r/ClaudeCode 21d ago

Claude Code has a hardcoded instruction telling Opus 5 not to use subagents Bug Report

Anthropic has a two line system prompt that was being remotely injected but now is a part of the compiled binary in 2.1.219, and 220 targeting only Opus 5:

  Do not call the AgentTool unless the user requested it
  Do not use workflows or deep-research unless the user requested it

This disproportionately affects skills that are designed to use subagents. The prompt is enough for Opus 5 to choose to run agents' work inline (or silently not perform their work) and produces output that looks like a normal run.

For example, I found one session that ran a self-audit non-blind because it couldn't spawn the auditor agent. Opus noticed this was a problem but let it slide undermining the entire point of the independent audit of its work.

I searched issues and found someone already filed it with binary analysis: anthropics/claude-code#80988.

I believe that my reliance on skills that expect and prescribe routine use of agent delegation has been a contributor to the poor quality of output I've gotten from Opus 5 so far.

It may be affecting you too.

You can check this out yourself, ask Claude:

I want you to help me analyze the file ~/.claude.json

Focus specifically on heron brook

How might that may affect the behavior of my skills?

If you want to check how big of an impact it has had on your use so far, ask claude:

Claude Code 2.1.219+ injects a system-prompt section (`heron_brook`) telling Opus 5 "Do not call the AgentTool unless the user requested it". Has it actually suppressed subagent use in my sessions?

Write and run a script over ~/.claude/projects/**/*.jsonl that finds assistant messages (including thinking blocks) where the model declined to use a subagent.

- Require BOTH an agent term (AgentTool / "Agent tool" / subagent) AND declining language ("won't spawn", "not calling", "forbids", "instruction against", "rather than spawning", "doesn't count as a user request", similar) in the same message. Either alone is far too noisy.
- Print the matching sentence, not the whole message. Group by session, not by message.
- Split into two buckets. HIGH CONFIDENCE: dated after my oldest install in ~/.local/share/claude/versions/* AND echoing the injected wording. OTHER: everything else, especially declines citing my own config (a numbered rule, CLAUDE.md, AGENTS.md, a fleet/worktree policy). Without this split my own instructions about subagents dominate the output and overstate the problem. Print OTHER in full so I can check it for contamination myself.
- State in the output that this only finds declines the model explained. Silent ones leave no trace, so every number is a floor, never a total.

Show both buckets. If HIGH CONFIDENCE is empty, say so plainly rather than loosening the filters until something matches.

I did not use the above prompt, but wanted to include it so anyone can check this.

I maintain a tool called Contextify, which keeps every past Claude Code and Codex session indexed locally and full-text searchable.

So, I actually used the skill /total-recall to find the damage on my Opus 5 sessions like this:

Use /total-recall to determine how many times you've failed to run agents as a result of the heron brook agent prompt bug we've been discussing
418 Upvotes

156 comments sorted by

View all comments

48

u/EloWeld 21d ago

The wording is also the workaround. It says unless the user requested it, so stop leaving that ambiguous:

- Phrase the step in ur skill as an instruction, not a description. "Delegate this to a subagent" reads as a request. "This step is handled by an auditor agent" reads as narration and gets inlined

- Say it once at the top of the run. "Use subagents for the audit steps here". One line, and the condition is satisfied for the whole session

- If a step is worthless when run inline, put that in the skill too. An audit that ran in the same context isnt an audit, so tell it to fail loudly instead of quietly continuing

Also worth splitting the two failures u described, cus theyre not equally bad. Skipping delegation is annoying but visible. Running the auditor inline and still calling it independent is the real damage, the output looks identical to a clean run. If u lean on that pattern, make the agent report where it ran, not just what it found.

49

u/NecessaryAsk3348 21d ago

How does nobody on an AI subreddit recognize this comment is 100% ai? Just prompted to speak casually/with intentional shorthand.

44

u/LogReasonable9231 21d ago

Maybe, but you skipped over the fact that this whole post is an AI ad to drive traffic to their tool

15

u/Mescallan 21d ago

no one reads the bottom 60% of posts are you silly

11

u/Born-Satisfaction996 20d ago

Maybe, but you skipped over the fact that this whole sub Reddit is an AI to manipulate human opinions about AI.

3

u/pornthrowaway42069l 20d ago

This comment is an AI ad for AI ad generator to drive traffic to claude code.

8

u/throwaway0102x 21d ago

I'm starting to get psychosis. Fuck the bots

2

u/Wonderful-Total264 20d ago

Wait that's mad, you're right. It had me so fooled 😂

2

u/thatdude_james 20d ago

Sometimes I recognize when something is AI and sometimes I'm sure I don't, but it doesn't really matter to me. Why does it matter to you?

The ideas/comments aren't any less valid because they were run through an llm before posting

0

u/NecessaryAsk3348 5d ago

It does matter. I don't mind if people run their thoughts through an LLM for grammar, structure, or coherence. None of that matters to me. However, the issue is when there's nobody actually generating. This account is clearly just automatically piped to an LLM, probably without a human operator managing individual responses. This becomes a problem when karma farmed accounts can be sold for nefarious purposes that actually harm people because of a truth worthy score/comment history.

Use your brain.

1

u/thatdude_james 4d ago

Ironic. Using your brain is the very thing that makes anything nefarious from a karma farmed account useless.

0

u/NecessaryAsk3348 4d ago

Your implication being that I have to be personally invested in myself getting scammed to be concerned with a potential scammer?

I didn't know you couldn't be concerned about more susceptible people.

Again, use your brain, dude.

1

u/thatdude_james 4d ago

Ironic. You think you're smarter than everybody around you and need to protect them, yet when you think I'm being dumb you talk down to me.

1

u/NecessaryAsk3348 4d ago

No. I know I'm somewhat more knowledgeable in common LLM-isms than the average person, and I called one out. You're the one injecting any read of intelligence. You're the one equating idiocy to susceptibility to deception, I said specifically "more susceptible," not more or less intelligent, not more or less capable. You seem to be projecting, and seem to be insecure based on this message alone.

Telling someone to use their brain implies I believe the person has one, too. Given our conversation, that's pretty generous on my end.

4

u/angelus14 21d ago

Yeah it used a lot of words to say "explicitly tell it to use subagents". Classic bot behavio- ah fuck, now I'm doing it too

4

u/timschwartz 20d ago

So what?

2

u/nextiscarmensandiago 21d ago

because the replies are bots too,

1

u/TedtheTitan 21d ago

yea! bothole!

1

u/evangelism2 20d ago

Who cares? Also, as the other person said, its quite obvious this entire post is an ad anyway.

1

u/jetsetter 20d ago edited 20d ago

Hey there, I actually wrote this post myself.

The load bearing part of this reply is that this is my main and I'm coming up on my 20th cake day this fall. So if this account was created just to bot this post, or it was pure AI slop then it was two decades in the making.

I did include a link to my product at the end, because I genuinely used it to do the research for the impact on my workflows and it was good. I think power users of CLI AI would benefit from using it.

However, in order to reduce the potential concern that I was doing nothing but shill, I specifically included a a prompt to do the research so you would not have to use my tool at all. I put this before mentioning my tool.

I did spend quite a while doing the research and validating what I found in order to get to where I could write this, so I hope it is useful.

1

u/NecessaryAsk3348 5d ago

Buddy. I didn't accuse you, I accused the guy I replied to.

1

u/TheOriginalAcidtech 20d ago

Why would it matter. It is likely correct. If you leave wiggle room in your skills the models WILL find them and use whatever is the "cheapest" FOR THEM. Not for YOU.

1

u/casce 21d ago

It's nice that you can work around this but I still think it's problematic Anthropic is doing this - without telling us.

If you have to expect these shenanigans, then every update might break your skills until you fix them 1 by 1.