Back in April, there was a bit of commotion in the cybersecurity space when Anthropic, the company behind Claude, unveiled one of its most advanced AI models, Claude Mythos Preview.
Anthropic said the model could surpass all but the most skilled humans at finding and exploiting software vulnerabilities. It held the model back from the public and made it available only to select partners under Project Glasswing.
Even US financial officials took notice: the Treasury Secretary and the Federal Reserve Chair convened major bank CEOs to warn about the model’s cyber risks, especially in the wrong hands.
But Anthropic is now trying to put similar capabilities to defensive use, and it’s giving some of that capability away for free.
The company just launched OSS Scanner, a free vulnerability-scanning service for open-source projects. It uses Anthropic’s strongest models, including Claude Mythos, to find security flaws and generate bug reports.

Why Anthropic is doing this
AI models have become far better at finding vulnerabilities. On CyberGym, an academic benchmark, large language models went from finding fewer than 20% of vulnerabilities at the beginning of last year to more than 85% this year, according to Anthropic.
That capability is useful for defenders. It’s also useful for attackers. Anthropic knows this, so it’s trying to get ahead of the problem by putting strong tools in defenders’ hands.
OSS Scanner is part of a broader effort called the Anthropic Cyber Mission. It also includes the Critical Infrastructure Defense Program, which brings frontier Claude models, on-site engineers, and threat research to the security providers that protect power grids, water systems, and transportation networks.
How OSS Scanner works
OSS Scanner is opt-in. Core maintainers of eligible projects submit a pull request to a GitHub repository Anthropic set up. Eligibility follows criteria similar to those of Google’s OSS-Fuzz, chiefly that a project has “critical impact on infrastructure and user security.”
The output is fully model-generated, with no human review or triage. Each report includes a self-contained reproducer, an explanation of the vulnerability (including when the bug was introduced, where possible), and a candidate patch when available.
Anthropic says this allows faster and more frequent scans, but some reports may be incorrect or invalid. For projects without the resources to triage reports themselves, the company will keep sending human-verified reports through its existing coordinated disclosure process.
Early results of the scanner
Anthropic says it spent several weeks validating the pipeline with dozens of open-source projects. The first disclosures contained hundreds of bug reports, including multiple vulnerabilities that could be chained into unauthenticated remote code execution exploits.
Subscribe for free to continue reading this article
Subscribe SubscribeAlready have an account? Log in
