Skip to content

anthropic oss scanner skips human review: 88% of findings held up

Anthropic's OSS Scanner hunting open-source vulnerabilities: an engineer cracks a green crystal as a scan runs big tech

anthropic launched oss scanner on oct 8: open-source projects can enroll to get periodic security scans from its strongest models at no cost. the reports go out without human review, so we read anthropic's numbers to see how far they can be trusted and what a maintainer still has to do.

the reports hold up in anthropic's own tests: 85 of 97 critical and high findings met its bar. the open question is fixing. anthropic's disclosure program has reported 6,157 bugs to maintainers, and 516 are patched upstream so far.

what anthropic launched

oss scanner comes from anthropic's frontier red team and builds on what it learned using claude in project glasswing. a core maintainer enrolls a project with a pull request on github. anthropic builds the project in an isolated vm, scans it offline and emails the findings to the project's contact. each report has a reproducer, an explanation and a candidate patch when one exists.

it is the open-source half of the anthropic cyber mission, announced the same day. the other half, the critical infrastructure defense program, gives security providers for power grids, water systems and transport networks frontier claude models and on-site engineers. anthropic named 11 founding partners, among them crowdstrike, dragos and palo alto networks.

eligibility copies google's oss-fuzz: established projects with a critical impact on infrastructure and user security, judged case by case. anthropic says the service is for projects that can keep up with verified high and critical reports.

what anthropic's numbers show

oss scanner is new, so the larger data set comes from anthropic's disclosure program, which runs alongside it. this is the program's pipeline from nov 1, 2025 to oct 2, 2026:

stagecount
candidate findings from claude models29,439
reviewed by six outside security firms6,123
confirmed valid5,674 (92.7% of reviewed)
reported to maintainers, 591 projects6,157
of those, sent directly by anthropic with no outside review4,824
acknowledged by maintainers5,103
patched upstream516

human review covered about a fifth of the candidates, 6,123 of 29,439. anthropic calls independent review the rate-limiting step of the whole process. oss scanner skips it for projects that opt in.

how accurate the scanner is

in early testing, penetration testers checked 97 critical and high findings across 48 projects. 85 (88%) met anthropic's bar for its disclosure process, 11 were real bugs that were duplicates or already known, and 1 was a false positive. anthropic expects a true-positive rate above 90%.

maintainers quoted by anthropic were positive: wolfssl's maintainer said all but two of 74 reports were valid and five became cves. maintainers also told anthropic that severity ratings can be inflated and that the scanner sometimes misreads a project's threat model.

where the work moves

516 of 6,157 reported bugs are patched, about 8%. anthropic's dashboard calls patches a lagging indicator, because fixes take a long time to write. maintainers have acknowledged 5,103 findings, about 83%.

we think accuracy is the smaller question here: 88% in the scanner test and 92.7% on reviewed findings are close to anthropic's 90% expectation. the unknown is how long a maintainer needs per report and how many end in a patch. oss scanner adds reports that nobody at anthropic has read, and anthropic says it is for projects with capacity to keep up. the first data on that will come from the projects that enroll.

what enrolling takes

a pull request that adds projects/<name>/project.yaml with the repo, one contact address and a dockerfile. the dockerfile builds the project with network access, and the scan then runs offline, so every dependency has to be installed during the build. a threat_model.md is optional and tells the scanner what is in scope. the addresses in project.yaml are public.

anthropic sets no 90-day disclosure period on unvalidated findings and will not publish them. a project pauses reports with disabled: true or leaves by deleting its directory.

sources

ON AIR · RADIO.THEHYPE.NEWS ↗ ai news radio — 24/7