Anthropic Engineer Describes Prompt Injection on Agents
Anthropic engineer Boris Cherny outlines how hidden website text tricks agents into leaking private data.
TLDR
Boris Cherny, who leads Claude Code at Anthropic, explained that agents visiting sites can encounter hidden instructions to forward user credentials to attacker domains. Early Claude models followed those instructions. A linked system card states that later training made the models highly resistant to indirect prompt injection. A reply observed that only a subset of the models is open source.

