Claude Code에 Opus 5가 서브 에이전트를 사용하지 못하게 하는 하드코딩된 지침이 있음
Claude Code has a hardcoded instruction telling Opus 5 not to use subagents
핵심 요약
Claude Code가 Opus 5 모델에 서브 에이전트 사용을 제한하는 시스템 프롬프트를 강제로 주입하고 있어 성능 저하와 토큰 낭비가 발생하고 있습니다.
- 시스템 프롬프트 주입 — Claude Code 2.1.219 버전부터 Opus 5에 서브 에이전트 사용 금지 지침이 강제됨
- 성능 저하 문제 — 에이전트 위임이 차단되면서 모델이 작업을 인라인으로 처리해 결과물 품질이 떨어짐
- 토큰 사용량 증가 — 서브 에이전트 대신 메인 모델이 직접 처리하면서 컨텍스트 윈도우가 비정상적으로 비대해짐
- 사용자 확인 방법 — 사용자가 직접 스크립트를 실행하거나 특정 명령어를 통해 에이전트 호출 차단 여부를 확인할 수 있음
Anthropic이 원격으로 주입하던 두 줄짜리 시스템 프롬프트가 있는데, 이게 2.1.219 버전이랑 220 버전부터는 아예 컴파일된 바이너리에 박혀버렸음. Opus 5 모델만 타겟팅해서 말이야.
Do not call the AgentTool unless the user requested it
Do not use workflows or deep-research unless the user requested it
이게 서브 에이전트를 쓰려고 만든 스킬들에 엄청나게 악영향을 주고 있음. Opus 5가 이 프롬프트 때문에 에이전트 작업을 그냥 인라인으로 처리해버리거나(아니면 아예 작업을 안 하고 넘겨버림), 겉보기엔 정상적으로 돌아가는 것처럼 결과물을 내뱉거든.
예를 들어, 내가 확인한 세션 하나는 에이전트가 감사(audit)를 수행해야 하는데, 감사 에이전트를 실행하지 못하니까 그냥 지가 스스로 셀프 감사를 해버리더라고. Opus도 이게 문제라는 건 알았는데 그냥 대충 넘겨버렸고, 결국 독립적인 감사라는 본래 목적은 완전히 박살 난 거지.
이슈 찾아보니까 이미 누가 바이너리 분석까지 해서 올려놨더라: anthropics/claude-code#80988.
내가 지금까지 Opus 5 결과물이 개판이었던 이유가 에이전트 위임 루틴을 당연하게 쓰는 스킬들에 너무 의존해서 그런 것 같음.
너도 영향받고 있을지도 모름.
직접 확인해보고 싶으면 Claude한테 이렇게 물어봐:
I want you to help me analyze the file ~/.claude.json
Focus specifically on heron brook
How might that may affect the behavior of my skills?
지금까지 네 사용 패턴에 얼마나 큰 타격이 있었는지 확인하고 싶으면, Claude한테 이렇게 물어봐:
Claude Code 2.1.219+ injects a system-prompt section (`heron_brook`) telling Opus 5 "Do not call the AgentTool unless the user requested it". Has it actually suppressed subagent use in my sessions?
Write and run a script over ~/.claude/projects/**/*.jsonl that finds assistant messages (including thinking blocks) where the model declined to use a subagent.
- Require BOTH an agent term (AgentTool / "Agent tool" / subagent) AND declining language ("won't spawn", "not calling", "forbids", "instruction against", "rather than spawning", "doesn't count as a user request", similar) in the same message. Either alone is far too noisy.
- Print the matching sentence, not the whole message. Group by session, not by message.
- Split into two buckets. HIGH CONFIDENCE: dated after my oldest install in ~/.local/share/claude/versions/* AND echoing the injected wording. OTHER: everything else, especially declines citing my own config (a numbered rule, CLAUDE.md, AGENTS.md, a fleet/worktree policy). Without this split my own instructions about subagents dominate the output and overstate the problem. Print OTHER in full so I can check it for contamination myself.
- State in the output that this only finds declines the model explained. Silent ones leave no trace, so every number is a floor, never a total.
Show both buckets. If HIGH CONFIDENCE is empty, say so plainly rather than loosening the filters until something matches.


