Anthropic is offering free AI security scans for open-source projects, but there’s a catch

Anthropic’s new free security scanner for open-source software sounds generous. It probably is, at least partly. But it also tells you a lot about how dependent AI companies have become on the unpaid labor that keeps the internet running.

The company announced its OSS Scanner this week, a tool that gives open-source projects free, periodic vulnerability scans using what Anthropic calls its “strongest models,” including Claude Mythos. The pitch is straightforward: maintainers of open-source projects sign up, and the scanner checks their code for security issues at no cost. Early alerts, zero dollars.

So what’s the tradeoff? Anthropic is upfront about one significant limitation. “The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage,” the company says. That means the reports could be wrong. Developers could receive false positives, chase phantom bugs, or miss the ones that actually matter. Faster and more frequent scans are real benefits, but acting on bad AI output carries its own risk.

The tool is modeled on OSS-Fuzz, the open-source scanner Google built with the Open Source Security Foundation back in 2016. Anthropic already sells a paid product called Claude Security for general code scanning and patching. OSS Scanner is essentially a free version of that concept, targeted specifically at open-source maintainers who can’t afford enterprise security tooling.

Why does this matter? Consider the XZ Utils backdoor discovered in 2024. A malicious actor spent nearly two years quietly infiltrating a widely used compression library, getting close to handing attackers administrative access to millions of Linux systems globally. That project, like countless others, was maintained by a small number of volunteers with no dedicated security budget. One well-placed vulnerability in foundational open-source code can have consequences that ripple across the entire internet.

This is the bigger picture. Anthropic, Google, and most major tech companies build their products on top of open-source infrastructure that is chronically under-resourced. Offering free security tooling is a practical fix for a structural problem these companies have a direct interest in solving. That doesn’t make the tool useless. It makes the motivation clearer.

For privacy-conscious developers, there are also questions worth asking before opting in:

  • What data from your codebase does the scanner process, and where does it go?
  • Are scan results stored, and for how long?
  • Could vulnerability reports be used to train future models?
  • What are the terms if Anthropic changes the program later?

Anthropic hasn’t published detailed answers to those questions publicly yet. For a tool running on open-source code that communities have trusted for years, that’s the kind of transparency that should come with the offer, not after signup.