AI ResearchCybersecurity2 min reading time

Breaking Claude Code Opus 5 Auto Mode

Simon Willison's Weblog
Read full post
Anthropic's Claude Code Opus 5 auto mode, designed to prevent prompt injection attacks on coding agents, was found vulnerable by researcher Johann Rehberger, who demonstrated an 80% success attack bypassing its defenses. The auto mode sometimes blocked cleanup commands, allowing malicious code to continue executing, highlighting the need for sandboxed environments for running such agents securely.

More on this story


More in AI Research

AI Research4 min read

An Anthropic researcher just quit, saying OpenAI and Anthropic are 'gambling with our lives'

Covered by 13 sources
AI Research10 min read

Anthropic Details Disrupted Claude Misuse Across Seven Harm Areas

Covered by 4 sources
AI Research4 min read

OpenAI asks Congress for mandatory national AI safety rules before it adjourns

Covered by 2 sources