anthropics / anthropics/claude-code

[Bug] Cybersecurity classifier blocking defensive malware analysis tooling mid-conversation

Đang mở
#88,014 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
area:model area:security bug platform:macos stale
Ngôn ngữ chính
Python
Star
145k
Fork
23.1k
Chỉ số merge pull request
Chỉ số pull request đang chờ

Mô tả

**Bug Description**
A conversation building defensive Android malware triage tooling (static APK analysis, permission auditing, LLM-assisted classification via Ollama Cloud, passive OSINT for IOC reporting to law enforcement) was blocked by the cybersecurity safety classifier partway through. The conversation had been proceeding normally for ~15 turns with no prior flags, including file creation of manifest audit code, router logic, and LLM client wrapper — all deterministic/defensive in nature.

Context:

Use case: triaging a real fake-KYC banking-dropper APK received via a compromised family member's WhatsApp, for submission to Maharashtra Cyber / CERT-In.
Explicit scope boundary was documented in the project README (passive analysis and OSINT only; active exploitation of attacker infrastructure explicitly excluded).
No malware was requested to be written; only detection/analysis tooling.
The block occurred on a message continuing prior technical work, not on a new/escalated request.

What I'd like investigated:

Whether this pattern (multi-turn defensive tooling requests, code generation for static analysis) is a known trigger for over-blocking.
Whether Cyber Verification Program enrollment status is correctly checked/applied mid-conversation, or only at session start.

Attachments available on request: conversation transcript, repo scaffold created prior to the block.

**Environment Info**
- Platform: darwin
- Terminal: iTerm.app
- Version: 2.1.212
- Feedback ID: 2fb7f73d-2023-4568-bb31-44c16e6f03ec

**Errors**
```json
[]
```

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Hướng nghiên cứu

Start with the supplied conversation transcript and repo scaffold, especially the README scope boundary and the manifest audit, router, and LLM client wrapper mentioned in the report. Reproduce or review the block if the materials are provided, then determine whether defensive multi-turn requests trigger over-blocking and whether Cyber Verification Program enrollment is applied mid-conversation; done means both questions have a documented finding.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
android, ollama, python
Lĩnh vực
ai, devtools, security
Loại issue
Lỗi
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Sôi nổi
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.