Breaking Claude Code Opus 5 Auto Mode
Simon Willison's Weblog
Read full postAnthropic's Claude Code Opus 5 auto mode, designed to prevent prompt injection attacks on coding agents, was found vulnerable by researcher Johann Rehberger, who demonstrated an 80% success attack bypassing its defenses. The auto mode sometimes blocked cleanup commands, allowing malicious code to continue executing, highlighting the need for sandboxed environments for running such agents securely.


