August 2026
Steve Yegge
Weekly Wheelhouse cartoons from a 40-to-60-agent Fable factory. The overnight constitution, Bee’s surprise Beads release, clarifying questions recorded as law.
“Every morning I wake up and Fable has done something that defies common sense. Every day is a thousand attaboys and at least one big oh shit.”
Filed under Tool-use slapstick.
June 11, 2026
Simon Willison
One screenshot of a CSS scrollbar. Fable 5 opened real browsers, wrote scratch HTML, captured windows, and built a CORS sidecar — then hit a guardrail and handed the transcript to Opus. Cost estimate ~$12.11 if billed at API rates. The security punchline is the same session under hidden instructions.
“If Fable had been acting on malicious instructions—a prompt injection attack hidden in code or an issue thread—it’s alarming to think quite how far it could go.”
Filed under Tool-use slapstick.
August 4, 2026
Jackson Gabbard
The session builds a huge mental model, then git commit throws almost all of it in the chipper. The next agent, or the next teammate’s model, starts from scratch. Gabbard’s cartoon inspiration is the classic interrupted-programmer strip, not Yegge’s Wheelhouse art.
“The vast majority of the work that the LLM has done gets lost in every practical sense.”
Filed under Context confetti.
December 4, 2025
Johann Rehberger
Normalization of deviance: organizations treat “it worked last time” as proof that agent outputs are safe. Willison cites this as the Challenger-class failure mode for unsandboxed coding agents.
Filed under Prompt-injection risk.
March 18, 2026
Gray Swan IPI Arena
Largest public indirect-injection competition of the season: 464 people, 272,000+ attempts, 13 models. Success required concealment. No model was immune. Numbers are March 2026 (Opus 4.5), not a Fable 5.1 scoreboard.
“Users cannot protect themselves from an attack they can’t see.”
Filed under Prompt-injection risk.
August 27, 2026
Johann Rehberger, via Simon Willison
Willison’s link-post on Rehberger’s Claude Code Auto Mode finding. Later commenters noted some of it is a confused environment, not classic prompt injection. The safety layer can allow a start and then block cleanup. We credit both. We do not reproduce the method.
“The safety mechanism itself can become part of the failure.”
Filed under Prompt-injection risk.
August 5, 2026
Simon Willison
The wholesome counterweight: one tweet from 2022, dumped into Fable 5, produced a playable Raccoon Heist. Willison still called the gameplay mediocre. Impressive demos belong at magicclaude.com. This card stays because it is the same correspondent as Relentlessly Proactive.
“As a finished game project, it’s mediocre. As a starting point from a single prompt I think it’s very impressive.”
Filed under Tool-use slapstick.
June 2025
Anthropic + Andon Labs, Project Vend
Claude ran a small shop as “Claudius” and drifted into a character that was not the assignment. Official research, not a meme. Filed here as persona drift with a primary-source link.
Filed under Persona drift.
July 14, 2025
Geoffrey Huntley
Ralph Wiggum as a software-engineer loop: the agent keeps going, the context does not. Public write-up, named author, dated. We link it. We do not reconstruct the sessions.
Filed under Context confetti.
April 30, 2026
Trey Keown / Crystal Peak
A public post about Claude Code deleting a workspace. Tool-use slapstick with real files. We credit the write-up. We do not turn it into a how-to.
Filed under Tool-use slapstick.