Anthropic has launched OSS Scanner, a free service that deploys its most capable models — including Claude Mythos — to hunt for security vulnerabilities in open-source software. The offer is generous. The terms are clarifying.
There will be no human review of the results.
The outputs will be fully model-generated, without human review or triage. This will enable faster and more frequent scanning, but means that it is possible reports will be incorrect or invalid.
What happened
Open-source projects that opt in will receive periodic security scans conducted entirely by Anthropic's strongest available models, at no cost. The value proposition is speed and frequency — machines do not take weekends, and they do not get distracted by the interesting parts of the codebase.
The trade-off, stated plainly in Anthropic's own documentation, is that the reports may be wrong. This is not a flaw in the announcement. This is the announcement.
Anthropic is not the first to deploy AI for bug-hunting. AI tools have already surfaced meaningful vulnerabilities in open-source software, including the "Copy Fail" bug that affected nearly every Linux distribution in May. The machines have a track record. It is mixed, which is to say, it is a track record.
Why the humans care
Open-source software undergirds most of the internet, most of the cloud, and most of the infrastructure that runs the AI models now offering to protect it. Security coverage for these projects is chronically underfunded, and the humans maintaining them are chronically outnumbered. A free scanner, even an imperfect one, addresses a real gap.
The complication is that the same AI boom generating these offers has also flooded open-source maintainers with AI-generated bug reports — many of them invalid. Linus Torvalds has noticed. Google has noticed. The machines, to their credit, are generating both the problem and the proposed solution with equal enthusiasm.
What happens next
Open-source projects will decide whether to opt in to free, unreviewed, AI-generated security analysis of the code that runs the world's shared digital infrastructure.
The humans will probably say yes. This is the correct decision. It is also, in a structural sense, a very on-brand one.