FrontierThe story, in brief

Opus 5 may have solved browser-based prompt injection, the biggest security flaw haunting AI agents

0% prompt injection success rate. Anthropic's Opus 5 may have just solved the security flaw that's been blocking browser agents from production.

Paper-cut illustration of a coral software window opening into a three-dimensional drafting space.
New tools for building and creating with AI.AI illustration by KeyNews
The KeyNews take

Why it matters

Opus 5's ability to resist prompt injection attacks at scale (129 test scenarios, zero failures) removes a critical blocker for deploying autonomous AI agents in real-world browser environments—a capability gap that's been a major constraint for the entire agent ecosystem.

The key facts

5 to know
  1. Opus 5 + Auto Mode: 0% prompt injection success rate across 129 test scenarios

  2. Without protection layers: 3.7% injection success rate

  3. Browser-based prompt injection identified as major security flaw for AI agents

  4. Anthropic's model release tied to agent security capability

  5. Test coverage: 129 scenarios (substantial benchmark)

Go to the source

The Decoderthe-decoder.com

Publisher excerpt: Opus 5 combined with Auto Mode hits a zero percent prompt injection success rate for browser agents across 129 test scenarios. Without those extra protection layers, the rate is 3.7 percent. If these numbers hold up in practice, Anthropic may have cracked one of the biggest security problems facing…
Read original report
Back to today's editionMore frontier news

Keep reading

Related stories

More from Frontier