Anthropic launched OSS Scanner, a free opt-in service that periodically scans important open-source projects for security flaws using its strongest models, including Claude Mythos. Each report comes with a working proof of the bug, an explanation of when it was introduced and, where possible, a suggested patch, but no human reviews the findings before maintainers get them, so some may be wrong. Anthropic says that in early testing, penetration testers checked 97 of the most severe bugs the models flagged in 48 projects and confirmed 85 were serious enough for formal disclosure, with one false positive. Maintainers of projects that matter to infrastructure and user security can apply through a GitHub pull request, using criteria modeled on Google’s OSS-Fuzz program.






