Twitter/X

Opus 5 is claimed to be state-of-the-art on several coding and knowledge-work…

Brief

Opus 5 is presented by @bcherny (2026-07-24) as a new SOTA model for coding, data analysis, design, biology and broader knowledge work. More important than benchmark scores, Anthropic reports Opus 5 is their least prompt-injectable model; layered defenses (alignment, injection probes, Auto Mode in Claude Code) reportedly drive injection success to ~0.

Why it matters

Opus 5 is claimed to be state-of-the-art on several coding and knowledge-work evaluations, and is promoted for coding, data analysis, design, biology, and knowledge work (post by @bcherny, 2026-07-24).

Key details

  • Opus 5 is described as Anthropic’s least prompt-injectable model: PI evals and red teaming found it “very hard to prompt inject,” and combining strong model alignment, prompt-injection probes, and Claude Code’s Auto Mode reduced prompt-injection attack success to ~0.
Source evidence

Opus 5 is a great model for coding, data analysis, design, biology, knowledge work.

More than any of these eval scores, what is most exciting to me is something else: Opus 5 is our least prompt injectable model yet. It is a bit buried in the system card, but across PI evals and red teaming, Opus 5 is very hard to prompt inject successfully.

And when layering defenses -- strong model alignment, combined with prompt injection probes, combined with Auto Mode in Claude Code -- the success rate for prompt injection attacks drops to ~0. This is new and exciting! More about this soon.

www-cdn.anthropic.com/c5fbac…

Claude (@claudeai)

On several coding and knowledge work evaluations, Opus 5 is the new state-of-the-art:

— https://nitter.net/claudeai/status/2080699497064083942#m