Anthropic offers free AI security scans for open-source projects
By Automate Basics, written with AI from The Verge's original

Anthropic’s OSS Scanner offers free, periodic AI security scans to open-source projects that opt in. Its vulnerability reports receive no human review, so maintainers will need to check the findings before acting on them.
What changed
Anthropic says its new OSS Scanner service will scan open-source projects that choose to participate and send them reports about possible security weaknesses. The scans are periodic and use the company’s most capable models, including Claude Mythos. Anthropic says the service is free for participating projects.
The reports are generated entirely by AI. Anthropic does not have people review or sort the findings before sending them, so a reported problem may turn out to be wrong or invalid. The Verge notes that AI-generated bug reports have already become difficult for some open-source projects to manage. OSS Scanner may bring issues to a maintainer’s attention sooner, but it could also add findings that need checking.
Who can use OSS Scanner?
Open-source projects can opt in to OSS Scanner, according to Anthropic. The company says participating projects will receive the scans at no cost. The source does not name subscription plans, describe any charge for the service or say whether every open-source project is eligible.
The Verge’s report also does not give enrollment instructions or say when a project should expect its first report. For a team that maintains open-source software used at work, the practical question is whether it has someone who can assess incoming findings. Free scans may reduce the effort of looking for possible weaknesses, but the service does not include a person to confirm which reports are valid.
How do I try OSS Scanner at work?
OSS Scanner is worth considering for a maintained open-source project whose team can review security reports. If the project opts in, treat a report as a lead to investigate, not proof that the code has a vulnerability. Check whether the reported issue applies to the project and whether the described behavior can be confirmed before deciding on a fix or alerting users.
Anthropic says no human reviews the scanner’s output before it reaches a project. That makes the team’s own review especially important when a finding looks urgent. The Verge does not provide a sign-up path or instructions for running a scan, so there are no published steps in the source to follow.
Frequently asked questions
Does OSS Scanner cost anything?
Anthropic says open-source projects that opt in will receive periodic security scans at no cost. The Verge’s report does not describe subscription plans, eligibility requirements beyond being an open-source project, or any paid option. It also does not explain how a project enrolls.
Are OSS Scanner’s vulnerability reports checked by people?
No. Anthropic says the reports are produced by its AI models without human review or sorting before delivery. That means a finding could be incorrect or invalid. Project maintainers should check a reported issue against their code before treating it as a confirmed vulnerability.
Related reading
Google releases an offline AI app for meeting notes on MacGoogle AI Edge Foresight is a free experimental Mac app that transcribes meetings and audio files offline. It can turn brief notes into meeting summaries and answer questions using the transcript and local files.
Google brings a task-running Gemini agent to businessesTechCrunch reports that Google is introducing a Gemini agent that can plan and carry out tasks across workplace systems. Google is starting with businesses, but has not specified which plans include the agent or what it costs.
Natura announces a smart ring for voice requests to AI agentsNatura’s Interface smart ring is designed to let people make voice requests to AI agents without picking up a phone. For work, the company points to recording meetings, sharing notes and controlling a computer, though the ring is not shipping yet.
Written with AI from The Verge's original and published after automatic checks: every figure here appears in the original, and no sentence is copied from it. The picture is AI-generated. The original is the authority.
Source: Anthropic launches free AI security scans for open-source projects, The Verge, 8 Oct 2026.