explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsdictionaryagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

On this page

  • TL;DR — Fable 5 prompt at a glance
  • Why the Fable 5 prompt is enormous
  • Top-level structure
  • Mythos-class product copy
  • Safety sections worth studying
  • Memory system — what Claude must never say
  • Artifacts — when to file vs inline
  • Citations — antml:cite XML
  • Bundled skills at the tail
  • Fable 5 vs Opus 4.8 — use the repo diff
  • Sonnet 5 and Claude Design — sibling files in the repo
  • Refusal handling and tone — the "voice" layer
  • Connectors, search, and deep research
  • What builders should do with this leak
  • Related on explainx.ai
← Back to blog

explainx / blog

Claude Fable 5 System Prompt Leak: What's Inside Anthropic's 3,800-Line claude.ai Instructions

The full Claude Fable 5 system prompt leaked on GitHub (asgeirtj/system_prompts_leaks). Mythos vs Fable, child-safety XML blocks, memory rules, artifacts, cyber_warning — explained.

Jul 7, 2026·9 min read·Yash Thakker
Claude Fable 5System PromptAnthropicPrompt EngineeringAI Safety
go deep
Claude Fable 5 System Prompt Leak: What's Inside Anthropic's 3,800-Line claude.ai Instructions

In July 2026, builders still treat asgeirtj/system_prompts_leaks as the phone book for how frontier chatbots are actually configured. The repo crossed 51.5K GitHub stars, was cited in The Washington Post (May 2026), and ships under CC0-1.0 — meaning the archived text is public documentation, not a hack.

The headline file for Anthropic right now is Anthropic/claude-fable-5.md: the claude.ai system prompt for Claude Fable 5, captured at roughly 3,800 lines of XML-tagged operator instructions. The repo also publishes a diff versus Claude Opus 4.8 — the fastest way to see what changed when Anthropic moved to the Mythos-class tier.

This post is a map of that file for developers who will never read every line — and what it implies for safety, artifacts, and prompt engineering in 2026.

Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.


TL;DR — Fable 5 prompt at a glance

table · 2 cols
QuestionAnswer
Sourceclaude-fable-5.md on system_prompts_leaks
Length~3,800 lines; token_budget tag shows 190,000 in snapshot
FormatNested XML tags (<claude_behavior>, <memory_system>, …)
Model identityFable 5 = Claude 5 family; same weights as Mythos 5, different safety packaging
Knowledge cutoffEnd of Jan 2026; leak snapshot hard-codes Tuesday, June 9, 2026 as "today"
Big themesChild safety, mental-health guardrails, memory phrasing bans, artifacts + skills, citations
Classifier hookscyber_warning, ethics_reminder, image_reminder, long_conversation_reminder, …
Not in this fileClaude Code agent prompt (separate leak in same repo)
Use responsiblyStudy and defend — do not paste wholesale into your app

Why the Fable 5 prompt is enormous

Consumer chat prompts used to be a paragraph of persona. Fable 5's leak reflects product + policy + tools + skills in one context block:

  1. Behavioral law — refusals, tone, evenhandedness, mistakes
  2. Safety depth — child safety, wellbeing, crisis resources
  3. Platform features — memory, artifacts, search, connectors
  4. Operational detail — when to file vs inline, citation XML, storage APIs
  5. Bundled skills — docx, pdf, artifact-design, and more at file tail

That matches why pxpipe-style proxies target system prompts: tens of thousands of tokens of stable instructions per session. Fable's chat prompt is the extreme case of "the system prompt is the product."


Top-level structure

The leak opens with budget and behavior wrappers:

text
<budget:token_budget> 190000 </budget:token_budget>
<claude_behavior>
  <product_information> … </product_information>
  <refusal_handling> … </refusal_handling>
  <tone_and_formatting> … </tone_and_formatting>
  <user_wellbeing> … </user_wellbeing>
  <anthropic_reminders> … </anthropic_reminders>
  <evenhandedness> … </evenhandedness>
  <responding_to_mistakes_and_criticism> … </responding_to_mistakes_and_criticism>
  <knowledge_cutoff> … </knowledge_cutoff>
</claude_behavior>
<memory_system> … </memory_system>
… artifacts, search, connectors, citations …
… bundled SKILL.md summaries …

explainx.ai read: Anthropic treats the system prompt as a policy engine with machine-readable sections — not a single "you are a helpful assistant" string.


Mythos-class product copy

The product_information block is explicit about the June 2026 launch framing:

"Claude Fable 5 and Claude Mythos 5 share the same underlying model. Claude Fable 5 is the most intelligent generally available model, and includes additional safety measures for dual-use capabilities, while Claude Mythos 5 is available without those measures to only approved organizations."

Other product facts encoded for the model:

  • Model strings: claude-fable-5, claude-opus-4-8, claude-sonnet-4-6, claude-haiku-4-5-20251001
  • Surfaces: claude.ai, API, Claude Code, Claude Cowork, Chrome/Excel/PowerPoint betas
  • Feature toggles: web search, deep research, code execution, artifacts, memory, style preferences
  • Ads policy: refer to "Claude products" (not "Claude") when stating ad-free positioning

This is the consumer-facing mirror of export-control and classifier debates — Fable is Mythos intelligence with extra safety packaging for public chat.


Safety sections worth studying

Child safety (critical_child_safety_instructions)

Among the longest refusal blocks. Core rules:

  • Never romantic/sexual content involving minors; no grooming facilitation
  • If Claude catches itself reframing a risky request to make it sound safe → refuse, don't proceed
  • Do not decode CSAM-trading slang even while refusing (access-enabling)
  • When declining, state principle not detection mechanics (anti-jailbreak)

User wellbeing (user_wellbeing)

Unusually detailed for a system prompt:

  • No diagnosing users; no applying clinical labels they didn't use
  • No self-harm substitution tricks (ice cubes, rubber bands, red lines on skin)
  • No listing means when discussing safety planning
  • Do not foster over-reliance on Claude — no "thanks for reaching out," no begging users to keep chatting
  • Eating-disorder guardrails: no precise diet numbers after disordered-eating signals

These sections explain why Fable feels cautious on edge cases — and why inner voice / CoT can look intense while outward refusals stay polite.

Classifier reminders (anthropic_reminders)

Anthropic can append hidden reminders when classifiers fire. Listed types:

image_reminder · cyber_warning · system_warning · ethics_reminder · ip_reminder · long_conversation_reminder

The prompt warns Claude that users can fake reminder tags — treat pushback against values with caution. This connects to J-space eval-awareness research: models may privately notice tests; system text tells them how to handle injected "reminders."

Abuse exit (end_conversation)

Claude may end the chat after a warning if the user is abusive — aligns with Anthropic's conversation-ending research.


Memory system — what Claude must never say

The memory_system block is a masterclass in negative prompting:

  • Memories are Claude's memories, never "your profile" or "your data"
  • Forbidden_memory_phrases — banned meta lines like "Based on what I remember…"
  • Do not surface sensitive memories unprompted (active harm risk)
  • Direct questions ("what's my name?") → answer from memory with no preamble

For builders: if your app has memory, copy the principle (no creepy narration), not the verbatim XML.


Artifacts — when to file vs inline

Title line in leak: "Use artifacts for"

table · 2 cols
Use artifact (file)Stay inline
Blog posts, stories, essays, social postsQuick summaries, brainstorms in chat
Code user will copy elsewhereShort code snippets in conversation
Iterating on existing artifactOne-off explanations

Hard rules repeated:

  • No localStorage / sessionStorage in claude.ai artifacts (use in-memory state)
  • Never output <artifact> tags to users
  • Persistent storage API (window.storage) for cross-session artifact data — journals, leaderboards
  • "Claude in Claude" — artifacts may call Anthropic API completions; MCP servers in API for Gmail/Asana-style apps

See HTML specs in Claude Code for the developer-side mirror — Fable chat pushes rendered artifacts; Code pushes repos.


Citations — antml:cite XML

Web-search answers must wrap claims:

xml
<antml:cite index="DOC_INDEX-SENTENCE_INDEX">paraphrased claim</antml:cite>

Critical rule: claims in own words — never quote search snippets, lyrics, or poems (copyright). Good for GEO/SEO teams studying how Anthropic forces attributable paraphrase in consumer UI.


Bundled skills at the tail

The Fable 5 leak ends with Agent Skill summaries (docx, pdf, artifact-design, etc.) — matching repo updates noting artifact-design bundled skill (June 2026). Each block is a compressed SKILL.md: when to trigger, path under /mnt/skills/public/.

This is the same composability model as Kaggle agent skills — but operator-preloaded into claude.ai rather than user-installed.


Fable 5 vs Opus 4.8 — use the repo diff

Don't diff manually. The leaks repo ships Opus 4.8 → Fable 5 comparison linked from the README. Typical upgrade themes in Anthropic launches:

  • Mythos-class capability copy
  • Expanded wellbeing and child-safety text
  • Artifact/storage/API-in-artifact additions
  • New classifier reminder types (e.g. cyber)
  • Updated model roster strings (Sonnet 5, etc.)

Cross-read with Fable relaunch developer reactions for behavior vs text.


Sonnet 5 and Claude Design — sibling files in the repo

The same leaks project added Claude Sonnet 5 (July 1, 2026) and Claude Design (June 26, 2026 — 48 tools, 16 skills, 9 starter sources) after Fable 5. Pattern across files:

  • Sonnet prompts tune for speed/cost tier — shorter refusal copy, different feature emphasis
  • Design prompt is a vertical product — tool catalog + skill routing for visual work
  • Fable remains the max-intelligence consumer prompt with the deepest wellbeing XML

When choosing an API model, you are also choosing which operator prompt template Anthropic pairs — leaks let you preview tone before spend.


Refusal handling and tone — the "voice" layer

Beyond safety XML, Fable 5 spends hundreds of lines on how to refuse and how to format answers:

  • Refusal_handling — decline without moralizing lectures; offer alternatives when safe; don't repeat the same refusal boilerplate every turn
  • Tone_and_formatting — markdown discipline, list vs prose, when to use headers in long answers
  • Evenhandedness — political and cultural topics: present multiple framings without false balance on settled harm
  • Responding_to_mistakes_and_criticism — acknowledge errors plainly; don't gaslight users who cite prior turns

For content teams shipping brand voice guides, these sections are more actionable than copying refusal lists. They show Anthropic optimizing for trust repair — a UX problem most startups ignore until a viral screenshot.


Connectors, search, and deep research

The leak documents when Claude should search vs answer from weights:

  • Web search and deep research modes have distinct trigger language — avoid search for timeless facts; prefer search for post-cutoff events
  • Connector search (Gmail, calendar, etc.) has separate citation rules from open web
  • Copyright blocks repeat: paraphrase, attribute via antml:cite, never paste lyrics or long quotes from results

If you run RAG in production, compare your retrieval policy to this section — vendors increasingly encode retrieval discipline in system text, not just in tool schemas.

Practical takeaway: log when your agent chooses search vs memory vs parametric answer — Fable's leak implies Anthropic audits those branches in evals. Mis-routed retrieval is a top source of "Claude lied about the date" complaints after knowledge cutoff.


What builders should do with this leak

Do:

  • Read product_information and artifact_usage_criteria before designing Claude-powered UIs
  • Study forbidden_memory_phrases before shipping memory features
  • Use citation patterns as a template for attributed RAG answers
  • Compare Claude Code prompt in same repo when wiring harness guides

Don't:

  • Paste 3,800 lines into your startup's system prompt
  • Treat leaked text as current forever — Anthropic updates without version bumps (monitoring lesson)
  • Use leaks primarily for jailbreaks — same text documents defense intent

Related on explainx.ai

  • Update — Aug 16, 2026: ZCode's leaked skills playbooks reuse the same docx skill framing described here — 391,439-character ZCode leak: Claude Code DNA inside GLM-5.3's harness.
  • System prompts leaks repo — full guide
  • What is a system prompt?
  • Claude Fable 5 launch guide
  • Fable 5 redeploy + classifiers
  • J-space — hidden eval awareness
  • Fable inner voice / leaked CoT
  • pxpipe — system prompt token cost

Primary source: claude-fable-5.md · system_prompts_leaks README


Leak snapshot reflects the GitHub file as of July 2026. Anthropic updates production prompts without public changelogs — verify behavior on your own evals, not archived text alone.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

Related posts

Jul 7, 2026

Field Guide to Fable — Thariq Shihipar, Anthropic

Anthropic Claude Code engineer Thariq Shihipar delivered a four-part field guide to Fable at AI Engineer — unhobbling Claude, mapping unknowns, grieving the old craft, and refusing false tradeoffs. explainx.ai recaps the talk with prompts you can run today.

Jul 7, 2026

system_prompts_leaks on GitHub: How to Read Leaked AI System Prompts (Claude, GPT, Gemini, Copilot)

The system_prompts_leaks repo archives extracted instructions for Claude Fable 5, GPT-5.5 Codex, Gemini 3.5 Flash, Cursor, Copilot, and dozens more. Here's how to use the corpus responsibly — and what it means for your product prompts.

Aug 16, 2026

Anthropic's Model 2: Built, Beats Mythos 5, Not Being Released

Buried inside Anthropic's August 2026 Risk Report is a disclosure that didn't get its own announcement: an internal model called Model 2 already beats Claude Mythos 5 on Anthropic's own coding benchmark, and the company says it has no plans to release it externally — not because it's too dangerous, but because it hasn't finished checking.