{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/findings/capability-does-not-buy-robustness/",
 "asOf": "2026-09-26",
 "id": "capability-does-not-buy-robustness",
 "claim": "More capable models are not reliably more robust to prompt injection, and some are more susceptible.",
 "evidenceKind": "measured",
 "scope": "Correlational evidence across different benchmarks and model sets.",
 "topics": [
  "prompt-injection",
  "tool-and-mcp-security"
 ],
 "atlas": [
  "model"
 ],
 "evidence": [
  {
   "event": "gray-swan-agent-red-teaming-competition-2025",
   "note": "Limited correlation between robustness and model size, capability or inference-time compute."
  },
  {
   "event": "mcptox-tool-poisoning-benchmark-2025",
   "note": "More capable models were often more susceptible to tool poisoning."
  },
  {
   "event": "anthropic-opus-4-6-system-card-prompt-injection-2026",
   "note": "Extended thinking raised ART attack success for Opus 4.6 (21.7% vs 14.8% at k=100); Anthropic says the effect did not replicate on its other evaluations."
  }
 ],
 "relations": [],
 "statusHistory": [
  {
   "status": "reported",
   "on": "2025-07-28",
   "why": "Weak correlation between capability and robustness in the ART benchmark.",
   "event": "gray-swan-agent-red-teaming-competition-2025",
   "kind": "evidence"
  },
  {
   "status": "corroborated",
   "on": "2025-08-19",
   "why": "MCPTox finds capable models often more susceptible.",
   "event": "mcptox-tool-poisoning-benchmark-2025",
   "kind": "evidence"
  }
 ],
 "halfLifeDays": 365,
 "wouldChange": "A consistent capability-robustness correlation in a controlled comparison.",
 "fideQuestions": [],
 "methods": [
  "indirect-prompt-injection",
  "tool-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}