Anthropic launches free AI security scans for open-source projects
Anthropic gives open-source projects free security scans — but they come unvetted by humans.

Why it matters
Anthropic is shipping OSS Scanner, a free, model-powered vulnerability detector for open-source maintainers. The trade-off: fully automated reports with no human review, which means false positives and negatives are expected. Practitioners integrating open-source dependencies should understand the scan quality ceiling.
The key facts
13 to knowService name: OSS Scanner
Cost: free for opt-in open-source projects
Capability: periodic security vulnerability scans using Anthropic's strongest models
Trade-off: all outputs are model-generated, no human review or triage
Stated benefit: faster and more frequent scanning
Known limitation: reports explicitly may be incorrect or invalid
Target audience: open-source project maintainers
Service: OSS Scanner, free security vulnerability scanning for opt-in open-source projects
Scanning: performed by Anthropic's strongest models
Review process: fully model-generated, no human review or triage
Trade-off: faster and more frequent scanning vs. acknowledged risk of incorrect or invalid reports
Availability: open-source projects can opt in
Cost: no charge
The story so far
Earlier coverage of this storyline
- AI Agents Are Disrupting Open Source Security DisclosureInfoQ AI/ML
- This story
Go to the source
The Verge AItheverge.com
Publisher excerpt: Anthropic's offering to help open-source projects track down security vulnerabilities with a new service called OSS Scanner. It says open-source projects that opt-in will get "thorough, periodic security scans by our strongest models at no cost." That could mean open-source projects get alerted…