Open-source maintainers will start getting vulnerability reports from Anthropic that were written by AI, and no person at the company will look at them before they are sent. Anthropic says it expects the reports to be more than 90 percent accurate, but it also admits they may contain errors.
A free scanner that skips human review
The service is a free “OSS” AI scanner. It will check open-source projects on a regular schedule, flag vulnerabilities automatically, explain each finding and propose patches.
The stakes are high because almost all modern software is built on open-source code, and a large share of that code is looked after by small volunteer teams with no security department to back them up.
Those same small teams are where the trouble lies. If a scanner gets things wrong almost 10 percent of the time, a project run by two people still has to separate the real flaws from the false alarms. The scanning costs nothing, but maintainers still pay for it in the time they spend checking each report.
Who can use it
Maintainers have to opt in. Projects that are critical to infrastructure or user safety can sign up through GitHub, and Anthropic has not made the scanner available to every repository.
Anthropic frames the launch as a question of who has the tools. The company said attackers already have powerful AI models, while defenders still don’t have anything comparable.
The bigger program behind it
The scanner is not part of Cyber Mission, Anthropic’s long-term program to protect critical infrastructure and open-source software from cyberattacks.
Cyber Mission includes the Critical Infrastructure Defense Program, or CIDP. It gives operators of power grids, water systems and transportation networks access to Claude models, Anthropic engineers and threat analysis.
Its founding partners are CrowdStrike, Palo Alto Networks, Deloitte and Rockwell Automation. That lineup of two security vendors, a consulting firm and an industrial automation company suggests the program is built for large utility operators rather than hobby projects.
What maintainers should do
If infrastructure or user safety depends on a project you maintain, signing up through GitHub is free. Treat the first reports the way you would treat a pull request from someone you don’t know. Reproduce every flaw yourself before you merge any suggested patch, because no one at Anthropic will have checked it before it reached you.

























STAY ALWAYS UP TO DATE