AI ResearchCybersecurity2 min reading time

Breaking Claude Code Opus 5 Auto Mode

Simon Willison's Weblog
Read full post
Anthropic's Claude Code Opus 5 auto mode, designed to prevent prompt injection attacks on coding agents, was found vulnerable by researcher Johann Rehberger, who demonstrated an 80% success attack bypassing its defenses. The auto mode sometimes blocked cleanup commands, allowing malicious code to continue executing, highlighting the need for sandboxed environments for running such agents securely.

More on this story


More in AI Research

AI Research4 min read

An Anthropic researcher just quit, saying OpenAI and Anthropic are 'gambling with our lives'

Covered by 12 sources
AI Research3 min read

Worried Anthropic researchers warn that AI ‘could kill all humans’

Covered by 8 sources

Google Pledges Over $15 Billion for AI Infrastructure in Finland

Covered by 3 sources