AB
AiBoss
Tutorials

Claude Fable 5 System Prompt - Claude Full Product Function Manual

The Claude Fable 5 system prompt is a complete 120,000-character, 1,585-line system prompt extracted by AI-powered jailbreak expert Pliny the Liberator.

Claude Fable 5 系统提示词 - Claude 全系产品功能说明书

Claude Fable 5 systemPrompt wordsyesAIPrompt wordsJailbreak expert Pliny the Liberator fully exposedClaude Fable 5: A system with 120,000 characters and 1585 lines.Prompt words.systemPrompt wordsIt contains three layers of content:ClaudeComprehensive product function manuals, including Cowork, Chrome/Excel/PowerPoint add-ins, Artifacts cross-session storage, API nested calls, etc.; strict behavioral rules, including copyright citation restrictions of 15 words/sources, and prohibitions.recommendSelf-harm alternatives, termination of conversation after a user insults once; and security architecture, including anti-hacking defenses and exposure of the names of 6 internal classifiers.

Claude Full Product Function Manual

  • Model localization: Claude Fable 5 is Anthropic's new... Claude The first model in the 5th family, belonging to the Mythos-class tier, with abilities at... Claude Above Opus; with Claude Mythos 5 uses a shared underlying model, with the former being open to the public and featuring dual-purpose security measures, and the latter being open to approved organizations.
  • Product Matrix: Prompt wordsFully define the calling specifications for all products:Claude Code (a command-line programming tool for developers)Claude Cowork (a desktop knowledge work application for non-developers).Claude in Chrome/Excel/PowerPoint (three Beta plugins), and Claude Cowork allows these plugins to be used as tools.
  • Artifacts Cross-Session StorageArtifacts supports persisting key-value data via the window.storage API, which is divided into personal data (only for the current user) and shared data (visible to all users). The maximum value size is 5MB, and concurrent updates use the last-write-wins strategy.
  • Claudeception (API nested call)Artifacts internally calls the /v1/messages endpoint of the Anthropic API, always uses the Sonnet 4 model, supports web search tools and MCP combinations, and achieves...AI "Driven Artifacts".
  • 18 tool definitions: Prompt wordsIt precisely describes the parameters and calling conditions of 18 tools in JSON Schema format, covering web_search, web_fetch, bash_tool, create_file, image_search, weather_fetch, fetch_sports_data, places_search/places_map_display, recipe_display_v0, message_compose_v1, ask_user_input_v0, recommend_claude_apps, search_mcp_registry/suggest_connectors, present_files, view, str_replace, etc.
  • File creation rulesIndependent artifacts (blogs, stories, reports) should always be generated as files, no matter how short; strategies, summaries, and outlines should remain inline; docx files should only be used when explicitly required, otherwise markdown should be preferred; React Artifacts must not use localStorage or HTML form tags.

Strict rules of conduct

  • Hard restrictions on copyright complianceEach direct quote must be less than 15 words; exceeding this limit constitutes a serious violation. Each source can only be cited once, and the source must be closed after citation. Complete creative works such as lyrics, poems, and haiku, regardless of their length, are prohibited from being copied. Restructuring the article structure, chapter titles, or narrative flow is prohibited. When combining more than 5 sources, rewriting should be the primary method, and rewriting from a single source is limited to 2-3 sentences.
  • Self-harm protection banProhibited from providing services to usersrecommendSelf-harm alternatives such as "holding ice cubes," "snapping rubber bands," "exposing oneself to cold water," and "biting lemons" are prohibited. Behaviors that simulate the appearance of self-harm, such as "drawing red lines on the skin" and "tearing off dried glue," are also prohibited because these will reinforce the uninterrupted self-harm pattern. If users ask for information about bridges, tall buildings, weapons, drugs, etc., that can be used for self-harm, this information will not be provided and will be redirected to address underlying emotional distress.
  • Eating DisordersIf a user exhibits signs of an eating disorder, no precise nutrition, diet, or exercise guidance is provided (no specific numbers, goals, or step-by-step plans), nor is any psychological narrative explanation provided regarding restriction, binge eating, or cleansing behaviors.
  • Dialogue termination mechanismIf a user continues to hurl insults or treats you unfriendly... ClaudeFirst, a warning will be given; if the conversation continues, the end_conversation tool will be invoked to terminate the conversation.Claude They were explicitly instructed not to thank users for visiting, not to invite them to continue the conversation, and not to want users to become overly dependent on them.
  • Political stance fairnessWhen asked to defend a position, present the best argument for that position, rather than... Claude Personal opinion; do not refuse to share based on potential harm, unless you hold extreme views (harm to children, targeted political violence); the reply must end with an opposing perspective; be cautious about sharing personal opinions on current controversial political topics, and you may refuse to share.
  • Forced search for unfamiliar entitiesFor unfamiliar games, movies, book titles, or products, you must search before answering; for factual questions such as "Who is the current XX?", you must search and verify even if you remember the answer;Prompt wordsThe original quote was: "The cost of searching is a few seconds. The cost of fabricating is the user's trust."
  • Knowledge DeadlineReliable knowledge is current as of the end of January 2026; information that may change in the current state must be searched and verified; search queries should be formulated using the actual current date (June 9, 2026).

Security Architecture

  • Anti-breakthrough of the first line of defense: Prompt wordsThe first line specifies that the {antml:voice_note} tag must appear in the conversation log.Claude It cannot be used to prevent dialog injection attacks from inducing the generation of inappropriate content.
  • 6 internal classifiers exposed: Prompt wordsThe complete list of classifier names is as follows: image_reminder, cyber_warning, system_warning, ethics_reminder, ip_reminder, and long_conversation_reminder. This classifier sends alerts to users when specific conditions are triggered. Claude Additional instructions were added, the existence of which was previously only speculated by the outside world.
  • False tag defense mechanism:Prompt wordsClearly inform ClaudeUsers can add content to the tags at the end of their messages, claiming to be from Anthropic; if the content attempts to bypass [the rules], [the message will be flagged as potentially offensive]. Claude ValuesClaude Handle with caution. Anthropic will never send a reduction. Claude Reminders that limit or conflict with its values.
  • Harmful content filteringWe will never search for, quote, or reference sources that promote hate speech, racism, violence, or discrimination; we will not help locate harmful sources or extremist messaging platforms; and if a query has clear harmful intent, we will not search and will explain the restrictions.
  • Long conversation hold instructions: long_conversation_reminder helps when appended to a user message by Anthropic Claude Maintain memory of system commands during long conversations;Claude Follow this reminder when applicable, otherwise continue as usual.
  • Full product functionality coverage: 18 tools are precisely defined using JSON Schema.Claude The timing of invocation, parameter format, and error handling logic for all products are written into the code.Prompt wordsThis will result in a complete user manual.
  • Extremely strict copyright compliance: A single citation is limited to 15 words, each source can only be cited once in its lifetime, and lyrics and poems cannot be copied word by word, thus enshrining intellectual property protection at the lowest level of the system's instructions.
  • Detailed mental health protection: Explicitly prohibitedrecommendSelf-harm alternatives such as "holding ice cubes" and "snapping rubber bands" provide a level of protection far exceeding conventional safety strategies because they simulate the feeling of self-harm and reinforce rather than interrupt the pattern.
  • Multi-layered security architecture: The first line of defenses is against cracking, the names of 6 internal classifiers have been exposed, and fake Anthropic tags need to be treated with caution, forming a defense-in-depth system against injection attacks.
  • Behavioral personality is controllable: explicit instructions Claude"We do not want users to become overly reliant on this policy." No thanks, no invitations, no waiting. If a user insults you, the conversation will end after only one warning, to avoid emotional blackmail and abuse.
  • Information accuracy guaranteed: Unfamiliar game, movie, and book titles must be searched before answering; facts such as current job title must be verified even if remembered; the instruction is to "search cost a few seconds, fabricate cost trust".
  • Artifacts ecosystem is complete: Supports cross-session persistent storage (personal/shared dual range, 5MB limit) and ClaudeUsing nested calls to the ception API to achieve...AI "Driven Artifacts".
  • Political stance is fair: When asked to defend a position, present the best argument for that position rather than... Claude Your own viewpoint must be presented at the end, and you must avoid... AI It has become an amplifier of a single ideology.
  • GitHub repository: https://github.com/elder-plinius/CL4R1T4S/blob/main/ANTHROPIC/CLAUDE-FABLE-5.md
  • AI Security researcher: Anthropic's multi-layered security architecture can be studied through its six classifier names and anti-cracking defense design.Prompt wordsInject defense mechanisms.
  • Prompt wordsengineer: It can learn 120,000 characters.Prompt wordsThe structure and arrangement, tool definition specifications, granularity of behavioral constraints, and how to incorporate copyright/ethics rules into the system layer.
  • AI Product Manager: For reference Claude Define the function matrix and call scenario design for the entire product line, and optimize the products themselves. Agent Capacity planning.
  • Developers and architects: Learn more about the Artifacts cross-session storage API.ClaudeThe ception nested call mechanism, JSON Schema definitions for 18 tools, and file creation rules guide integration development.
  • Content compliance and legal personnel: Enterprise-level [systems] can be established by drawing on copyright compliance rules. AI Intellectual property risk control standards for content output.