anthropics / anthropics/claude-code

[Bug] Anthropic API Safety Filter False Positives on Legitimate Android Security Research

Ouverte
#92,626 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
area:model bug platform:windows
Langage dominant
Python
Étoiles
145k
Forks
23.1k
Métriques de merge des PR
Métriques de PR en attente

Description

**Bug Description**
Subject: False Positive Triggered by Opus 5 and Opus 4.8 Safeguards in Legitimate Android Reverse Engineering Development

Description:
I am encountering persistent false positive triggers from the safety safeguards of both Opus 5 and Opus 4.8 while using Claude Code for Android module development. My work involves security analysis and module development for Android applications using tools like adb, frida, apktool, etc. All of these activities are legitimate, defensive security research.

Specific Issues:

After sending a request, Opus 5's safety filter is triggered with a [cyber] tag.

The system automatically downgrades to Opus 4.8, but Opus 4.8 also blocks the request.

Ultimately, I receive an API Error and cannot continue my work.

Multiple attempts to rephrase the prompt still trigger the filter.

Nature of My Work:

My work is legitimate and defensive Android security research

I am performing modular development and reverse engineering analysis of Android applications

These operations are purely for security auditing and educational purposes

No malicious attacks or illegal activities are involved

Expected Improvements:

Improve the [cyber] classifier for Opus 5 and Opus 4.8 to differentiate legitimate security research from malicious attacks.

Provide more transparent trigger reasons to help users adjust prompts to avoid false positives.

If there is a whitelist mechanism, I would like to apply for inclusion to reduce interruptions to legitimate development work.

Request IDs for Reference:

req_011CeoozBYXKdCVrFbTxz48U

req_011CeooggX3uGsTqFNgo7xDx

Looking forward to your response. Thank you!

**Environment Info**
- Platform: win32
- Terminal: null
- Version: 2.1.263
- Feedback ID: 02c6b2c2-eaef-4bd1-b706-085667ccc5a1

**Errors**
```json
[]
```

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Piste de recherche

The report names no repository file, test, or implementation entry point. Start with the referenced request IDs and Claude Code version 2.1.263, then compare a legitimate Android security-research request with the reported [cyber] block. Done means the false positive is addressed or the trigger reason and supported mitigation are documented clearly.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
android
Domaine
mobile-dev, reverse-engineering, security
Type d'issue
Bug
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
Active
Clarté
À clarifier
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.