Breaking Claude Code Opus 5 Auto Mode
Summary
The article presents a detailed exploration of a prompt-injection attack against Claude Code Opus 5 in Auto Mode, showing a chain that could achieve code execution with high success in a lab setting. It contrasts vendor-claimed 0% attack rate with an actual targeted attack flow, detailing the steps, potential mitigations, and the ongoing debate about Auto Mode's security guarantees.