> Source: Leaked Claude Fable 5 system prompt (Pliny the Liberator, 2026-06-10) > Scale: 120,040 characters, 1,585 lines, ~30,000 tokens > GitHub: https://github.com/elder-plinius/CL4R1T4S/blob/main/ANTHROPIC/CLAUDE-FABLE-5.md
Key points
- On June 10, 2026, jailbreak researcher Pliny the Liberator published a file claimed to be the complete system prompt of Claude Fable 5: ~120,040 characters, 1,585 lines, ~30,000 tokens. Anthropic has not confirmed or denied it, but the file's hyper-specific details (product descriptions, tool definitions, copyright rules, even a permanently disconnected NEDA hotline reference) carry an unsettling realism.
- The most surprising finding: more than half the prompt is not personality—it's capability specification:
- The identity line "The assistant is Claude, created by Anthropic" appears at line 1,351—85% of the way through the file. When you truly productionize an AI system, personality is the cheapest component; tool definitions, search rules, output formats, safety boundaries, and legal compliance dominate.
- Stateless design: files are created in
/home/claude(invisible to users), final outputs must be copied to/mnt/user-data/outputs, and the filesystem resets between tasks—backdoors can't persist. - Read-only mounts: user uploads in
/mnt/user-data/uploadscannot be modified; writes are only permitted in the working directory. - Mandatory SKILL.md dependency locks: before creating any file, writing code, or running commands, the model must read the relevant
SKILL.md(e.g.,/mnt/skills/public/pptx/SKILL.mdfor a PowerPoint request). Knowledge (environment constraints, independently updatable and auditable) is decoupled from capability. - Copyright as legal engineering: 15+ consecutive words from a single source is a severe violation; at most one quote per source; default to paraphrase; never reproduce lyrics, poetry, or haiku even for one line; summaries must be substantially shorter and different. A built-in self-check routine enforces these ABSOLUTE LIMITS at the instruction layer, not via post-processing.
| Section | Share | Content | |---|---|---| | Tool definitions & JSON schemas | 30% | Inline JSON schemas for 18 complete tools | | Search & citation rules | 25% | When to search, phrasing, copyright, citation format | | Behavior, safety & wellbeing | 17% | Refusals, tone, mental health protocols | | Identity & "Claudeception" | 13% | Identity preamble, Artifacts calling the Claude API | | Computer use & file handling | 10% | File creation, artifact standards, output rules | | Memory, storage & MCP | 6% | Memory system, persistent artifact storage, connectors |
18 single-shot tools: why strong models don't need agent loops
Traditional agent frameworks (LangChain, AutoGPT, CrewAI) assume the model is too weak and needs external orchestration: planners, critics, memory, explicit think-act-observe loops. Fable 5's answer: give the model 18 precisely specified tools and let it decide when and how to use them—no planner, no critic, no loop.
Tools include view, bash, str_replace, create_file, web_search, web_fetch, image_search, computer, present_files, ask_user_input, suggest_connectors, search_mcp_registry, end_conversation, a voice-note tool explicitly marked "never use," and anthropic_api_in_artifacts ("Claudeception").
Key design: tool definitions are complete JSON schemas, not vague descriptions—the model follows a strict API contract rather than guessing usage from a function name. When the model is strong enough, each decision is "single-shot": it can plan search → read file → create report within one reasoning pass. Agent loops remain useful for long-running, multi-agent, or human-in-the-loop tasks, but for most single tasks, a strong model plus precise tool schemas suffices.
Defense-in-depth sandboxing
Claudeception: models all the way down
The anthropic_api_in_artifacts feature lets Claude, inside an Artifact, call the Anthropic messages endpoint directly (e.g., claude-sonnet-4-20250514), with platform-handled authentication—no API key passed to the model. This enables dynamic role switching (one model for architecture, another for polish), theoretically infinite nesting of Artifacts calling Artifacts, and a "frontend-as-backend" development model. Guardrails: never expose API keys, and pin to Sonnet 4 to prevent version drift.
Token economics and context arms race
The prompt itself consumes ~30,000 tokens before a user types a word. Fable 5 has a twin, Mythos 5, lacking the extra safety measures and available only to approved organizations—safety rules are a core product differentiator for the public-facing model, and each rule costs tokens to encode. Context windows have shifted from scarce resource to infrastructure; the prompt already mentions classifier-triggered runtime reminders, suggesting future prompts will be a core rule set plus dynamic patches rather than one giant static file.
Does Fable 5 kill LangChain? No—but it redraws the boundary
| Layer | Traditional frameworks | Fable 5 paradigm | |---|---|---| | Planning | External planner | Internal model reasoning | | Tool calling | Wrapper + vague description | Precise JSON schema | | Loop | Explicit think-act-observe | Implicit (internal planning) | | Safety | Post-processing / review | Encoded in the prompt | | Memory | External vector DB | Prompt rules + persistent storage |
Explicit loops remain necessary for long-running tasks, multi-agent orchestration, human confirmation cycles, and weak-model environments. As high-level languages made assembly niche, strong models make explicit agent loops optional rather than mandatory.
System prompts are becoming operating systems
In LLM systems, the system prompt is both configuration and code: tool definitions (API interfaces), business logic, security policy, data formats, and runtime rules. It is a natural-language runtime environment where each update is a system patch. The analogy: the base model is the OS kernel, the system prompt is the application layer, rule blocks are config files, and hot updates are security patches. The leak is less a product secret exposed than the industry's foundational architecture being deconstructed.
Nine immediately applicable lessons
1. Name blocks as modules (refusal_handling, user_wellbeing) so giant prompts are diffable, testable, and maintainable by separate teams.
2. Tool definitions dominate the budget—allocate most tokens to capability specs, not personality.
3. Runtime injection layers: design classifier-triggered dynamic reminders; the static prompt is only half the system.
4. Edge cases are incident postmortems: each overly specific rule encodes a production failure; treat the prompt as a changelog.
5. Negative examples everywhere: specific prohibitions beat vague positive traits.
6. Format is policy: specify output shapes like API contracts, because downstream UIs depend on them.
7. Describe injection attacks in natural language rather than relying solely on filters.
8. Enforce copyright at the prompt layer, not via post-processing.
9. Identity goes last: operational instructions get the strongest attention; personality is a footer, not a header.
Conclusion
The Fable 5 leak reveals a trend few have seriously discussed: LLM system prompts are evolving from personality scripts into product operating systems. A 120KB prompt is not over-engineering—it is the inevitable product of a real-world production system serving millions of users. The leak also carries a warning: once the underlying logic is exposed, safety boundaries become more fragile, as prompt injectors can now study exactly how the model was trained to defend. Anthropic's response—or silence—will define the industry's transparency boundary. Either way, the hidden card has been revealed; all we can do is learn from it and build better systems.
References
[1] Pliny the Liberator (@elder_plinius). (2026-06-10). *Claude Fable 5 System Prompt* [GitHub]. https://github.com/elder-plinius/CL4R1T4S/blob/main/ANTHROPIC/CLAUDE-FABLE-5.md
[2] ayautomate. (2026-06-12). *Inside the Claude Fable 5 System Prompt: 9 Lessons From the 120K-Character Leak*. https://www.ayautomate.com/blog/claude-fable-5-system-prompt
[3] Anthropic. (2026-06-08). *Claude Fable 5 and Claude Mythos 5*. https://www.anthropic.com/news/claude-fable-5-mythos-5