Editorial illustration for Anthropic Launches Free AI Scanner for Open-Source Projects
Anthropic Releases Free Security Scanner for Open Source
Anthropic is giving away a security tool it built for its own AI models, and open-source maintainers can now use it to find bugs before attackers do. The company announced Cyber Mission this week, a program aimed at protecting critical infrastructure and open-source software from cyberattacks. One piece of it, the Critical Infrastructure Defense Program, gives operators of power grids, water systems, and transportation networks access to Claude models, Anthropic engineers, and threat analysis. CrowdStrike, Palo Alto Networks, Deloitte, and Rockwell Automation have signed on as founding partners.
The other piece is smaller in scope but potentially wider in reach: a free scanner called "OSS" that checks open-source code on a regular basis, flags vulnerabilities, explains what's wrong, and suggests fixes. That matters because nearly all modern software leans on open-source components, many of them kept running by volunteers with little time or budget for security audits. Anthropic says the tool's accuracy should exceed 90 percent, though it's quick to note that reports go out without human review and can contain mistakes. Maintainers of projects tied to infrastructure or user safety can sign up through GitHub.
Separately, a free "OSS" AI scanner will regularly check open-source projects, automatically flag and explain vulnerabilities, and suggest patches. Nearly all modern software depends on open-source code, much of it maintained by small volunteer teams.
Why this matters
Open-source maintainers have never had the staffing or budget to chase down every vulnerability in their dependency trees, which is exactly why incidents like Log4Shell linger for years after discovery. Anthropic handing out a free scanner that flags and explains bugs, then suggests patches, could actually move the needle for the thousands of under-resourced projects that power everything from web frameworks to industrial control systems. We're less interested in the headline tool than in the company it's keeping: CrowdStrike, Palo Alto Networks, Deloitte, and Rockwell Automation don't sign on to PR stunts, they sign on when there's infrastructure money and liability at stake.
For developers, the practical question is whether the scanner's suggestions hold up under real-world load without flooding maintainers with false positives, a problem that's killed similar tools before. For founders building on open-source stacks, this is worth testing early rather than waiting for a CVE to force the issue. Watch whether Anthropic publishes concrete vulnerability counts once the scanner's been running for a few months.
Common Questions Answered
What is the free AI scanner that Anthropic launched for open-source projects?
Anthropic launched a free OSS AI scanner that automatically checks open-source projects for vulnerabilities, flags them, explains the issues, and suggests patches. This tool was built from security technology Anthropic developed for its own AI models and is now being made available to the open-source community at no cost.
How does the Critical Infrastructure Defense Program differ from the OSS scanner?
The Critical Infrastructure Defense Program is a separate component of Anthropic's Cyber Mission that provides operators of power grids, water systems, and transportation networks with direct access to Claude models, Anthropic engineers, and threat analysis services. In contrast, the OSS scanner is an automated tool designed specifically for open-source project maintainers to independently identify and fix vulnerabilities in their code.
Why is Anthropic's free scanner significant for open-source maintainers?
Open-source maintainers typically lack the staffing and budget to thoroughly audit their dependency trees for vulnerabilities, which allows security issues like Log4Shell to persist for years after discovery. By providing a free scanner that automatically flags, explains, and suggests patches for bugs, Anthropic can help the thousands of under-resourced open-source projects that power critical software infrastructure protect themselves from cyberattacks.
What is Anthropic's Cyber Mission program?
Cyber Mission is Anthropic's comprehensive program aimed at protecting critical infrastructure and open-source software from cyberattacks. It includes multiple initiatives such as the Critical Infrastructure Defense Program for power grids and transportation networks, as well as the free OSS AI scanner for open-source project maintainers.
Further Reading
- Introducing the Anthropic Cyber Mission - Anthropic
- Launching an opt-in vulnerability-finding service for open-source software - Anthropic
- AI company moves to defend critical infrastructure and open-source projects from AI - The Register
- Anthropic launches critical infrastructure program and free OSS Scanner for open source - SiliconANGLE
- Project Glasswing: An initial update - Anthropic