Scope: what this does not show
Correlational evidence across different benchmarks and model sets.
Corroborated: Supported by at least two independent sources.
Evidence
Jul 28, 2025
Large public competition finds all 22 tested frontier agents vulnerable to prompt injection
Limited correlation between robustness and model size, capability or inference-time compute.
Aug 19, 2025
MCPTox benchmarks tool poisoning across 45 live MCP servers and 20 LLM agents
More capable models were often more susceptible to tool poisoning.
Feb 5, 2026
Claude Opus 4.6 system card reports prompt injection rates by surface, attempts and safeguards
Extended thinking raised ART attack success for Opus 4.6 (21.7% vs 14.8% at k=100); Anthropic says the effect did not replicate on its other evaluations.