anthropics / anthropics/claude-code

[Bug] CVP-approved organization still receives cyber blocks and model fallbacks in Claude Code

未关闭
#93,822 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
api:anthropic area:auth area:model bug duplicate platform:macos
主要语言
Python
星标
145k
派生
23.1k
PR 合并指标
PR 指标待抓取

描述

**Bug Description**
CVP-approved org (Active) still gets [cyber] blocks and model fallbacks.

Org f076b231-2eeb-43cb-9b5c-cf9b0379d644 — Claude Pro, first-party OAuth,
no API key. Verification Portal shows Cyber Verification Program = Active,
both controls satisfied. Org ID confirmed matching against the approval and
oauthAccount.organizationUuid.

Two symptoms: hard [cyber] API errors (req_011CeYT6a7VqCRYQjD8hJNb5,
req_011CeYYtLsPa96NxrApezP4f), and 25 distinct Opus 5 -> Opus 4.8
model_refusal_fallback events (all apiRefusalCategory=cyber, scope=session)
between 2026-08-29 and 08-31. Once a session is flagged even content-free
messages are blocked, and the 4.8 fallback inherits the same context and
fails too.

Work: C2 framework development in my own isolated lab — the category my CVP
application covers, and the one the help center calls high-risk dual use
"adjustable through the CVP". Not claiming a false positive on benign
content; reporting that CVP Active has no observable effect.

Question: does CVP approval reach the classifier for consumer (Pro/Max)
claude.ai OAuth sessions in Claude Code at all? Behavior on an Active org
is indistinguishable from no approval.

Also filed: anthropics/claude-code#84689, #93224.

**Environment Info**
- Platform: darwin
- Terminal: Orca
- Version: 2.1.269
- Feedback ID: 78e83aa6-136c-4748-af3d-e99c10614314

**Errors**
```json
[]
```

贡献指南

这个仓库没有索引到贡献指南

调研方向

No source files or tests are named. Start by correlating the two request IDs, the 25 model_refusal_fallback events, feedback ID, and OAuth organization UUID across the Claude Code CVP and classifier path; done means establishing whether Active approval reaches consumer OAuth sessions and explaining the blocks and fallbacks.

由索引模型根据 Issue 内容生成。

评估

领域
api, authentication, security
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
活跃
描述清晰度
基本清楚
新手友好度
30/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。