OSS Scanner Drops the Human Gate on Purpose
Anthropic's free OSS Scanner sends unreviewed findings from its strongest models, including Claude Mythos, to opted-in projects and how that differs from CVD.
Anthropic opened a free, opt-in vulnerability scanner for open-source projects that ships findings from its strongest models, including Claude Mythos, without a human clearing each report first. The company dated the launch October 8, 2026, in its Frontier Red Team research post.
Over the last six months Anthropic says it discovered more than 29,000 candidate vulnerabilities and manually reviewed and triaged only about 6,000 of them. OSS Scanner and Anthropic's coordinated vulnerability disclosure process diverge on whether a human still clears each finding before it reaches a maintainer.
Human triage still bottlenecks Anthropic's six-month scan backlog
Over the last six months Anthropic used its latest models on major software projects and says it discovered more than 29,000 candidate vulnerabilities. Only about 6,000 of those went through manual review and triage. The company is blunt about the constraint: human capacity, not model throughput, is the choke point.
That is why Anthropic still runs coordinated vulnerability disclosure (CVD) for human-verified reports, especially for projects that cannot triage a flood of findings. Maintainers who could handle volume already asked for something else. Anthropic says it has sent nearly 5,000 reports directly after projects requested every unverified finding with proposed patches. The CVD lane remains the gated path. It is also the path that cannot keep up with the discovery rate Anthropic itself is publishing.
OSS Scanner removes that gate so maintainers get raw model packs
OSS Scanner is the optional fast track. Opted-in projects get periodic scans at no cost from Anthropic's strongest models. The outputs are fully model-generated, with no human review or triage. Anthropic says that design choice enables faster and more frequent scanning, and that reports can be incorrect or invalid. The Verge's October 8 write-up quotes the same trade-off: projects may get alerted sooner, but OSS Scanner's reports do not come with human review.
Each report is meant to be actionable on arrival. Anthropic describes a self-contained reproducer, an explanation of the vulnerability (with a bisection to when the bug was introduced when possible), and a candidate patch when one is available. Early validation with dozens of projects produced hundreds of bug reports, including chains to unauthenticated remote code execution. Anthropic lists those contents as the standard package for each OSS Scanner report in the launch post.
SecurityWeek's account adds that Anthropic expects a true-positive rate above 90% and wants to improve it over time. The public accuracy check Anthropic did publish is narrower and dated to the launch materials: expert penetration testers who review CVD findings checked 97 critical and high-severity scanner findings across 48 projects. Of those, 85 (88%) met the CVD bar. Of the remaining 12, 11 were real but duplicated known issues or other scan findings, and one was a false positive. Maintainers have also told Anthropic that severity can be inflated or that the scanner can miss a project's threat model. Anthropic does not claim perfection.
| Dimension | OSS Scanner | Anthropic CVD disclosures |
|---|---|---|
| Human review before delivery | None. Fully model-generated. | Manual review and triage before disclosure. |
| Cost to eligible OSS projects | No cost, per Anthropic's launch post. | No product fee stated. Throughput limited by Anthropic's review staff. |
| Models named | Strongest models, including Claude Mythos. | Same discovery stack, filtered through human CVD. |
| Typical package | Reproducer, explanation, bisection when possible, candidate patch when available. | Human-verified vulnerability reports through the existing CVD process. |
| Who starts the flow | Core maintainers opt in via a GitHub PR using Anthropic's project template. | Anthropic discloses after validation, especially when projects lack triage capacity. |
| Error mode Anthropic flags | Incorrect or invalid reports, inflated severity, threat-model mismatch. | Backlog: tens of thousands of candidates versus thousands reviewed. |
Projects that asked for every unverified finding already proved the demand
Anthropic positioned Claude Security as the general-access enterprise scanning and patching product. OSS Scanner is the no-cost lane for open-source projects with critical infrastructure impact, judged case by case on criteria similar to Google's OSS-Fuzz. Enrollment is a maintainer PR into Anthropic's GitHub repo, with an extended FAQ for details. Anthropic also points remediating projects toward Claude for OSS free Claude Max 20x subscriptions, and toward the Cyber Verification Program for vetted security professionals who need advanced cyber capabilities.
Maintainer quotes in the launch post describe what early reports looked like in practice. Noah Misch at PostgreSQL said an unusually high fraction of findings uncovered real defects and that fast-track access let the project address issues before a GA release. Anton Arapov at OpenSSL Corporation said raw model output was as good as, and sometimes better than, human reports when a real exploit was attached. Todd Ouska at wolfSSL said 74 reports arrived with all but two valid and five becoming CVEs. Daniel Stenberg said OSS Scanner found multiple curl issues worth fixing, including one of the worst curl vulnerabilities reported in recent years. Anthropic says maintainers have gone from receiving mostly slop from LLMs to receiving high-quality bug reports, and it will continue human-verified CVD especially for projects without the resourcing to triage reports themselves.
OSS Scanner assumes the receiving project can reproduce exploits, discard inflated severity, and absorb occasional incorrect or invalid reports. If you need Anthropic to vouch for each finding before it hits your tracker, CVD is still the gate, and the 29,000-to-6,000 gap is why that gate stays slow. The CyberGym jump Anthropic cites (under 20% of vulnerabilities found early last year to over 85% this year on that academic benchmark) explains the discovery side. It does not erase triage work on the receiving end.
The accuracy sample that exists is the 97-finding CVD-bar check Anthropic published with the October 8 launch. Broader field performance after wider enrollment is not in the public materials yet. Until Anthropic publishes a dated post-enrollment true-positive sample for OSS Scanner beyond that launch validation, the 88% CVD-bar figure and the single confirmed false positive in that set are the only hard accuracy numbers on the record.
Keep reading
AI21 Labs Cuts 60% of Staff, Bets on Maestro
AI21 Labs slashes over 60% of staff, drops foundation models, and pivots to its Maestro agent optimization platform after Nebius acquisition talks collapse.
Alibaba Bans Claude Code Over Security Concerns
Alibaba told staff to remove Anthropic's Claude Code by July 10 over security concerns. Here's what triggered the ban and what it signals.
Anthropic Acquires Stainless: What It Means for AI
Anthropic bought Stainless, the SDK generator behind OpenAI and Cloudflare's client libraries. Here's the strategic play for AI agents.