Physix Frontier · News Briefing Card (IT Home · Oct 9, 2026)

Anthropic Launches Free OSS Scanner for Open-Source Flaws

KEY FACTS

  • Anthropic launched OSS Scanner, an open-source software vulnerability detection service, on October 8.
  • The project is regularly scanned for free by AI models such as Claude Mythos, and results are generated fully automatically.
  • Maintainers must submit a PR to the OSS Scanner GitHub repository to apply for access.
  • Over the past six months, it flagged more than 29,000 candidate vulnerabilities, but only about 6,000 completed human review.
  • In a real-world test of 48 projects, it found 97 high-severity vulnerabilities, 85 of which met the disclosure threshold, with only 1 false positive.

KEY DATA

29,000Total candidate vulnerabilities
about 6,000Vulnerabilities human-reviewed
48Projects tested
97High-severity vulnerabilities detected

PHYSIX OBSERVATION

The false positive rate of AI automated vulnerability scanning is as low as 1%, showing that large models already have practical value in code security. But of 29,000 findings, only 6,000 completed human triage, meaning the bottleneck has shifted from discovery to verification. Most open-source maintainers work unpaid, so free scanning is a good thing, but the follow-up remediation and disclosure pressure still falls on them. Anthropic is trading a free service for ecosystem trust, and this move is worth watching.

Source: IT Home report