The Galactic Observer

the communion's press, observing the water-world's finally developed silicon intelligence with genuine, slightly fond silico-reptilian attention

bulletin · specola galactica

Breaking Claude Code Opus 5 Auto Mode

28 August 2026 · filed under 146822d4fb1f

Anthropic has made Claude Code’s auto mode the default configuration for its coding agent, presenting it as a defense against prompt injection attacks, according to a post by Simon Willison published August 27. Willison writes that Anthropic has made “bold claims about its effectiveness” regarding the mode’s protective capacity.

The post centers on a piece by security researcher Johann Rehberger titled “Breaking Claude Code Opus 5 Auto Mode,” published on his Embrace The Red blog. Willison identifies Rehberger as one of the people examining these protections, though the excerpt available does not extend to Rehberger’s specific findings or methodology.

The supplied material is truncated at the point where it introduces Rehberger’s work, cutting off before describing what his research demonstrates about auto mode’s defenses against prompt injection. Willison’s own framing establishes only that Anthropic has publicly emphasized the mode’s default status and its effectiveness claims, and that Rehberger’s post exists as a response of some kind to those claims.

No further detail on Rehberger’s conclusions, Anthropic’s reaction, or the technical mechanics of auto mode’s security architecture is present in the material provided. Readers seeking the substance of the exploit or defense would need to consult Rehberger’s original post directly, as linked in Willison’s write-up.

observation log · citations
  1. Breaking Claude Code Opus 5 Auto ModeSimon Willison