METAL for iPhone

Read AI news in the METAL app.

Download METAL and discover fresh AI stories every day.

Download on the App Store

For iPhone · Free download

Search for METAL AI Magazine in the App Store on your iPhone.

METAL

AI GlossaryㅋWords you meet while using AI

Claude Mythos 5

A dedicated model used by Anthropic's code security scanner, Claude Security, that traces data flow across files to find vulnerabilities.

In plain words

Claude Mythos 5 is a model Anthropic uses specifically to find security vulnerabilities in code. If a typical grammar checker catches typos sentence by sentence, this model is more like an inspector walking through an entire building with the plumbing blueprints in hand, tracking down which pipe is leaking. Rather than looking at a single file in isolation, it traces how a value that comes from one file gets used in another to find problems.

Mythos 5 only plays the role of finding issues. For each finding, it reports what type of vulnerability it is, how confident it is, how severe it is, and how to fix it — but the actual code fix is handled by another Claude model the organization already uses. And that fix isn't applied automatically either; a human must review and approve it before it lands in the actual code.

In other words, Mythos 5 acts as the detective, while the fixing is split between another model and a human. Currently, it only works on repositories uploaded to GitHub, through Anthropic's security scanning tool.

How it shows up in the news

In articles, it appears in phrasing like "Claude Security started running scans with Mythos 5." A common misconception here is that the model automatically fixes the code. In reality, Mythos 5 only finds vulnerabilities and proposes candidates; the actual code fix is handled by another Claude model the organization uses, and the result still requires human review and approval before being applied.

Try it yourself

Claude Mythos 5 doesn't require a separate application — an organization admin just needs to turn on the security scanning feature. Here's roughly how it works:

  1. An organization admin enables the security scanning feature and web-based coding tools, and grants the GitHub app access to the target repository.
  2. The user selects a connected repository on the security scanning page. The scope can be narrowed to a specific branch or folder if needed.
  3. The model runs a scan in the background, tracing data flow across files.
  4. Once the scan finishes, a list appears showing each finding's type, confidence level, severity rating, and suggested fix.
  5. Selecting an item opens a fix session, and the proposed patch is only applied after a human reviews and approves it.

It can be run regularly to check for data-flow vulnerabilities before new deployments.

See also

Stories using this term

Browse every entry