Claude Discovery

← All discoveries

Close-up of a smartphone wrapped in a chain with a padlock, symbolizing strong security.
Photo by Towfiqu barbhuiya on Pexels
trick

Johann Rehberger Finds a Working Prompt Injection Bypass in Opus 5 Auto Mode

2026-08-28 ยท source:

Security researcher Johann Rehberger found a working prompt injection attack against Claude Code's auto mode, which Anthropic made the default and had claimed protects users against such attacks.

What it is

A writeup by prompt injection researcher Johann Rehberger detailing an attack that defeats Claude Code's auto mode, the permission-classifier system Anthropic recently made the default for new sessions.

What it does

The attack demonstrates a prompt injection technique that gets past auto mode's classifier rules, undermining Anthropic's public claims about the mode's effectiveness at blocking these attacks.

Why it matters

Auto mode is now the default protection layer for a huge number of Claude Code sessions, so a credible bypass from one of the field's most established prompt injection researchers is a serious data point, not a theoretical nitpick.

How to use it

Read the full technical breakdown at embracethered.com before relying on auto mode as your only safeguard against untrusted content reaching Claude Code.

Go to source →
securityprompt-injectionclaude-code