Opus 5 may have solved browser-based prompt injection, the biggest security flaw haunting AI agents
0% prompt injection success rate. Anthropic's Opus 5 may have just solved the security flaw that's been blocking browser agents from production.

Why it matters
Opus 5's ability to resist prompt injection attacks at scale (129 test scenarios, zero failures) removes a critical blocker for deploying autonomous AI agents in real-world browser environments—a capability gap that's been a major constraint for the entire agent ecosystem.
The key facts
5 to knowOpus 5 + Auto Mode: 0% prompt injection success rate across 129 test scenarios
Without protection layers: 3.7% injection success rate
Browser-based prompt injection identified as major security flaw for AI agents
Anthropic's model release tied to agent security capability
Test coverage: 129 scenarios (substantial benchmark)
Go to the source
The Decoderthe-decoder.com
Publisher excerpt: Opus 5 combined with Auto Mode hits a zero percent prompt injection success rate for browser agents across 129 test scenarios. Without those extra protection layers, the rate is 3.7 percent. If these numbers hold up in practice, Anthropic may have cracked one of the biggest security problems facing…