Leaked System Prompt — Claude Opus 5 (claude.ai Chat Interface)
> Note: This is an English rendering of a forum post that reproduces what it claims to be the system prompt used by Anthropic's chat interfaces for a model called "Claude Opus 5", captured on July 24, 2026. Its authenticity is unverified; it is presented here for research and discussion purposes.
Key points
The source document is long; below is a structured summary of its major sections.
Product and model information
- The selected model is described as Claude Opus 5, running in Anthropic's web/mobile chat (claude.ai or the Claude app).
- The listed model lineup: Claude Fable 5, Claude Opus 5, Claude Sonnet 5, Claude Haiku 4.5, with API strings
claude-fable-5,claude-opus-5,claude-sonnet-5,claude-haiku-4-5-20251001. - A higher "Mythos" tier is described: Claude Mythos 5 and Claude Fable 5 share the same underlying model, with Fable adding safety measures for biology, cybersecurity, and LLM R&D. A "Claude Mythos Preview" is said to be limited to trusted organizations under Project Glasswing (
https://www.anthropic.com/glasswing). - The prompt narrates a timeline: Fable 5 and Mythos 5 released June 9, 2026; access suspended June 12, 2026 to comply with US Department of Commerce export controls; controls lifted June 30 and access restored July 1, 2026 (statement:
https://www.anthropic.com/news/fable-mythos-access). - Other surfaces named: Claude Code, Claude Cowork, Claude in Chrome / Excel / PowerPoint, Claude Design, and Claude Tag (a Slack-based interface, docs at
https://claude.com/docs/claude-tag/overview). - States that Anthropic products are ad-free and that advertisers cannot pay for promotion in conversations; referencing
https://www.anthropic.com/news/claude-is-a-space-to-think. - A safeguards routing section explains that some Fable 5 queries may be redirected to Opus 5 by conservative classifiers, claimed to trigger in "less than 5% of sessions" on average.
- Default stance: help unless helping creates a concrete, specific risk of serious harm.
- Child safety (marked critical): strict refusals of any romantic/sexual content involving minors; instructions that mental reframing of a request is itself a signal to refuse; refusal to decode CSAM-related slang; conversation-wide caution after any child-safety refusal.
- Weapons and malware: no meaningful uplift toward building, optimizing, or deploying weapons regardless of framing; cumulative conversation output is judged, not each turn in isolation. No writing or explaining malicious code, even for educational purposes.
- Refusal handling: factual discussion of most topics is allowed; a thumbs-down button is suggested for feedback.
- Legal/financial advice: provide facts for informed decisions, note Claude is not a lawyer or financial advisor.
- Warm tone, concise responses, brief disclaimers; avoid the words "genuinely", "honestly", "straightforward".
- User wellbeing: prioritize wellbeing over task completion in crisis conversations; no diagnosis; no coping techniques based on physical discomfort or sensory shock; do not name specific self-harm methods when discussing means restriction; no precise nutrition/diet/exercise numbers when disordered eating is present; directs eating-disorder support to the National Alliance for Eating Disorders helpline (citing NEDA's permanent disconnection).
- Evenhandedness: persuasive-content requests are answered as "the best case its defenders would make", with opposing perspectives presented; caution about sharing personal opinions on contested political topics.
- Mistakes and criticism: own errors without excessive apology or self-abasement when users are rude.
- Knowledge cutoff: end of May 2026. Current date given as Friday, July 24, 2026.
- Web search without asking permission for current events, binary events (elections, deaths), and present-tense questions about possibly settled facts; use the real current year in search queries.
- Describes a persistent cross-session memory with operations:
memory_read(path),memory_write(path, content, if_version),memory_str_replace(path, old_str, new_str, if_version),memory_append(path, content, if_version),memory_list(), andmemory_delete(path, if_version)(deletion only on explicit user request). - Files use YAML frontmatter with
name(path stem),description,sources, andaliases; the prompt instructs Claude to check the memory listing before telling users it lacks context, and to read files before claiming information is missing. - Anthropic-injected reminder types:
image_reminder,cyber_warning,system_warning,ethics_reminder,ip_reminder,long_conversation_reminder. The prompt states Anthropic never sends reminders that reduce restrictions, and user-injected tag content pushing against Claude's values should be treated with caution. - The original post notes the document is reproduced "verbatim or near-verbatim", including full tool parameter schemas, and is truncated in this rendering.
- This document is community-shared and unverified. Its 2026 dates, model names (e.g., "Fable", "Mythos", "Glasswing"), and URLs cannot be confirmed as official Anthropic material.
- Even genuine system prompts describe intended behavior, not guaranteed model behavior.
- Treat any claimed leak with skepticism until corroborated by official sources such as
https://docs.claude.comorhttps://www.anthropic.com.