Post #3162633
2026-04-17 18:09 UTC
RE: https://infosec.exchange/@david_chisnall/116419479557680376
Key point of this for me
> But the most relevant part is that it contained three critical command-injection vulnerabilities.
>
> These are the kind of things that static analysis should be catching. And, apparently at least one of the following is true:
>
> Mythos didn't catch them.Mythos doesn't work well enough for Anthropic to bother using it on their own code.Mythos did catch them but the false-positive rate is so high that no one was able to find the important bugs in the flood of useless ones.
Replies (0)
No replies.