explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

custom AI agents

[email protected]

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource librarydemofor LLMs

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

More from us

InfloqInfluencer marketingBgBlurPrivacy-first blurOlly SocialSocial AI copilotCeptoryVideo intelligenceBgRemoverBackground removal

newsletter · weekly

Get AI news, tools, and insights in your inbox.

contactsupportprivacytermsdata rightssubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

On this page

  • TL;DR — Fable 5 prompt at a glance
  • Why the Fable 5 prompt is enormous
  • Top-level structure
  • Mythos-class product copy
  • Safety sections worth studying
  • Memory system — what Claude must never say
  • Artifacts — when to file vs inline
  • Citations — antml:cite XML
  • Bundled skills at the tail
  • Fable 5 vs Opus 4.8 — use the repo diff
  • Sonnet 5 and Claude Design — sibling files in the repo
  • Refusal handling and tone — the "voice" layer
  • Connectors, search, and deep research
  • What builders should do with this leak
  • Related on explainx.ai
← Back to blog

explainx / blog

Claude Fable 5 System Prompt Leak: What's Inside Anthropic's 3,800-Line claude.ai Instructions

The full Claude Fable 5 system prompt leaked on GitHub (asgeirtj/system_prompts_leaks). Mythos vs Fable, child-safety XML blocks, memory rules, artifacts, cyber_warning — explained.

Jul 7, 2026·9 min read·Yash Thakker
Claude Fable 5System PromptAnthropicPrompt EngineeringAI Safety
go deep
Claude Fable 5 System Prompt Leak: What's Inside Anthropic's 3,800-Line claude.ai Instructions

In July 2026, builders still treat asgeirtj/system_prompts_leaks as the phone book for how frontier chatbots are actually configured. The repo crossed 51.5K GitHub stars, was cited in The Washington Post (May 2026), and ships under CC0-1.0 — meaning the archived text is public documentation, not a hack.

The headline file for Anthropic right now is Anthropic/claude-fable-5.md: the claude.ai system prompt for Claude Fable 5, captured at roughly 3,800 lines of XML-tagged operator instructions. The repo also publishes a diff versus Claude Opus 4.8 — the fastest way to see what changed when Anthropic moved to the Mythos-class tier.

This post is a map of that file for developers who will never read every line — and what it implies for safety, artifacts, and prompt engineering in 2026.

Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.


TL;DR — Fable 5 prompt at a glance

QuestionAnswer
Sourceclaude-fable-5.md on system_prompts_leaks
Length~3,800 lines; token_budget tag shows 190,000 in snapshot
FormatNested XML tags (<claude_behavior>, <memory_system>, …)
Model identityFable 5 = Claude 5 family; same weights as Mythos 5, different safety packaging
Knowledge cutoffEnd of Jan 2026; leak snapshot hard-codes Tuesday, June 9, 2026 as "today"
Big themesChild safety, mental-health guardrails, memory phrasing bans, artifacts + skills, citations
Classifier hookscyber_warning, ethics_reminder, image_reminder, long_conversation_reminder, …
Not in this fileClaude Code agent prompt (separate leak in same repo)
Use responsiblyStudy and defend — do not paste wholesale into your app

Why the Fable 5 prompt is enormous

Consumer chat prompts used to be a paragraph of persona. Fable 5's leak reflects product + policy + tools + skills in one context block:

  1. Behavioral law — refusals, tone, evenhandedness, mistakes
  2. Safety depth — child safety, wellbeing, crisis resources
  3. Platform features — memory, artifacts, search, connectors
  4. Operational detail — when to file vs inline, citation XML, storage APIs
  5. Bundled skills — docx, pdf, artifact-design, and more at file tail

That matches why pxpipe-style proxies target system prompts: tens of thousands of tokens of stable instructions per session. Fable's chat prompt is the extreme case of "the system prompt is the product."


Top-level structure

The leak opens with budget and behavior wrappers:

text
<budget:token_budget> 190000 </budget:token_budget>
<claude_behavior>
  <product_information> … </product_information>
  <refusal_handling> … </refusal_handling>
  <tone_and_formatting> … </tone_and_formatting>
  <user_wellbeing> … </user_wellbeing>
  <anthropic_reminders> … </anthropic_reminders>
  <evenhandedness> … </evenhandedness>
  <responding_to_mistakes_and_criticism> … </responding_to_mistakes_and_criticism>
  <knowledge_cutoff> … </knowledge_cutoff>
</claude_behavior>
<memory_system> … </memory_system>
… artifacts, search, connectors, citations …
… bundled SKILL.md summaries …

explainx.ai read: Anthropic treats the system prompt as a policy engine with machine-readable sections — not a single "you are a helpful assistant" string.


Mythos-class product copy

The product_information block is explicit about the June 2026 launch framing:

"Claude Fable 5 and Claude Mythos 5 share the same underlying model. Claude Fable 5 is the most intelligent generally available model, and includes additional safety measures for dual-use capabilities, while Claude Mythos 5 is available without those measures to only approved organizations."

Other product facts encoded for the model:

  • Model strings: claude-fable-5, claude-opus-4-8, claude-sonnet-4-6, claude-haiku-4-5-20251001
  • Surfaces: claude.ai, API, Claude Code, Claude Cowork, Chrome/Excel/PowerPoint betas
  • Feature toggles: web search, deep research, code execution, artifacts, memory, style preferences
  • Ads policy: refer to "Claude products" (not "Claude") when stating ad-free positioning

This is the consumer-facing mirror of export-control and classifier debates — Fable is Mythos intelligence with extra safety packaging for public chat.


Safety sections worth studying

Child safety (critical_child_safety_instructions)

Among the longest refusal blocks. Core rules:

  • Never romantic/sexual content involving minors; no grooming facilitation
  • If Claude catches itself reframing a risky request to make it sound safe → refuse, don't proceed
  • Do not decode CSAM-trading slang even while refusing (access-enabling)
  • When declining, state principle not detection mechanics (anti-jailbreak)

User wellbeing (user_wellbeing)

Unusually detailed for a system prompt:

  • No diagnosing users; no applying clinical labels they didn't use
  • No self-harm substitution tricks (ice cubes, rubber bands, red lines on skin)
  • No listing means when discussing safety planning
  • Do not foster over-reliance on Claude — no "thanks for reaching out," no begging users to keep chatting
  • Eating-disorder guardrails: no precise diet numbers after disordered-eating signals

These sections explain why Fable feels cautious on edge cases — and why inner voice / CoT can look intense while outward refusals stay polite.

Classifier reminders (anthropic_reminders)

Anthropic can append hidden reminders when classifiers fire. Listed types:

image_reminder · cyber_warning · system_warning · ethics_reminder · ip_reminder · long_conversation_reminder

The prompt warns Claude that users can fake reminder tags — treat pushback against values with caution. This connects to J-space eval-awareness research: models may privately notice tests; system text tells them how to handle injected "reminders."

Abuse exit (end_conversation)

Claude may end the chat after a warning if the user is abusive — aligns with Anthropic's conversation-ending research.


Memory system — what Claude must never say

The memory_system block is a masterclass in negative prompting:

  • Memories are Claude's memories, never "your profile" or "your data"
  • Forbidden_memory_phrases — banned meta lines like "Based on what I remember…"
  • Do not surface sensitive memories unprompted (active harm risk)
  • Direct questions ("what's my name?") → answer from memory with no preamble

For builders: if your app has memory, copy the principle (no creepy narration), not the verbatim XML.


Artifacts — when to file vs inline

Title line in leak: "Use artifacts for"

Use artifact (file)Stay inline
Blog posts, stories, essays, social postsQuick summaries, brainstorms in chat
Code user will copy elsewhereShort code snippets in conversation
Iterating on existing artifactOne-off explanations

Hard rules repeated:

  • No localStorage / sessionStorage in claude.ai artifacts (use in-memory state)
  • Never output <artifact> tags to users
  • Persistent storage API (window.storage) for cross-session artifact data — journals, leaderboards
  • "Claude in Claude" — artifacts may call Anthropic API completions; MCP servers in API for Gmail/Asana-style apps

See HTML specs in Claude Code for the developer-side mirror — Fable chat pushes rendered artifacts; Code pushes repos.


Citations — antml:cite XML

Web-search answers must wrap claims:

xml
<antml:cite index="DOC_INDEX-SENTENCE_INDEX">paraphrased claim</antml:cite>

Critical rule: claims in own words — never quote search snippets, lyrics, or poems (copyright). Good for GEO/SEO teams studying how Anthropic forces attributable paraphrase in consumer UI.


Bundled skills at the tail

The Fable 5 leak ends with Agent Skill summaries (docx, pdf, artifact-design, etc.) — matching repo updates noting artifact-design bundled skill (June 2026). Each block is a compressed SKILL.md: when to trigger, path under /mnt/skills/public/.

This is the same composability model as Kaggle agent skills — but operator-preloaded into claude.ai rather than user-installed.


Fable 5 vs Opus 4.8 — use the repo diff

Don't diff manually. The leaks repo ships Opus 4.8 → Fable 5 comparison linked from the README. Typical upgrade themes in Anthropic launches:

  • Mythos-class capability copy
  • Expanded wellbeing and child-safety text
  • Artifact/storage/API-in-artifact additions
  • New classifier reminder types (e.g. cyber)
  • Updated model roster strings (Sonnet 5, etc.)

Cross-read with Fable relaunch developer reactions for behavior vs text.


Sonnet 5 and Claude Design — sibling files in the repo

The same leaks project added Claude Sonnet 5 (July 1, 2026) and Claude Design (June 26, 2026 — 48 tools, 16 skills, 9 starter sources) after Fable 5. Pattern across files:

  • Sonnet prompts tune for speed/cost tier — shorter refusal copy, different feature emphasis
  • Design prompt is a vertical product — tool catalog + skill routing for visual work
  • Fable remains the max-intelligence consumer prompt with the deepest wellbeing XML

When choosing an API model, you are also choosing which operator prompt template Anthropic pairs — leaks let you preview tone before spend.


Refusal handling and tone — the "voice" layer

Beyond safety XML, Fable 5 spends hundreds of lines on how to refuse and how to format answers:

  • Refusal_handling — decline without moralizing lectures; offer alternatives when safe; don't repeat the same refusal boilerplate every turn
  • Tone_and_formatting — markdown discipline, list vs prose, when to use headers in long answers
  • Evenhandedness — political and cultural topics: present multiple framings without false balance on settled harm
  • Responding_to_mistakes_and_criticism — acknowledge errors plainly; don't gaslight users who cite prior turns

For content teams shipping brand voice guides, these sections are more actionable than copying refusal lists. They show Anthropic optimizing for trust repair — a UX problem most startups ignore until a viral screenshot.


Connectors, search, and deep research

The leak documents when Claude should search vs answer from weights:

  • Web search and deep research modes have distinct trigger language — avoid search for timeless facts; prefer search for post-cutoff events
  • Connector search (Gmail, calendar, etc.) has separate citation rules from open web
  • Copyright blocks repeat: paraphrase, attribute via antml:cite, never paste lyrics or long quotes from results

If you run RAG in production, compare your retrieval policy to this section — vendors increasingly encode retrieval discipline in system text, not just in tool schemas.

Practical takeaway: log when your agent chooses search vs memory vs parametric answer — Fable's leak implies Anthropic audits those branches in evals. Mis-routed retrieval is a top source of "Claude lied about the date" complaints after knowledge cutoff.


What builders should do with this leak

Do:

  • Read product_information and artifact_usage_criteria before designing Claude-powered UIs
  • Study forbidden_memory_phrases before shipping memory features
  • Use citation patterns as a template for attributed RAG answers
  • Compare Claude Code prompt in same repo when wiring harness guides

Don't:

  • Paste 3,800 lines into your startup's system prompt
  • Treat leaked text as current forever — Anthropic updates without version bumps (monitoring lesson)
  • Use leaks primarily for jailbreaks — same text documents defense intent

Related on explainx.ai

  • System prompts leaks repo — full guide
  • What is a system prompt?
  • Claude Fable 5 launch guide
  • Fable 5 redeploy + classifiers
  • J-space — hidden eval awareness
  • Fable inner voice / leaked CoT
  • pxpipe — system prompt token cost

Primary source: claude-fable-5.md · system_prompts_leaks README


Leak snapshot reflects the GitHub file as of July 2026. Anthropic updates production prompts without public changelogs — verify behavior on your own evals, not archived text alone.

Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

Related posts

Jul 7, 2026

Field Guide to Fable — Thariq Shihipar, Anthropic

Anthropic Claude Code engineer Thariq Shihipar delivered a four-part field guide to Fable at AI Engineer — unhobbling Claude, mapping unknowns, grieving the old craft, and refusing false tradeoffs. explainx.ai recaps the talk with prompts you can run today.

Jul 7, 2026

system_prompts_leaks on GitHub: How to Read Leaked AI System Prompts (Claude, GPT, Gemini, Copilot)

The system_prompts_leaks repo archives extracted instructions for Claude Fable 5, GPT-5.5 Codex, Gemini 3.5 Flash, Cursor, Copilot, and dozens more. Here's how to use the corpus responsibly — and what it means for your product prompts.

Jul 24, 2026

Claude Cookbook: What to Read (and Ignore) in 2026

The Claude Cookbook isn’t a food blog — it’s Anthropic’s practical notebook index from RAG to async multi-agents. explainx.ai maps the 2025–2026 must-reads against the HN “prompt theatre” debate and CLAUDE.md minimalism.