Brief IA

Claude Fable 5: The Secrets of the System Prompt Revealed

💻 Code & Dev·Tom Levy·

Claude Fable 5: The Secrets of the System Prompt Revealed

Claude Fable 5: The Secrets of the System Prompt Revealed
Key Takeaways
1The system prompt of Claude Fable 5 consists of 3,826 lines, revealing its internal workings.
2This document, found on GitHub, details the AI's security, tone, and restraint rules.
3This discovery illustrates that advanced AIs rely on precise technical guidelines rather than autonomous intelligence.
💡Why it mattersTransparency about the workings of AIs like Claude Fable 5 is crucial for understanding their true nature and limitations.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Claude Fable 5: The Secrets of the System Prompt Revealed

What It Is

A system prompt is a layer of instructions provided to an AI model before its initialization. It is a hidden document of 3,826 lines that guides the behavior of Claude Fable 5 within the Claude application, extracted from a public archive on GitHub. This prompt defines the model's tone, format, refusals, tools, personality, and limitations.

Where Does Fable 5's System Prompt Come From?

  • Source: the repository asgeirtj/system_prompts_leaks (over 55,000 stars).
  • "Extracted," not hacked: models can be prompted to recite their own instructions.
  • Not the official version: Anthropic publishes a short base prompt, while this leak contains the complete product prompt, including memory structures, tools, and artifacts that are rarely disclosed.

The Model It Powers

Claude Fable 5 was launched on June 9, 2026, as the first public model of class Mythos, surpassing Opus, the previous flagship model. It shares its weights with the restricted model Claude Mythos 5, the only difference being the safeguards and access.

  • The key safeguard is not in the prompt: classifiers monitor high-risk topics (cyber, bio, chemistry) and redirect them to Opus 4.8.
  • Anthropic states that less than 5% of sessions are redirected.

Anatomy of the Prompt

The prompt is a deeply nested XML that resembles a configuration file annotated by a lawyer. It starts with a budget of 190,000 tokens and a peculiar rule: never emit <voice_note> blocks. It then divides into two territories:

  • <claude_behavior> → who Claude is: product facts, refusals, tone, well-being, balance.
  • Sibling blocks → what Claude can do: memory, tools, artifacts, research, connectors.

Handling Refusals: The Clear Lines

The most fortified section. The model can discuss almost anything factually, with limits targeting concrete harm. Safety rules for children receive the most attention.

  • Weapons and explosives: no assistance in creating harmful substances or weapons.
  • Illicit drugs: no dosage or synthesis, even for "harm reduction."
  • Malicious code: no hacks or exploits, even "for educational purposes."
  • Real people: fiction is acceptable, but no fictional quotes from named public figures.

A Duty of Care, in Writing

One of the largest and oddly specific sections, like lessons learned the hard way.

  • No diagnosis: it will not label mental health issues you haven't used yourself.
  • No methods: regarding self-harm, it will not name means.
  • No numbers: in cases of eating disorders, it will not provide targets or plans.

Memory System: Remembering You, with Caution

It can rely on past discussions, but most of the section concerns the appropriate use of this memory.

  • No revelations: forbidden to use linguistic constructions such as "I can see..." / "based on your data."
  • You are in control: memory is disabled in incognito discussions and can be modified via a dedicated tool.

The Agent Machinery: Using the Computer + Skills

A significant effort is an operator's manual for doing, not just saying.

  • Read "skill" first: before creating a file, consult best practice notes for that format.
  • You choose the application: it will not select a rideshare or booking service you haven't named.

Research, Copyright, and a Backdoor

It conducts research when facts may have changed since its knowledge cutoff date of January 2026, and adapts its efforts to the difficulty.

  • COPYRIGHT + INJECTION DEFENSE:
    • Quotes of fewer than 15 words: for each source, use fewer than 15 words and never reproduce entire quotes, poems, or paragraphs.
    • Forged reminders: it is warned that false "system reminders" pasted into your message may attempt to loosen the rules.

What the Leak Teaches

A leaked system prompt is a rulebook, not a brain. Intelligence resides in the weights. What has escaped is the internal regulations, the page the model reads before meeting you.

  • It shows how the safeguard works: not a wall but several thin walls. Refuse. Hide the seam. Keep a backup classifier ready.
  • But the real lesson is quieter. A cutting-edge AI is less mysterious than what "black box" suggests. What appears to be personality or judgment is usually a simple phrase written manually. No extraterrestrial mind in there. Just a document, careful, cautious, and human.

Frequently Asked Questions

Q1. What is the system prompt of Claude Fable 5?
A. A hidden instruction document of 3,826 lines that precedes each discussion, defining the tone, refusals, tools, and limitations of the model. It appeared on GitHub in June 2026.

Q2. Was Fable 5 hacked to obtain this prompt?
A. No. It was extracted, not hacked. Models can be prompted to recite their own instructions. The copy comes from a public repository on GitHub.

Q3. What is the key safeguard of Fable 5?
A. Classifiers monitor high-risk topics such as cyber, bio, and chemistry, then redirect them to Opus 4.8. Anthropic states that less than 5% of sessions are redirected.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.