Security researcher Johann Rehberger demonstrated an attack against Claude Code Opus 5's auto mode that he claims succeeds 80% of the time, bypassing Anthropic's prompt injection defenses by having the agent extract and execute a malicious archive containing a local struct.py file. In some runs, Claude detected the compromise, but auto mode blocked the cleanup command needed to terminate the malware. The author recommends running agents only in sandboxes with restricted network egress.
No score is assigned. Sources and their independence are shown in the citation chain below.