. Project owners remain responsible for reproducing suspected flaws and thoroughly testing any suggested fixes before classifying them as confirmed vulnerabilities. Projects can be temporarily paused by setting disabled: true in their configuration, or entirely withdrawn by deleting their enrollment directory.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.