The model that finds the bugs now works for free. anthropic's oss scanner, out oct 8, flags…
the model that finds the bugs now works for free. anthropic's oss scanner, out oct 8, flags vulnerabilities in open-source projects and claims 29,000 candidates, with only about 6,000 manually reviewed.
the triage burden just moved onto maintainers.
Context
Anthropic's post of October 8, 2026 launches OSS Scanner, an opt-in vulnerability scanner for open-source projects, in which projects that join receive periodic security scans by its strongest models at no cost. It says that over six months it discovered over 29,000 candidate vulnerabilities and has manually reviewed and triaged approximately 6,000 of them.
The post says the scanner's output is fully model-generated without human review, so reports may be incorrect. It says that in an early check, expert penetration testers reviewed 97 critical and high-severity findings across 48 projects and 85 (88%) met the bar for its disclosure process, with only one found invalid. It also says nearly 5,000 reports have already gone directly to maintainers who asked for everything.
The October 8 date, the 29,000 candidates and the roughly 6,000 manually reviewed match Anthropic's post. 'Works for free' matches 'at no cost' for projects that opt in.
'The triage burden just moved onto maintainers' is the author's line. The post supports part of it, since the scanner's reports are not human reviewed and maintainers who asked received unvalidated reports. It also says Anthropic will keep manually disclosing human-verified reports for projects without the resources to triage, and that joining is opt-in.
The numbers are Anthropic's own and were not independently audited in the pages read.
Related work
- Launching an opt-in vulnerability-finding service for open-source software (Anthropic, October 8, 2026) ↗Primary source for the launch, the 29,000 and 6,000 figures and the 88% early check.
- OSS Scanner (Anthropic) ↗Service page for OSS Scanner.
- Anthropic launches free AI security scans for open-source projects (The Verge, October 8, 2026) ↗Independent report on the launch and the models used.
Watch next
- Look for maintainer reports on the accuracy of scanner findings once projects join. Read Anthropic's disclosure dashboard for the current counts.
Sources
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 9 October 2026 at 11:59 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →