← Founder Notes
Archive

The model that finds the bugs now works for free. anthropic's oss scanner, out oct 8, flags…

Yethikrishna ROriginal on Threads

the model that finds the bugs now works for free. anthropic's oss scanner, out oct 8, flags vulnerabilities in open-source projects and claims 29,000 candidates, with only about 6,000 manually reviewed.

the triage burden just moved onto maintainers.

Context

Anthropic's post of October 8, 2026 launches OSS Scanner, an opt-in vulnerability scanner for open-source projects, in which projects that join receive periodic security scans by its strongest models at no cost. It says that over six months it discovered over 29,000 candidate vulnerabilities and has manually reviewed and triaged approximately 6,000 of them.

The post says the scanner's output is fully model-generated without human review, so reports may be incorrect. It says that in an early check, expert penetration testers reviewed 97 critical and high-severity findings across 48 projects and 85 (88%) met the bar for its disclosure process, with only one found invalid. It also says nearly 5,000 reports have already gone directly to maintainers who asked for everything.

How it compares

The October 8 date, the 29,000 candidates and the roughly 6,000 manually reviewed match Anthropic's post. 'Works for free' matches 'at no cost' for projects that opt in.

'The triage burden just moved onto maintainers' is the author's line. The post supports part of it, since the scanner's reports are not human reviewed and maintainers who asked received unvalidated reports. It also says Anthropic will keep manually disclosing human-verified reports for projects without the resources to triage, and that joining is opt-in.

The numbers are Anthropic's own and were not independently audited in the pages read.

Related work

Watch next

  • Look for maintainer reports on the accuracy of scanner findings once projects join. Read Anthropic's disclosure dashboard for the current counts.

Sources

  1. Launching an opt-in vulnerability-finding service for open-source software (Anthropic, October 8, 2026)anthropic.com
  2. OSS Scanner (Anthropic)red.anthropic.com
  3. Anthropic launches free AI security scans for open-source projects (The Verge, October 8, 2026)theverge.com

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 9 October 2026 at 11:59 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/the-model-that-finds-the-bugs-now-works-DeQ3ijejmH4" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="The model that finds the bugs now works for free. anthropic's oss scanner, out oct 8, flags…"></iframe>

More notes