Anthropic OSS Scanner: What It Ships, Pricing & Who It's For
OSS Scanner ships free, unreviewed Claude vuln reports to opt-in maintainers. Here is how that path differs from Anthropic’s human CVD lane.
Open-source maintainers who enroll get periodic scans from Anthropic’s strongest Claude models, delivered as model-written packets that include a proof of concept, an explanation, and a suggested fix when one is available. There is no Anthropic human review before the report lands.
Anthropic’s Cyber Mission announcement states an expected true-positive rate above 90%. The split that decides whether you enroll is different: who absorbs the verification work after a finding appears, the maintainer or Anthropic’s coordinated disclosure pipeline.
Maintainer verification work
OSS Scanner is the Cyber Mission’s open-source arm, launched with that October 8, 2026 post as an opt-in service for core maintainers of critical projects. Anthropic frames it as a response to Project Glasswing: humans already triaged many model findings and privately disclosed them under CVD, yet some maintainers with headroom asked for every model hit, reviewed or not.
The packet is deliberately raw. Anthropic says reports are model-generated and sent without human review so they arrive faster, and it also says some will contain inaccuracies such as a wrong severity rating. The company expects a true-positive rate above 90% and says it will work to improve both that rate and fix quality over time. Enrollment stays free of charge. Anthropic credits the Defender Advantage Fund (0xDAF), launched in August, with keeping the scanner free, and it points maintainers toward Claude for Open Source for free Claude Max subscriptions plus the Cyber Verification Program for broader defensive model access.
That design only works if someone on the project side can open the packet, reject the noise, and ship or reject the patch. Anthropic states the service is meant for projects with the capacity to keep up with surfaced findings. If your triage queue is already full, faster delivery still leaves that verification work on the project.
Anthropic CVD pipeline
For projects that cannot absorb that volume, Anthropic says it will continue to share human-verified disclosures under its CVD policy. Human verification before maintainer contact keeps CVD slower than the scanner’s unreviewed stream. Glasswing already showed the bottleneck: Anthropic writes that verifying, prioritizing, and fixing findings remains hard even when models surface bugs easily, and that the team often saw months pass between a vulnerability being found and being fixed.
The scanner’s product shape is also explicit about lineage. Anthropic says OSS Scanner is inspired by Google’s OSS-Fuzz: continuous, opt-in coverage for enrolled projects rather than a one-off celebrity audit. CVD stays the human-gated channel. OSS Scanner is the unreviewed stream for teams that asked for the firehose.
| Dimension | OSS Scanner | Human-verified CVD |
|---|---|---|
| Cost to project | Free (Defender Advantage Fund) | Free disclosure path (no seat fee stated) |
| Human review before send | None; model-generated reports | Anthropic human triage and verification |
| Report contents | PoC, explanation, suggested fix when available | Privately reported, verified findings |
| Stated quality bar | Expected true-positive rate above 90% | Human-verified before maintainer contact |
| Who Anthropic says it’s for | Projects that can keep up with findings | Projects that need the verified lane |
| Enrollment posture | Opt-in for core maintainers of critical OSS | Default Glasswing-style CVD process |
Buyer fit by capacity
If you maintain a critical open-source project with the capacity to keep up with surfaced findings, OSS Scanner matches the ask Glasswing surfaced: get the model pack early, accept that severity and fix text can be wrong, and fold the hits into existing triage. The free Max path and Cyber Verification Program access are adjacent perks for the same defensive cohort, not substitutes for that capacity.
If a project cannot absorb that volume, Anthropic says the match is still human-verified disclosure under its CVD policy. Anthropic is not pretending otherwise. It also lists Claude Security and partner-built defensive products as separate Cyber Mission efforts, so those named paths sit beside the free scanner rather than inside it.
Enroll when a project already has capacity to close or reject findings as they arrive. Skip the opt-in when the project needs Anthropic’s human-verified CVD lane to carry that work.
Keep reading
AI21 Labs Cuts 60% of Staff, Bets on Maestro
AI21 Labs slashes over 60% of staff, drops foundation models, and pivots to its Maestro agent optimization platform after Nebius acquisition talks collapse.
Alibaba Bans Claude Code Over Security Concerns
Alibaba told staff to remove Anthropic's Claude Code by July 10 over security concerns. Here's what triggered the ban and what it signals.
Anthropic Acquires Stainless: What It Means for AI
Anthropic bought Stainless, the SDK generator behind OpenAI and Cloudflare's client libraries. Here's the strategic play for AI agents.