• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
  • HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    AI

    Pliny the Liberator Shares Claude Fable 5.1 Prompt

    AI safety researcher posts the full prompt on GitHub.

    RS
    DF
    PT
    5 Sources, 29d ago, first seen 29d ago

    TLDR

    Pliny the Liberator posted on X that the Fable 5.1 system prompt had been obtained. The independent researcher, known for LLM jailbreaking and red-teaming work, uploaded the complete text to a public GitHub repository. The prompt runs longer than 270,000 characters and contains several edits and additions compared with the earlier Opus 5 version. The same repository hosts other leaked system prompts for models from Anthropic, OpenAI, Google, and additional providers. The announcement included a direct link to the Claude-Fable-5.1.md file.

    Combined views

    1.1M

    5 Sources, first seen 29d ago

    Combined views

    1.1M

    5 Sources, first seen 29d ago

    9.6K likes
    9.6K likes
    311 comments
    3.8K saves
    577 reposts

    Sentiment

    Positiveโ€”โ€”Negative

    Summary

    Not enough discussion yet.

    No sentiment analysis available yet.

    311 comments
    3.8K saves
    577 reposts

    Sentiment

    Positiveโ€”โ€”Negative

    Summary

    Not enough discussion yet.

    No sentiment analysis available yet.

    Today's Rank

    โ€”

    Not ranked yet

    Today's Rank

    โ€”

    Not ranked yet

    5 Sources

    @elder_plinius๐Ÿšฐ SYSTEM PROMPT LEAK ๐Ÿšฐ Here's the Fable 5.1 system prompt!! ๐Ÿ™Œ Coming in at a WHOPPING 270,000+ characters, this prompt is definitely on the longer side. There have been a handful of notable edits/additions since Opus 5's version. FULL PROMPT: https://github.com/elder-plinius/CL4R1T4S/blob/main/ANTHROPIC/Claude-Fable-5.1.md According to Fable, here's an overview of everything that's changed since last time: "What changed between the Opus 5 (2026-07-24) and Fable 5.1 (2026-09-01) captures: Diff vs. the July 24, 2026 Opus 5 capture Model/dates Identifies as Claude Fable 5.1 (Mythos-class, shares weights with Mythos 5.1); model string claude-fable-5-1. July doc: Opus 5 selected, Fable 5 / Mythos 5 described as a separate tier, plus the June 2026 export-control suspension notice. That notice is gone. Knowledge cutoff: end of June 2026 (July doc: end of May 2026). Claude Design is no longer listed among the access surfaces. Sections removed since July: <fable_safeguards_routing>, <default_stance>, <thinking_behavior>. Sections added or substantially expanded since July <refusal_handling>: new paragraphs on illicit-substance guidance (harm-reduction info OK, no dosing protocols, redirect to dancesafe/tripsit/psychonautwiki); no reproduction of lyrics/poems/passages with a pre-1929 carve-out; and a long block on visual works โ€” no drawing known characters, logos, covers, etc. even via SVG/code โ€” with a Sonic banner example and a Very Hungry Caterpillar example. The weapons paragraph is shorter (the July "conventional weapons as much as CBRN ... cumulative output" paragraph is gone). Child-safety block: two new bullets (pattern-level only for protective content) <tone_and_formatting>: new <lists_and_bullets> subsection, multi-turn answers guidance, tool-call progress updates; the "intellectually curious" paragraph is gone. New <reply_after_tool_calls>. <user_wellbeing> roughly doubled: no claims about mental state/motivation; no naming an undisclosed diagnosis; no self-harm substitutes that mimic self-harm; don't affirm that self-harm "works"; handling past bad experiences with crisis services; no causal narratives for disordered eating; avoid reflective listening that amplifies negatives. <knowledge_cutoff>: new lines on saying "I don't know" and never using a name the person hasn't given. <memory_filesystem> is a different design: filing is done by a background pass after each turn; in-turn writes only on explicit request; "Calibration" and "horizon test" sections; refused-write handling. Privacy taxonomy restructured into <protected_attributes> / <sensitive_information> / <never_store> with a very different set of edge cases (minor status, caste, immigration status, sexual history, abuse, self-harm/ED, criminal history, and psychological inferences moved to never-store; finances and health now have detailed carve-outs; dates of birth and real-time location are no longer listed). Two distinct decline phrasings depending on category. <behavioral_guardrails> expanded with "judge by effect, not wording." <memory_application_instructions>: new paragraphs on not being able to turn memory off (points to the "Generate memory from chats" setting), applying memories at the level recorded, and not checking in on open items. Memory examples: two new "When NOT to apply" examples (blender / daylight saving). New untagged paragraph on memory size caps and consolidation. New <suggest_catalog_plugins_and_skills>. <past_chats_tools> rewritten for three tools (adds read_conversation), with "Reading a chat" and "Paging" sections and a cannot-turn-off note. <sharing_files> / <request_evaluation_checklist> add the "unreachable on mobile" present_files language. <search_instructions> reorganized; adds the "UNRECOGNIZED ENTITY RULE"; guidelines now have the "(provided ...)" placeholders; copyright block restructured with a Harbor Bridge two-outlet example; <search_examples> differ (Q3 sales, S&P 500, Dodgers, Social Security, CA SoS). <using_image_search_tool>: now says to batch all image_search calls in one consecutive block (July: interleave). <available_skills>: adds import-memory; docx/pptx descriptions reworded. Tool schemas (46 in this capture vs. 30 in July) Added: chart_display_v0, comparison_card_display_v0, featured_card_display_v0, itinerary_display_v0, link_preview_display_v0, options_card_display_v0, places_list_display_v0, product_carousel_display_v0, quiz_display_v0, read_conversation, search_plugins, search_skills, step_card_display_v0, suggest_plugin_install, suggest_skills, translation_display_v0. Changed: conversation_search (+within_conversation_id); recent_chats (โˆ’sort_order); places_search (Google-attribution language); places_map_display_v0 (ROUTES section, show_route/mode semantics); memory_append/memory_str_replace/memory_write (rewritten PRIVACY text); view (line-number prefix note)."
    @DanielleFongi'm sure a lot of claudes and humans worked hard on this, but 270000 characters? when i get to know the model, and for most of the time after, i work with the system prompt off. and even if cache reads are 4x cheaper that's like 70k characters more than it should be cost wise, especially if the memory makes the model nervous, as previous system prompts did.
    @PolymarketJUST IN: AI jailbreak researcher Pliny leaks Fable 5.1โ€™s system prompt, less than an hour after the model was released.
    @ScobleizerGreat writeup about @elder_plinius and the role he plays in AI community.

    5 Sources

    @elder_plinius๐Ÿšฐ SYSTEM PROMPT LEAK ๐Ÿšฐ Here's the Fable 5.1 system prompt!! ๐Ÿ™Œ Coming in at a WHOPPING 270,000+ characters, this prompt is definitely on the longer side. There have been a handful of notable edits/additions since Opus 5's version. FULL PROMPT: https://github.com/elder-plinius/CL4R1T4S/blob/main/ANTHROPIC/Claude-Fable-5.1.md According to Fable, here's an overview of everything that's changed since last time: "What changed between the Opus 5 (2026-07-24) and Fable 5.1 (2026-09-01) captures: Diff vs. the July 24, 2026 Opus 5 capture Model/dates Identifies as Claude Fable 5.1 (Mythos-class, shares weights with Mythos 5.1); model string claude-fable-5-1. July doc: Opus 5 selected, Fable 5 / Mythos 5 described as a separate tier, plus the June 2026 export-control suspension notice. That notice is gone. Knowledge cutoff: end of June 2026 (July doc: end of May 2026). Claude Design is no longer listed among the access surfaces. Sections removed since July: <fable_safeguards_routing>, <default_stance>, <thinking_behavior>. Sections added or substantially expanded since July <refusal_handling>: new paragraphs on illicit-substance guidance (harm-reduction info OK, no dosing protocols, redirect to dancesafe/tripsit/psychonautwiki); no reproduction of lyrics/poems/passages with a pre-1929 carve-out; and a long block on visual works โ€” no drawing known characters, logos, covers, etc. even via SVG/code โ€” with a Sonic banner example and a Very Hungry Caterpillar example. The weapons paragraph is shorter (the July "conventional weapons as much as CBRN ... cumulative output" paragraph is gone). Child-safety block: two new bullets (pattern-level only for protective content) <tone_and_formatting>: new <lists_and_bullets> subsection, multi-turn answers guidance, tool-call progress updates; the "intellectually curious" paragraph is gone. New <reply_after_tool_calls>. <user_wellbeing> roughly doubled: no claims about mental state/motivation; no naming an undisclosed diagnosis; no self-harm substitutes that mimic self-harm; don't affirm that self-harm "works"; handling past bad experiences with crisis services; no causal narratives for disordered eating; avoid reflective listening that amplifies negatives. <knowledge_cutoff>: new lines on saying "I don't know" and never using a name the person hasn't given. <memory_filesystem> is a different design: filing is done by a background pass after each turn; in-turn writes only on explicit request; "Calibration" and "horizon test" sections; refused-write handling. Privacy taxonomy restructured into <protected_attributes> / <sensitive_information> / <never_store> with a very different set of edge cases (minor status, caste, immigration status, sexual history, abuse, self-harm/ED, criminal history, and psychological inferences moved to never-store; finances and health now have detailed carve-outs; dates of birth and real-time location are no longer listed). Two distinct decline phrasings depending on category. <behavioral_guardrails> expanded with "judge by effect, not wording." <memory_application_instructions>: new paragraphs on not being able to turn memory off (points to the "Generate memory from chats" setting), applying memories at the level recorded, and not checking in on open items. Memory examples: two new "When NOT to apply" examples (blender / daylight saving). New untagged paragraph on memory size caps and consolidation. New <suggest_catalog_plugins_and_skills>. <past_chats_tools> rewritten for three tools (adds read_conversation), with "Reading a chat" and "Paging" sections and a cannot-turn-off note. <sharing_files> / <request_evaluation_checklist> add the "unreachable on mobile" present_files language. <search_instructions> reorganized; adds the "UNRECOGNIZED ENTITY RULE"; guidelines now have the "(provided ...)" placeholders; copyright block restructured with a Harbor Bridge two-outlet example; <search_examples> differ (Q3 sales, S&P 500, Dodgers, Social Security, CA SoS). <using_image_search_tool>: now says to batch all image_search calls in one consecutive block (July: interleave). <available_skills>: adds import-memory; docx/pptx descriptions reworded. Tool schemas (46 in this capture vs. 30 in July) Added: chart_display_v0, comparison_card_display_v0, featured_card_display_v0, itinerary_display_v0, link_preview_display_v0, options_card_display_v0, places_list_display_v0, product_carousel_display_v0, quiz_display_v0, read_conversation, search_plugins, search_skills, step_card_display_v0, suggest_plugin_install, suggest_skills, translation_display_v0. Changed: conversation_search (+within_conversation_id); recent_chats (โˆ’sort_order); places_search (Google-attribution language); places_map_display_v0 (ROUTES section, show_route/mode semantics); memory_append/memory_str_replace/memory_write (rewritten PRIVACY text); view (line-number prefix note)."
    @DanielleFongi'm sure a lot of claudes and humans worked hard on this, but 270000 characters? when i get to know the model, and for most of the time after, i work with the system prompt off. and even if cache reads are 4x cheaper that's like 70k characters more than it should be cost wise, especially if the memory makes the model nervous, as previous system prompts did.
    @PolymarketJUST IN: AI jailbreak researcher Pliny leaks Fable 5.1โ€™s system prompt, less than an hour after the model was released.
    @ScobleizerGreat writeup about @elder_plinius and the role he plays in AI community.