Anthropic released the OSS AI scanner on October 9, 2026, saying it will automatically flag and explain vulnerabilities in open-source projects. It is the company's first software update since its launch in 2022.
Anthropic reported accuracy above 90 percent, measured on vulnerability detection in open-source projects. That compares with no prior figure provided by the source.
The OSS scanner is built on Claude models and targets open-source projects critical to infrastructure or user safety. Availability begins via GitHub, initially for project maintainers.
"Nearly all modern software depends on open-source code, much of it maintained by small volunteer teams," said Manuel Uth, the article's author. The company argues attackers already have powerful AI models, while defenders still lack comparable tools.
The announcement follows the launch of Cyber Mission, a long-term program to protect critical infrastructure and open-source software from cyberattacks. The source itself frames the significance as a step toward improving security in open-source ecosystems.
Anthropic did not say how the scanner will handle false positives, and the tool may contain errors due to lack of human review. The company said maintainers can opt in via GitHub.
Source: thedecoder