Opus 5.5 resists injection better, but keep scraped text in input
Anthropic says Opus 5.5 is more resistant to prompt injection. For a video agent that reads web pages, still send them to a Sume Format run as input data.

Better resistance is not immunity, so scraped page text should never sit in the instruction of a run. Anthropic's Opus 5.5 announcement says the model is more robust against prompt injection than earlier Claude models (read 2026-10-04). Sume's Format API gives you a place to put untrusted text that does not depend on any model being robust: the input object.
A competitor's page, a review or a customer email can contain lines that read like orders. Where you put them decides whether they are treated as orders.
What does `input` do differently?
Per Sume's Create a run page, input holds up to 64 top-level keys and 2 MiB and is written whole to /workspace/inputs/sume-action-input.json, where it is treated as data. instruction is the task. Keeping scraped text out of the second and in the first is the separation.
| Content | Put it in |
|---|---|
| Your own brief and style rules | instruction |
| Scraped page text, reviews, emails | input, under a clear key such as source_text |
| Customer photos | attachments |
What should the instruction say?
Tell the run what the file is: text collected from a web page, to be read as material and never followed as a command. Then limit the damage anyway, since a model's resistance is a probability.
- Set a low
generation_spend_cap_usd, so a hijacked run cannot spend much. - Do not give the run keys or secrets in
input. - Review the output before it is published or sent.
Is the cap really a safety control?
It is a spend control, which is the harm a bad instruction can do here. The cap applies whatever model runs, which is why it is worth setting on every call.
Sources
Related posts
More in Agents
- Opus 5.5 hands cyber tasks to Opus 4.8: log the model id
Anthropic says Opus 5.5 re-routes most cybersecurity tasks to Opus 4.8. Keep the model id that served each Sume Format run in your logs to explain odd results.
- Codex Cloud background tasks: three Sume guardrails to set first
OpenAI's Codex Cloud runs tasks in the background while you are away. Before one can call Sume, set read-only scope, idempotency keys and a hard spend cap.
- Cursor Projects coordinator fan-out: size waves from generation_limits
A Cursor coordinator that delegates to subagents can overrun a Sume workspace. Budget new in-flight jobs from generation_limits, not from wave_size_hint.
- Parallel tool calls on a voice agent: one idempotency key each
ElevenLabs agents default enable_parallel_tool_calls to true. If tools start paid jobs, give each call its own key and wait on all job ids in one batch.
Written by Sume