# anthropics/oss-scanner > Anthropic service that scans critical open-source repositories for vulnerabilities: the project is built in an isolated VM without network access, and a report with a reproducer and patch is emailed. Enrollment happens via a PR with a project.yaml config and Dockerfile. - Magnitude: 6.5 out of 10 — Early signal - Stars: 93 total · +13 stars measured 2026-10-09, 03:36–04:59 UTC, ≈ 80 by evening - Star trust: star growth looks organic - Category: Security · Language: Python · License: Apache-2.0 · Created: 2026-10-08 · Last push: 2026-10-09 - GitHub: https://github.com/anthropics/oss-scanner · Page: https://gitnova.dev/en/r/anthropics/oss-scanner ## Useful for - Enroll an open-source project in the scanner via a PR with project.yaml and a Dockerfile - Verify the project build in an isolated container with tools/check before opening the PR - Write a threat_model.md so the scanner accounts for the project's security priorities ## Why it’s here - Star-counter measurements on 2026-10-09 (UTC), 03:36–04:59: 80 → 93 stars (+13). This is the change over that interval. - Estimated end-of-day forecast: about +80 stars, using observed gains and the previous day. - The repository is 1 day old and already has 93 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet. - Top new repositories this week: #161. - About 188 forks a day — people are taking the code. - Recent forks include notable developers: @Brooooooklyn (5,091 followers), @maliming (3,817 followers), @strickvl (483 followers). ## Star trust Star growth looks organic. Star-trust labels are heuristics based on the repository’s behavior, not a check of every stargazer. ## Numbers - Forks: 69 - Issues and pull requests: 62 - Watchers: 3 - Average over the last week: 87 per day - Usual pace: too little history (under two weeks) - Stars in the last hour (measured): 10 ## Stars per day, last 6 days (oldest → newest, today is partial) 2026-10-04 … 2026-10-09: 0, 0, 0, 0, 93, 13 ## Spotted in now - Top new repositories this week: #161 ## Similar by description 1. **aquasecurity/trivy** — 1.6 · Steady · Security · Go · +4 stars measured 2026-10-09, 00:10–05:06 UTC, ≈ 14 by evening Security scanner that finds vulnerabilities, misconfigurations, secrets and SBOM in containers, Kubernetes, code repositories, clouds and filesystems. Aimed at developers and DevOps for checking artifact security. Full card: https://gitnova.dev/en/r/aquasecurity/trivy.md 2. **NVIDIA/SkillSpector** — 2.5 · Steady · Security · Python · +9 stars measured 2026-10-09, 00:08–05:02 UTC, ≈ 57 by evening Security scanner for AI agent skills: detects vulnerabilities, malicious patterns, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before installation. Full card: https://gitnova.dev/en/r/NVIDIA/SkillSpector.md --- Magnitude (0–10) measures how fast and how unusually interest in a repository is growing right now. It is not a quality score. Days are UTC. “So far today” is a fact; “expected by the end of the day” is a forecast. Summaries and use cases are written by an LLM (DeepSeek V4.1 Flash) from the README and may be inaccurate: verify specific claims (benchmarks, speed, hardware) in the repository itself. Data as of 2026-10-09 05:10 UTC, updated every 30 minutes.