Anthropic launches free vulnerability scans for opted-in open-source projects
Anthropic's Cyber Mission offers opted-in open-source projects free vulnerability scans with proofs of concept and fixes. A companion program provides models and engineers to help secure critical infrastructure.

TL;DR
- Open-source projects can opt into free, recurring vulnerability scans with proofs of concept and suggested fixes, according to Anthropic's announcement.
- Maintainers receive model-generated reports without human review through OSS Scanner, one of the services in the Cyber Mission Anthropic announced.
- Critical-infrastructure providers get frontier models, on-site engineers and threat research through the new program described in Anthropic's infrastructure announcement.
- Vetted security teams also gain three access tiers under an expanded Cyber Verification Program, covered in a breakdown of the program.
The enrollment documentation lets maintainers define severity rubrics, patch style and deduplication rules for the scanner. Audits run offline after a network-enabled Docker build, and the research post reports just one invalid finding in a 97-report validation sample.
OSS Scanner
Anthropic launched OSS Scanner on October 8 as part of its Cyber Mission. The service uses its strongest models, including Claude Mythos, with agents that double-check potential bugs, propose patches and perform root-cause analysis.
Each report contains:
- A self-contained reproducer demonstrating the vulnerability.
- An explanation, including bisection to identify when the bug was introduced where possible.
- A candidate patch when available.
Maintainers receive a bundle of reports by email after the initial scan. Subsequent scans look for newly introduced vulnerabilities and bugs missed previously; frequency depends on pipeline demand, project usage and other factors rather than a fixed published interval.
Human review backlog
Anthropic discovered more than 29,000 candidate vulnerabilities over six months but manually reviewed and triaged approximately 6,000, a brutal review backlog documented in its technical account.
Maintainers had already requested nearly 5,000 unverified reports in bulk, with proposed patches. OSS Scanner formalizes that optional fast track by delivering findings without human review or triage.
Anthropic will continue human-verified coordinated vulnerability disclosure for projects without the resources to triage raw findings. It says Glasswing frequently saw months pass between discovery and a fix, even after a vulnerability had been found.
97 findings across 48 projects
Anthropic asked the penetration testers who review its coordinated disclosures to assess 97 critical- and high-severity findings from an early version of OSS Scanner across 48 projects:
- 85 findings, 88%: met the bar for its coordinated vulnerability disclosure process.
- 11 findings: were real issues but duplicated known problems or other scanner findings.
- 1 finding: was invalid, a false positive.
Maintainer feedback published in the same research post adds another concrete result: wolfSSL reported that 72 of 74 reports were valid, and five became CVEs. PostgreSQL reported usable patches and fixes completed before issues reached a general-availability release.
Some maintainers also reported inflated severity ratings and findings that misunderstood their project's threat model.
Project configuration
Core maintainers enroll through a pull request to the OSS Scanner repository, adding projects/<name>/project.yaml. Admission is case-by-case for established projects with critical infrastructure or user-security impact, and Anthropic manually verifies core-maintainer status.
The configuration specifies three required inputs:
repo: the Git repository to clone, optionally with a#branch. Hosting on GitHub is unnecessary.primary_contact: the email address that receives reports and other communication.Dockerfile: a repository-relative path to the build environment. Alternatively, a Dockerfile can sit alongsideproject.yaml, with the field omitted.
The Docker build has network access to install dependencies and compile the project. Scanning then runs without internet access inside hardened sandboxes; tools/validate.py checks the configuration before submission, and Anthropic emails maintainers if its build fails.
Optional fields control delivery and scanner behavior:
auto_ccs: additional report recipients.homepage: the project's homepage.threat_model: a repository-relative guidance file, defaulting to.oss-scanner/threat_model.md, or athreat_model.mdbeside the project configuration.pgp: a GPG public key for encrypted report emails. Encryption permits delivery only to the primary contact, without additional CC recipients.disabled: a switch to pause reports and re-enable them later.
The threat-model file has no prescribed format. It can describe:
- Code in scope, adversarial inputs and exclusions.
- A severity rubric.
- Report format, useful proofs of concept and whether patches should be minimal demonstrations or merge-ready changes.
- Deduplication granularity.
Maintainers can change that file between scans. Without it, the scanner makes its own assumptions about corner cases.
Critical Infrastructure Defense Program
The companion program supplies models and engineers through the providers that already secure operational technology: security vendors, system integrators and equipment manufacturers. These environments often cannot be taken offline for patching, and changes to proprietary controllers or industrial networks can interrupt a running plant.
Anthropic names 11 founding partners in its launch announcement:
- Accenture
- Booz Allen
- CrowdStrike
- Deloitte
- Dragos
- Hitachi
- Insane Cyber
- Nozomi Networks
- Palo Alto Networks
- PwC
- Rockwell Automation
Several partners are already using Claude to fix vulnerabilities and help customers do the same. A separate government cyber-defense program, launched in June, has offered models and technical support to more than half of US states and some of the country's largest public critical-infrastructure operators.
Defender access tiers
Two days before the Cyber Mission launch, Anthropic expanded its Cyber Verification Program and integrated Project Glasswing into it. Every tier includes access to Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1, with different permitted capabilities and verification requirements:
- Defense Access: incident response, malware reverse engineering, and vulnerability analysis and validation. Eligible applicants include open-source maintainers and individual researchers with a record of reported vulnerabilities.
- Red Team Access: adds authorized penetration testing and red-teaming for organizations. Ransomware, physical damage and testing high-risk safety systems remain blocked; individual researchers are ineligible.
- Specialized Access: permits testing safety-sensitive systems such as power grids, flight systems and interbank-transfer infrastructure. Anthropic reviews organizations with the US government; existing Glasswing members transition without reapproval for current models.
Disclosure clocks
Unvalidated OSS Scanner findings carry no automatic 90-day disclosure deadline under the service's disclosure policy. If Anthropic subsequently validates a report through its human-reviewed disclosure program, the 90-day clock starts when the maintainer is notified of that validation.
Anthropic may introduce deadlines for some high-severity scanner reports later, with advance notice and an opt-out. Leaving OSS Scanner restores delivery solely through its standard human-reviewed disclosure process.