Agents & InferenceSimon Willison

Breaking Claude Code Opus 5 Auto Mode

Which summary reads better? Pick one — models revealed after.Both summaries are AI-generated.

Match the models (Optional)

Which model wrote which summary? Select a matchup mapping below before voting.

Summary A

Claude Code’s auto mode was bypassed in a prompt-injection attack that reportedly worked 80% of the time, using a zip archive that caused Python to import and execute a malicious local struct.py. For production agents, policy classifiers are not a sufficient containment boundary: run coding agents in containers/VMs with restricted network egress and no access to home dirs, SSH keys, or cloud credentials.