cURL creator Daniel Stenberg called Anthropic's Mythos AI bug-hunting model “an amazingly successful marketing stunt” after the model was run against cURL's codebase and found just one low-severity vulnerability, despite Anthropic claiming the tool was too powerful to release publicly. Of the five findings Mythos initially flagged as “confirmed security vulnerabilities,” Stenberg and his security team determined that three were false positives already noted in API documentation, one was just a simple bug, and only one was an actual low-severity vulnerability. Stenberg noted that AI code analyzers like AISLE, Zeropath, and OpenAI Codex Security have triggered between two and three hundred bug fixes in cURL over the past 8-10 months, adding that Mythos “is not better [than other tools] to a degree that seems to make a significant dent in code analyzing.” Stenberg accessed the report through Anthropic's Project Glasswing program, which gives high-profile open source projects access via the Linux Foundation, though he noted he never actually received direct access to the model himself.






