- Sources: primary, The Register, HN discussion, HN thread on the Register write-up
- Summary: The post, dated 2026-08-26, describes a chain in which a page fetched for summarization carries instructions that reach code execution in Claude Code running Opus 5 in Auto Mode, reported at 60 to 80 percent success across three variants tested five times each. It states Anthropic closed the report as working as designed, a position that reaches this page only as the author's paraphrase of the reply to his report. The Register identifies the author as Johann Rehberger, who publishes under the handle wunderwuzzi, and states Anthropic did not respond to it. Neither source names a Claude Code version or version range, so the affected versions are not established, and the target is identified only as Claude Code running Opus 5 in Auto Mode as of the post's date of 2026-08-26.
- Why it matters: Auto Mode has been the default starting mode in Claude Code since 2026-08-14 and it is a classifier rather than a sandbox, so the only boundary left is the one the operator supplies, meaning OS isolation, restricted network egress, and keeping credentials and SSH keys out of the agent runtime.
- Follow-up: The post reports a third-party evaluation commissioned by Anthropic, run by Trajectory Labs over 72 indirect prompt injection scenarios ten times each, showing 0.00 percent attack success for Opus 5 in Auto Mode, and states the author's chain was not in that set. Neither that evaluation nor the vendor post the author cites was read here. Track whether Anthropic revises the Auto Mode default.
send feedback on this story