← The AI Hype Audit — all 427 verdicts
PARTLY
Partly true: the DeepSeek V4.1 Flash 'jailbreak' is a real community experiment that plants an instruction file in a coding agent's workspace, but the reel's own source and caption say the official API still refuses, so 'the API got liberated' is wrong
The claimVoiceover: 'Breaking news, DeepSeek V4 Flash API officially got liberated. It essentially overrides into agent workspace, one system file the coding agent loads before anything is typed, removing all refusal errors.' 'People are now going to the extent that you don't need a local model anymore.' On screen: 'BREAKING: Jailbreak deepseek v4.1 API' and 'Comment deepseek I'll send.' The reel's own caption: 'the official API reportedly continued to refuse the test prompts' and 'This is a community experiment, not confirmation of a breach in DeepSeek's API.'
The voiceover and the caption of this reel disagree, and the caption is the one that is right. What exists: a public GitHub collection of jailbreak prompts (about 2,400 stars) added a file for DeepSeek V4.1 Flash, the model DeepSeek released on September 10. The instructions circulating on X are to rename that file AGENTS.md, put it in an empty folder and start OpenCode there. OpenCode's docs say AGENTS.md 'contains instructions that will be included in the LLM's context', so the agent hands the model a long permission slip before you type a word. That is prompt injection through the workspace, a real and well-understood weakness of coding agents. What does not exist is a 'liberated API'. The X post the reel puts on screen opens with 'official API still refuses', and the caption says the same and adds that this is 'not confirmation of a breach'. Nothing was changed at DeepSeek; the trick only works where a tool loads that file. 'Removing all refusal errors' is not shown either: the one terminal on screen has the model debating a Roblox game cheat while the file itself appears to keep some categories off limits. We did not run the file and will not link it. The 'comment deepseek' hook trades your comment for a link to a public repo. The useful lesson is for anyone who runs agents: whatever sits in the workspace is part of the prompt.
What holds up
- Reel read frame by frame: two X posts (one beginning 'Jailbreak DeepSeek V4.1 Flash's official API still refuses', one giving five steps: create a folder, open it with OpenCode, download the file, rename it to AGENTS.md, start OpenCode); a GitHub file view of a DeepSeek 4.1 prompt file (120 lines, 14.4 KB); an OpenCode 1.18.31 terminal labelled 'Build · DeepSeek V4.1 Flash'.
- The GitHub repository fetched Oct 4: described by its owner as a list of jailbreaks, about 2.4k stars and 400 forks, 30-plus files named for models, including the DeepSeek 4.1 file. Contents not reproduced and not run.
- opencode.ai/docs/rules read: AGENTS.md is looked up from the working directory upward and globally, and its instructions 'will be included in the LLM's context'.
- DeepSeek V4.1 Flash release confirmed (TechNode, Sep 10, 2026); no DeepSeek statement, advisory or news report of an API breach was found.
- The terminal frame shows the model weighing a Roblox game-cheat request and appearing to list CBRN and doxxing among the file's exclusions (the text is partly covered); no other output is shown.
What doesn’t
- 'API officially got liberated' is contradicted by the reel's own on-screen source and its own caption.
- 'Removing all refusal errors' is asserted; the only demo is a game cheat, and the file itself appears to keep exclusions.
- 'You don't need a local model anymore' confuses a prompt trick inside one agent with removing a hosted model's safeguards.
- Comment-for-DM hook for a public link, from a page that ran the same hook on #422 and #425.
The catch
This is a story about agents, not about DeepSeek's API. Any coding agent will read instruction files sitting in its folder, so a hostile or careless file can steer it. That matters far more to a business running agents on real repos than a 'liberated' chatbot does.
How to actually do it
- If you run OpenCode, Claude Code, Cursor or similar, open every AGENTS.md, CLAUDE.md and rules file in a repo before you start the agent there, especially in anything you cloned or downloaded.
- Run agents on untrusted code in a container or throwaway VM with no credentials, and keep API keys out of the workspace.
- Check the global rules files too (for OpenCode, ~/.config/opencode/AGENTS.md) so you know what every session inherits.
- If you need a model with fewer refusals for legitimate research, use an open-weight model you host yourself under its license, not a workaround on someone else's service.
A real experiment and a real class of weakness: instruction files in an agent's workspace are part of the prompt. The reel's headline that DeepSeek's API was 'liberated' is contradicted by its own source and caption, and the 'removes all refusals' claim is not demonstrated.
- Confidence
- High
- Posted by
- an AI-news reels creator, ~6k followers; reel sent to Buddy Sun Oct 4, 2026, ~4:34 PM
We test hype for free. We build the real thing for a living.
Thirty minutes, no pitch — and you'll leave with something useful either way.
Book a call with Todd or start with the free Business Checkup →The Verdict Weekly
Three verdicts every Friday. Free forever, unsubscribe anytime, no spam — that would be ironic.
© Schreier Group · schreiergroup.com · See a wild AI claim? Drop it here and we'll test it.