For Mythos, for example, Anthropic doesn't tell us the number of false positives their tool returns, i.e. the number of times their tool says that something is a vulnerability and it ends up not being. My security expert collaborators tell me that this is one of the most important metrics by which security tools are judged, because it tells you the difference between a useful tool and a useless one that engineers won't use.