Anthropic has launched a free scanner for open-source software as part of a broader Cyber Mission security program. Maintainers of projects important to infrastructure or user safety can apply through GitHub to have their code checked regularly.

The service uses AI to flag possible vulnerabilities, explain why they matter and propose patches. That could help projects maintained by small volunteer teams, which often support widely used commercial systems without having equivalent security resources. Anthropic says it expects accuracy above 90 percent.

That figure is a company expectation rather than an independently verified result, and each report reaches maintainers without prior human review. False positives, incomplete fixes and missed vulnerabilities therefore remain practical risks. Maintainers will still need to reproduce findings, inspect suggested changes and run their normal tests before merging a patch.

The accompanying Critical Infrastructure Defense Program gives operators of power grids, water systems and transport networks access to Claude models, Anthropic engineers and threat analysis. CrowdStrike, Palo Alto Networks, Deloitte and Rockwell Automation are founding partners.

The open-source scanner has the more direct public entry point, but it is opt-in rather than a universal audit of public repositories. Its value will depend on which projects qualify, how quickly maintainers can validate reports and whether the system can keep a low enough false-alarm rate to avoid adding work to already constrained teams.