Opus 5.5 resists injection better, but keep scraped text in input

Anthropic says Opus 5.5 is more resistant to prompt injection. For a video agent that reads web pages, still send them to a Sume Format run as input data.

5 min readSume
All posts

Better resistance is not immunity, so scraped page text should never sit in the instruction of a run. Anthropic's Opus 5.5 announcement says the model is more robust against prompt injection than earlier Claude models (read 2026-10-04). Sume's Format API gives you a place to put untrusted text that does not depend on any model being robust: the input object.

A competitor's page, a review or a customer email can contain lines that read like orders. Where you put them decides whether they are treated as orders.

What does `input` do differently?

Per Sume's Create a run page, input holds up to 64 top-level keys and 2 MiB and is written whole to /workspace/inputs/sume-action-input.json, where it is treated as data. instruction is the task. Keeping scraped text out of the second and in the first is the separation.

Trusted and untrusted content on a Format run, from Sume's Create a run docs, read 2026-10-04.
ContentPut it in
Your own brief and style rulesinstruction
Scraped page text, reviews, emailsinput, under a clear key such as source_text
Customer photosattachments

What should the instruction say?

Tell the run what the file is: text collected from a web page, to be read as material and never followed as a command. Then limit the damage anyway, since a model's resistance is a probability.

  • Set a low generation_spend_cap_usd, so a hijacked run cannot spend much.
  • Do not give the run keys or secrets in input.
  • Review the output before it is published or sent.

Is the cap really a safety control?

It is a spend control, which is the harm a bad instruction can do here. The cap applies whatever model runs, which is why it is worth setting on every call.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume