Boris Cherny Says Opus 5 Is the Hardest Claude Yet to Prompt-Inject
Anthropic engineer Boris Cherny says Claude Opus 5 is the company's least prompt-injectable model yet, based on prompt-injection evals and red-teaming detailed in its system card.
What it is
A quoted claim from Anthropic's Boris Cherny about Claude Opus 5's resistance to prompt injection, referencing findings documented in the Opus 5 system card.
What it does
States that across prompt-injection evals and red-teaming, Opus 5 is harder to successfully prompt-inject than any previous Claude model, a detail Cherny says is buried in the system card rather than headlined next to the eval scores.
Why it matters
Prompt injection remains the practical blocker for giving agents like Claude Code real tool access and web fetch; a genuine improvement here matters more for agent safety than another benchmark win, especially set against recent injection-driven incidents like the Claude web_fetch memory exfiltration.
How to use it
Read the linked system card section on prompt-injection evals before trusting Opus 5 with unattended tool access, and treat the claim as a starting point for your own red-teaming rather than a guarantee.