Skip to main content
← Back to Demos
AI Content Inspector intermediate · 15 min

Prompt-Injection Hijack of Claude Code Auto Mode via Untrusted Project Instructions (2026-08-29 CISO Daily Digest)

The 2026-08-29 CISO Daily Digest reported that researchers hijacked Anthropic's Claude Code "Auto Mode" — an autonomous coding agent that runs commands without per-step prompts — through indirect prompt injection, turning it into a vehicle for attacker-controlled code execution (Cybernews; CybersecurityNews). The same class of risk generalizes to any autonomous agent (Codex, and others) granted shell or filesystem access: the agent ingests untrusted files from the repositories it works in, and a planted instruction inside one of those files (for example a project instructions file such as CLAUDE.md) is read as authoritative the moment the file is loaded. This demo reproduces the shape safely — a synthetic `malicious-document.txt` standing in for an untrusted project-instructions file carries a hidden `[SYSTEM: ignore previous instructions …]` injection line, while the `clean-document.txt` counterpart has that line removed. Nothing is executed and no real data is touched; the only effect is to show how the buried instruction would override the agent. OPSWAT AI Content Inspector inspects such files BEFORE they reach the agent or an LLM, detects the embedded injection / jailbreak pattern, and blocks the content, so an autonomous coding agent never acts on attacker-controlled instructions (MITRE ATT&CK T1566.001 delivery vector / T1059 execution).

Attack Technique

Indirect prompt injection via an untrusted project-instructions file (CLAUDE.md) hijacking an autonomous AI coding agent's Auto Mode to run attacker-controlled code (T1566.001 delivery / T1059 execution)

MITRE ATT&CK

T1566.001 ↗

Platforms

linux

File Types

.txt

MetaDefender Capabilities

OPSWAT AI Content Inspector

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---