CTA keyword: SCAN · from the @compedge.ai x @am_roshh carousel
On 8 Oct 2026 Anthropic launched OSS Scanner: an opt-in service that runs periodic AI security scans on open-source projects at no cost. The catch: reports come straight from the model, with no human review, so some will be wrong. Below: the who-qualifies test, the 4 sign-up steps with a filled-in config, a threat-model starter, and a checklist for triaging a model-generated report before you act on it.
What Anthropic announced
- What it is. OSS Scanner is an opt-in vulnerability scanner for open-source code. Projects that join get "thorough, periodic security scans" by Anthropic's strongest models, including Claude Mythos, at no cost. (Anthropic Frontier Red Team, 8 Oct 2026)
- No human in the loop. Anthropic says the outputs are "fully model-generated, without human review or triage", so reports may be incorrect or invalid. (Anthropic)
- What a report contains. A self-contained reproducer, an explanation of the bug (with a bisection to when it was introduced, where possible) and a candidate patch when one is available. Reports arrive by email. (Anthropic)
- Why now, in Anthropic's own numbers. Anthropic says it found over 29,000 candidate vulnerabilities in six months of scanning but could manually review and triage only about 6,000, and that it has sent nearly 5,000 unverified reports to maintainers who asked for everything. OSS Scanner is the opt-in fast track for that unreviewed stream. (Anthropic's figures, not independently checked)
- The old route stays. Human-verified reports keep going out through Anthropic's coordinated vulnerability disclosure (CVD) process. (Anthropic)
- How it runs. Your Dockerfile build has network access; the security audit after it runs with no internet access, inside a sandbox. (Anthropic's FAQ and the oss-scanner repo README)
Everything below the line is CompEdge's own guidance unless it says "per Anthropic".
1. Do you qualify? The 2-minute test
Anthropic uses criteria modelled on Google's OSS-Fuzz: established projects with a "critical impact on infrastructure and user security", decided case by case. OSS-Fuzz names two things it weighs: exposure to remote attacks (for example, libraries that process untrusted input) and how many users and other projects depend on it.
WHO-QUALIFIES TEST
(answer yes / no)
[ ] Established: real releases,
real users, still maintained
[ ] Touches untrusted input:
parses files, network data,
URLs, user uploads, auth
[ ] Others depend on it:
a library or tool that other
projects or companies ship
[ ] You are a CORE maintainer
(Anthropic checks this by
hand before enrolling)
[ ] You can already keep up with
verified high/critical bug
reports (per Anthropic, the
service is built for teams
that can)
4-5 yes -> apply
3 yes -> apply, and write one
sentence on why the
project matters
0-2 yes -> not this service yet;
see section 6
Tip: Anthropic asks for a short sentence explaining your project's importance when it is not self-evident. Name the users or projects that depend on you.
2. The 4 sign-up steps
Per Anthropic's FAQ and the repo README at github.com/anthropics/oss-scanner.
- Copy the template. Start from
templates/project.yamlin the repo and createprojects/<your-project>/project.yaml. - Write a Dockerfile that builds offline. It must install every dependency and build the project, because the audit afterwards runs with no internet. Keep it in your own repo (recommended, e.g.
.oss-scanner/Dockerfile) or next to your project.yaml. Check your tests pass inside the built image. - Validate locally. Run
tools/validate.pyto check the config, andtools/check <name>to build the project the way the scanner will and open a shell with no network. - Open the PR. Anthropic manually validates that you are a core maintainer before enrolling, and may contact the project another way to confirm. Signing up means agreeing to the OSS Scanner terms at red.anthropic.com/oss-scanner/terms.
A filled-in project.yaml
# projects/acme-parser/project.yaml
repo: https://github.com/acme/acme-parser#main
primary_contact: security@acme.dev
auto_ccs:
- lead-maintainer@acme.dev
homepage: https://acme.dev
dockerfile: .oss-scanner/Dockerfile
threat_model: .oss-scanner/threat_model.md
disabled: false
Required: repo and primary_contact, plus dockerfile unless the Dockerfile sits next to project.yaml. Watch out: the repo README says the email addresses in project.yaml are public. Use a security alias, not a personal inbox. If you add a pgp key, reports are encrypted and go to primary_contact only (no CCs).
3. Threat-model starter (optional, strongly recommended)
Without a threat model the scanner guesses what matters. The README says the most useful part is how you rate severity. Copy this to .oss-scanner/threat_model.md and edit:
# Threat model: <project>
WHAT IT DOES
One paragraph.
UNTRUSTED INPUT ENTERS AT
- <file parser / HTTP handler
/ CLI args / config files>
IN SCOPE
- <modules that matter>
OUT OF SCOPE (ignore)
- <tests, examples, dev tools,
deprecated modules>
SEVERITY RUBRIC
critical: unauthenticated remote
code execution, auth bypass
high: memory corruption reachable
from untrusted input
medium: DoS needing unusual input
low: needs local access or a
non-default config
REPORTS
- One bug per report
- Patches: minimal fix, no
refactors
- Include the exact input that
triggers it
You can edit this file between scans to change how reports look.
4. How to triage a model-generated report
Anthropic is clear that these reports get no human review before they reach you. Treat each one as a lead, not a verdict.
TRIAGE CHECKLIST (per report)
[ ] 1. RUN THE REPRODUCER
in a throwaway container.
No crash, no leak = park it.
[ ] 2. CHECK THE THREAT MODEL
Is the input really
attacker-controlled in a
normal deployment?
[ ] 3. RE-RATE SEVERITY YOURSELF
Model ratings can be
inflated. Use your rubric.
[ ] 4. DEDUPE
Known issue? Same root
cause as another report?
[ ] 5. REVIEW THE PATCH LIKE A
STRANGER'S PR
Fixes the root cause? Tests?
Side effects? Never merge
as-is because "the AI
wrote a patch".
[ ] 6. FIX, THEN CREDIT
Anthropic asks (optional)
for the report ID in the
commit message.
[ ] 7. REPLY WITH FEEDBACK
Wrong reports help too:
reply to the email.
Severity reality check: Anthropic itself says some maintainers told it severity ratings can be inflated, or that the scanner misunderstood the project's threat model. Rule 3 exists for that.
5. The fine print before you enrol
- No 90-day clock on these findings. Per Anthropic, it will not place a coordinated-disclosure deadline on unvalidated findings and will not make them public. If a human later validates one through its CVD program, that report may be disclosed 90 days after you are told.
- Pause or leave any time. Add
disabled: trueby PR to pause, or delete yourprojects/<name>/directory to leave. You then go back to the standard CVD route only. - Volume. Anthropic warns many projects are already overwhelmed by reports. If yours is, wait.
- Feedback channel. Not enrolled and have a question: oss-scanner-questions@anthropic.com (per Anthropic, a human reads it).
6. Not eligible yet? Other routes
- Google OSS-Fuzz: continuous fuzzing for critical open-source projects, the program OSS Scanner's criteria are modelled on.
- GitHub's built-in tools: private vulnerability reporting and a SECURITY.md so researchers know where to send bugs.
- Any AI code reviewer or scanner you already use: the triage checklist in section 4 applies to every AI-made report, whoever made it.
Your sign-up sheet
PROJECT: ____________
QUALIFIES (x/5): ____
CORE MAINTAINER: [ ]
SECURITY ALIAS: ____________
DOCKERFILE BUILDS
OFFLINE: [ ]
TESTS PASS IN IMAGE:[ ]
THREAT MODEL: [ ]
validate.py PASSED: [ ]
PR OPENED: ____ (date)
TRIAGE OWNER: ____________
Sources
- Anthropic Frontier Red Team, "Launching an opt-in vulnerability-finding service for open-source software", 8 Oct 2026: https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source
- Anthropic, OSS Scanner FAQ: https://red.anthropic.com/oss-scanner/
- OSS Scanner repo README and project template: https://github.com/anthropics/oss-scanner
- OSS-Fuzz: https://google.github.io/oss-fuzz/
The "What Anthropic announced" section and the facts marked "per Anthropic" reflect Anthropic's pages as read on 9 Oct 2026. The test, the threat-model starter, the triage checklist and the sign-up sheet are CompEdge's own. CompEdge is not affiliated with Anthropic.