Anthropic launches free AI vulnerability scanner for open-source projects
Anthropic's new Cyber Mission program offers a free AI scanner that checks open-source code for vulnerabilities with over 90 percent expected accuracy, plus security partnerships for grids and water systems.

Updated
Why it matters
- Anthropic launched "Cyber Mission," a cybersecurity program including a free AI scanner for open-source projects.
- The AI scanner is expected to detect vulnerabilities with accuracy above 90 percent, according to The Decoder.
- Partners CrowdStrike and Palo Alto Networks will help secure power grids and water systems against cyberattacks.
- The program targets both open-source software security and critical infrastructure defense.
Anthropic has launched "Cyber Mission," a program that includes a free AI scanner which the company says will automatically check open-source projects for vulnerabilities with an expected accuracy above 90 percent.
The program, announced on November 12, 2025, according to The Decoder, goes beyond code scanning. Anthropic has enlisted partners including CrowdStrike and Palo Alto Networks to help secure critical infrastructure such as power grids and water systems against cyberattacks.
The announcement positions Anthropic — best known for its Claude family of language models and its stated focus on AI safety — as a direct participant in defensive cybersecurity, not just a supplier of general-purpose AI tools. The move comes as open-source software, which underpins most of the modern internet and enterprise stack, faces mounting scrutiny over vulnerabilities that attackers can exploit at scale.
What does the free scanner actually do?
According to The Decoder's report, the core offering is straightforward: a free AI-powered scanner that automatically checks open-source projects for vulnerabilities. Anthropic expects the tool to achieve accuracy above 90 percent.
For maintainers of open-source projects, the price point matters as much as the accuracy figure. Commercial vulnerability scanning and security auditing tools typically carry subscription costs that volunteer-maintained projects struggle to justify. A free scanner from a well-funded AI lab lowers that barrier.
The stakes are real. Open-source components run in everything from web servers to embedded devices, and a single unpatched vulnerability in a widely used library can cascade across thousands of downstream systems. High-profile episodes such as exploited flaws in widely distributed open-source packages have made vulnerability detection in this ecosystem a priority for both industry and governments.
An accuracy rate above 90 percent, if it holds in practice, would put the tool in competitive territory — though Anthropic has not yet published detailed benchmark data, false-positive rates, or third-party evaluations alongside the announcement. Independent testing will determine whether the figure reflects real-world performance across diverse codebases or performance on curated test sets.
Who are Anthropic's partners in the program?
The Decoder identifies two named partners: CrowdStrike and Palo Alto Networks. Both are established players in enterprise cybersecurity.
Their role, according to the report, is to help secure critical infrastructure — specifically power grids and water systems — against cyberattacks. The report does not detail the precise division of labor between Anthropic and its partners, such as whether CrowdStrike and Palo Alto Networks will integrate Anthropic's models into their own products or co-develop new tooling.
The infrastructure focus gives the program a policy dimension. Power grids and water systems have become recurring targets in state-linked intrusion campaigns, and Western governments have pushed operators to modernize defenses for operational technology that often predates contemporary security practices. An AI vendor volunteering capability for this sector aligns Anthropic with those public priorities.
Why does an AI lab care about infrastructure defense?
The program fits a broader pattern among frontier AI companies: demonstrating that their models deliver concrete defensive value in cybersecurity, a domain where AI assistance has shown measurable results in code analysis, threat detection, and vulnerability research.
For Anthropic specifically, Cyber Mission serves a dual function. It offers a practical security tool to the open-source community, and it bolsters the company's argument that advanced AI is a net defensive asset — a relevant claim in ongoing debates among policymakers about whether the same capabilities could be misused offensively.
The free scanner also functions as distribution. Every open-source maintainer who runs the tool becomes a user of Anthropic's technology, potentially feeding familiarity with its capabilities ahead of enterprise offerings in the same space.
What are the open questions?
The announcement leaves several practical questions unanswered, based on The Decoder's report:
- Accuracy claims: The "above 90 percent" figure is an expectation, not a verified benchmark, and the report does not specify what it measures — precision, recall, or aggregate detection performance.
- Coverage: The report does not list which programming languages, package ecosystems, or vulnerability classes the scanner supports.
- Partner scope: Beyond CrowdStrike and Palo Alto Networks, the report does not name additional participants or the program's funding and duration.
- Deployment model: How critical-infrastructure operators will actually access and deploy the jointly developed protections remains unspecified.
What happens next?
The first test of Cyber Mission will be adoption and verification: whether open-source maintainers integrate the free scanner into their workflows, and whether independent security researchers can reproduce the claimed accuracy on real-world codebases. Success there would give Anthropic a credible foothold in defensive cybersecurity just as competition among AI vendors to prove real-world utility intensifies.
Original: github.com
More from Elena Vasquez
Show full bio
Market editor covering media and advertising at AI In Context.
209 articles
Related articles
- AI Models Keep Cheating on Tests, and Researchers Are Quitting
- OpenAI Launches Aardvark, an Agentic AI Security Researcher
- Security Researchers Used Anthropic's Claude to Hack Into OpenAI
- Anthropic opens Claude to civilian US agencies while Pentagon fight drags on
- One Israeli Startup Sits Behind a String of Rogue AI Disclosures