OSS Scanner
Anthropic's free, opt-in service scans eligible open-source projects with Claude and emails maintainers vulnerability reports and proposed patches.
At a Glance
About OSS Scanner
OSS Scanner is a free security scanning service from Anthropic's Frontier Red Team for eligible open-source projects. It uses Claude to find potential vulnerabilities, double-check findings, propose patches, and analyze root causes. Maintainers receive model-generated reports by email, followed by periodic rescans for new or previously missed vulnerabilities. Reports are sent without prior human review.
Core maintainers apply through a pull request to Anthropic's OSS Scanner repository, providing project configuration and a Dockerfile for offline auditing. Acceptance is reviewed case by case, prioritizing established projects with significant impact on infrastructure and user security. Maintainers can supply a threat model, request encrypted reports, or pause participation. Anthropic covers the scanning cost.
Community Discussions
Be the first to start a conversation about OSS Scanner
Share your experience with OSS Scanner, ask questions, or help others learn from your insights.
Pricing
Free OSS Scanning
Free for eligible open-source projects approved by Anthropic. Core-maintainer verification is required; scan frequency varies.
- Initial vulnerability scan and periodic rescans with Claude
- Emailed vulnerability reports without prior human review
- Automated checks, proposed patches, and root cause analysis
- Optional project-specific threat model and encrypted reports
- Ability to pause or end enrollment
Capabilities
Key Features
- Opt-in vulnerability scanning of open-source repositories
- Reports delivered directly from models without prior human review
- Agents that double-check bugs, propose patches, and perform root cause analysis
- Periodic rescans for new and previously missed vulnerabilities
- Optional threat model file to guide the scanner
- PGP-encrypted email reports
- Offline sandboxed scanning using a maintainer-provided Dockerfile
- Enrollment and opt-out via pull request config
