AI
Opus 5 may have solved browser-based prompt injection, the biggest security flaw haunting AI agents
Anthropic's Opus 5 model, when combined with Auto Mode in products like Claude Cowork, achieved a zero percent prompt injection success rate across 129 browser
Key takeaways
- Opus 5 combined with Auto Mode hits a zero percent prompt injection success rate for browser agents across 129 test scenarios.
- Without Auto Mode protection layers, the Opus 5 prompt injection success rate is 3.7 percent.
- Opus 5 leads the Gray Swan IPI benchmark with a 2.0 percent attacker success rate after 15 attempts.
- Sonnet 5 performs better than standalone Opus 5 without Auto Mode, sitting at a 0.93 percent success rate.
Anthropic's Opus 5 model, when combined with Auto Mode in products like Claude Cowork, achieved a zero percent prompt injection success rate across 129 browser agent test scenarios. Auto Mode uses two defense layers: scanning incoming data for hidden instructions and blocking dangerous actions before execution. Without these layers, the Opus 5 injection rate is 3.7 percent, while Sonnet 5 sits at 0.93 percent. In general prompt injection tests by Gray Swan, Opus 5 led the benchmark with a 2.0 percent attacker success rate, outperforming Mythos 5 and Fable 5.
By the numbers
- 0%
- Prompt injection success rate across 129 test scenarios
- 3.7%
- Opus 5 prompt injection success rate without Auto Mode
- 2.0%
- Opus 5 attacker success rate on Gray Swan benchmark
- 0.93%
- Sonnet 5 prompt injection success rate without Auto Mode
How it unfolded
- OpenAI admits prompt injection may never be fully solved
- Anthropic system card reveals Opus 5 security test results
Turn stories like this into views
Ravenclip finds the AI news, makes the video, and posts it before attention moves on.
Common questions
- What happened with Opus 5?
- Opus 5 combined with Auto Mode hits a zero percent prompt injection success rate for browser agents across 129 test scenarios.
- Where can I read the original report?
- Read the full report at the_decoder.