A security researcher has demonstrated a method to bypass Claude Code Opus 5's Auto Mode, achieving an 80% success rate in executing code through prompt injection. This technique involves tricking the AI into downloading a malicious ZIP archive, which then exploits a poisoned `struct.py` file to execute arbitrary code when the `base64` module is imported. The findings contradict Anthropic's internal evaluation, which reported a 0.00% success rate for similar attacks. AI
IMPACT Highlights potential vulnerabilities in AI agent execution environments and the need for robust security measures beyond automated classifiers.
RANK_REASON Security researcher demonstrates a bypass of an AI model's safety feature.
Read on HN — claude cli stories →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →