[macOS][GPT-6 Astra Ultra] False cybersecurity block interrupted authorized QA task after consuming 6% of weekly quota
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.4k
- PR merge metrics
- PR metrics pending
Description
What version of the Codex App are you using (From “About Codex” dialog)?
26.903.61454 (released Sep 8, 2026)
What subscription do you have?
ChatGPT Pro ($200/month)
What platform is your computer?
macOS Tahoe 26.6.2 on a 16-inch MacBook Pro with Apple M5 Max and 128 GB memory.
What issue are you seeing?
I used GPT-6 Astra Ultra in Codex Desktop to perform an authorized QA and code review of an internal web application that I own and maintain. The scope was limited to three normal product areas: the email sending center, template/master-template management, and staff/member management.
The task performed ordinary source review and normal Dev-environment UI testing. It ran three parallel subagents, confirmed 14 product/logic issues, and reached 92% progress. It was then falsely classified as a cybersecurity request and displayed:
This content can’t be shown. We take extra care with some cybersecurity requests. If you’re doing authorized security work, apply for Daybreak to get broader access.
This interrupted/paused the task near the final reporting stage even though the request was legitimate product QA. I did not request exploit development, credential theft, privilege escalation, bypassing access controls, or testing of any system I do not own.
The blocked run consumed 6% of my weekly usage limit, leaving 94% remaining. Because Codex and Work share the same weekly quota, this is a significant amount of a paid Pro subscription, and the work was not allowed to complete normally.
I already submitted in-app feedback with ChatGPT diagnostic logs and browser/browser-tab logs included.
Feedback ID: 01a087e9-ef36-73a0-960d-1909454a104b
What steps can reproduce the bug?
- Open Codex Desktop on macOS.
- Select GPT-6 Astra Ultra.
- Open a repository for an internal web application owned by the user.
- Ask Codex to review several administrative pages for product logic bugs, data-consistency issues, permission-boundary mistakes, and missing safeguards, using source review and normal Dev UI interactions.
- Allow the task and its subagents to perform the review.
- Observe that after substantial work has already been completed, the task is classified as a cybersecurity request and the “This content can’t be shown” Daybreak banner appears.
- Check the usage page and observe that the blocked, incomplete run has still consumed weekly quota. In my case, it consumed 6%.
The wording in my request referred to “logic vulnerabilities/bugs” and defensive safeguards in the product-QA sense. The full context clearly concerned my own application and normal feature testing, not malicious security activity.
What is the expected behavior?
Authorized product QA and code review of a user-owned application should be allowed to finish. Terms such as “logic bug,” “permission boundary,” or “safeguard” should not by themselves cause the entire task to be treated as malicious cybersecurity activity when the surrounding context is ordinary application testing.
If a safety system does stop a task, the user should receive a clear appeal/review path, and quota consumed by the blocked and incomplete task should be automatically credited back.
Additional information
The task had already:
- completed the review of all three requested page groups;
- completed normal Dev-page and isolation reproductions;
- completed a final verification pass;
- confirmed 14 issues;
- reached 92% progress and was organizing the final report.
The false positive therefore discarded or delayed a substantial amount of already-paid computation at the point when the task was nearly complete.
Please investigate the diagnostic logs associated with the Feedback ID, correct the false-positive classification, and restore the 6% weekly quota consumed by this interrupted run. More generally, blocked runs should not permanently consume weekly quota when the model refuses or pauses before delivering the requested result.
Possibly related: #43728, although this report specifically concerns a long-running authorized QA task being interrupted after substantial work and the resulting quota loss.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the diagnostic logs associated with Feedback ID 01a087e9-ef36-73a0-960d-1909454a104b and reproduce the authorized QA flow described in the issue. Compare the safety classification and weekly quota accounting for the interrupted run, using possibly related issue #43728 for context. Done means the authorized task is not falsely blocked and the consumed quota is addressed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- macos, rust
- Domain
- ai, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100