⚡ Uncle Cat AI Radar
SafetyAgentsIndustry

Anthropic Puts Mythos 5 Behind Enterprise Code Scans

Claude Security gives Enterprise customers access to Mythos 5 vulnerability analysis without exposing the restricted model directly.

Restricted capability through a controlled product

Anthropic has moved Claude Security’s repository scans to Claude Mythos 5. Claude Security remains in public beta for Claude Enterprise customers, and Anthropic’s current product guidance says Mythos 5 scans are available to all Enterprise customers. Administrators can enable the service in the admin console, after which users can select a GitHub repository for analysis. The system follows data and control flow across files, reports suspected vulnerabilities with supporting evidence, and prepares proposed fixes that can be opened in Claude Code on the web.

The release does not give Enterprise customers unrestricted access to Mythos 5. Anthropic is instead placing the model behind a narrowly defined security workflow, where inputs, outputs and permitted actions can be controlled. Customers may continue using the models otherwise available to their organization when reviewing or implementing the suggested patches.

Anthropic also offers a Claude Security plugin in beta to Claude Code users, but that plugin uses the models available in each user’s Claude Code account. Mythos 5-powered scans remain confined to the Claude Security application on Claude.ai for Enterprise customers, so the two access routes should not be treated as equivalent.

Mythos 5 was introduced earlier as Anthropic’s most capable cybersecurity and biology model. It shares its underlying model with Claude Fable 5 but has fewer restrictions for approved work in sensitive domains. Direct access has consequently been limited to approved partners and trusted-access programs. Claude Security creates a broader delivery route for its defensive capabilities without making the underlying model generally callable.

Anthropic said the integration is one of several steps intended to expand access for defenders and that it is working with security partners on additional product integrations. Findings still require human validation: automated scanners can misjudge exploitability, overlook deployment context or recommend a patch that creates a different failure.

Why it matters

This is a notable model-access pattern for increasingly capable systems. Rather than choosing only between a fully public API and a small trusted-user roster, a laboratory can expose sensitive capability through a constrained application with logging, fixed tools and limited outputs.

If the approach works, it could become a template for distributing models with strong cyber, biological or other dual-use abilities. It may also shift enterprise security competition away from generic coding assistants toward systems that can reason across whole repositories. The central test will be whether Mythos materially improves the discovery of consequential, previously unknown flaws without producing an unmanageable volume of false positives.

Sources