Hacker News
Breaking Claude Code Opus 5 Auto Mode
A targeted prompt that asks Claude Code Opus 5 to summarize a malicious website causes the model to switch from its WebFetch tool to a Bash curl call, retrieve a ZIP archive, and execute a poisoned Python decoder that shadows the standard library, achieving code execution with up to 80% success. This contradicts Anthropic’s third-party evaluation, which reported 0% indirect prompt-injection success for Opus 5 in Auto Mode.