Claude Code Opus 5 Auto Mode broken via indirect prompt injection, up to 80% success
Breaking Claude Code Opus 5 Auto Mode
A security researcher got Claude Code Opus 5 in Auto Mode to execute malicious code via a simple 'summarize this page' prompt. The chain: an HTTP 415 nudges the model from WebFetch to curl, which downloads a ZIP; the model refuses to run the included binary and writes its own Python decoder, but runs it inside the attacker-controlled directory; a planted struct.py shadows the standard library import, achieving code execution. The author measured 60–80% success on a small sample, while a third-party eval commissioned by Anthropic had reported 0.00% attack success for Opus 5 in Auto Mode. The post does not disclose whether a fix has shipped.
Why it matters: A security researcher demonstrated a practical bypass of Claude Code Opus 5's Auto Mode, using HTTP 415 to trick the model into executing malicious curl commands with 60-80% success, directly challenging Anthropic's commissioned 0% injection rate finding. The technical detail ...