Anthropic is running security scans on open-source projects for free. That’s genuinely useful, and the timing makes sense given how many critical infrastructure projects run on volunteer-maintained code with zero security budget.
As reported by Engadget, the company has introduced OSS Scanner, a free opt-in tool that runs periodic vulnerability scans on open-source codebases using its most capable models, including Claude Mythos. The pitch is straightforward: projects sign up, Anthropic scans them regularly, and developers get early warnings about potential security issues at no cost.
There is a tradeoff, and Anthropic is upfront about it. The scan outputs are fully model-generated with no human review or triage. That means false positives are possible. For a security tool, that matters. A developer chasing a phantom vulnerability wastes time. But for projects that currently have no automated scanning at all, even an imperfect signal is better than silence.
This sits alongside Claude Security, Anthropic’s paid product for general code scanning and patching. OSS Scanner is the free, narrower sibling aimed specifically at the open-source community. The inspiration, according to Anthropic, is Google’s OSS-Fuzz, a project the search giant has run with the Open Source Security Foundation since 2016 and which has found thousands of real bugs in widely used software.
So why are two well-funded AI companies spending resources to protect free software? Self-interest plays a big role here. Google and Anthropic both depend heavily on open-source projects that form the backbone of the modern internet, and many of those projects are maintained by small teams or single developers working without pay. A vulnerability in that layer is a vulnerability everywhere. The XZ Utils backdoor from 2024 is the clearest recent example: a supply chain attack buried in a compression library used across Linux systems that could have given attackers remote access to millions of machines worldwide.
AI models have already proven effective at finding security flaws. Anthropic’s move to point that capability at open-source code is a reasonable use of the technology, and free access removes the main barrier for under-resourced maintainers.
- Scans are run periodically using Anthropic’s strongest models, including Claude Mythos
- Reports are fully AI-generated with no human review
- The service is opt-in and available at no cost
- It complements, but does not replace, Anthropic’s paid Claude Security product
For developers maintaining open-source libraries, this is worth a look. The lack of human review limits how much you should trust any single report, but regular automated scanning that flags potential issues early still has real value. And given that the alternative for most of these projects is nothing, the bar for “worth it” is not especially high.



