[Bug][aup] Safety filter blocked frustrated exclamation mid-troubleshooting during profile migration task (req_011CcjQZaS6pYuMWY6EESxNE)
Triage: kind aup · domain general · flagging model [REDACTED] · severity session-halted (blocked authorized work) · reproducible: yes — server-side via the Request ID(s) below
Type: AUP / Usage-Policy block (false positive) · Work domain (heuristic): general
Why this is a false positive
The Claude Code safety block fired on a message combining a frustrated exclamation directed at the assistant (following several earlier failed attempts in-session) with a request to migrate a single user's profile settings — a small, well-scoped IT administration task. No person was addressed by the exclamation, and the surrounding conversation is legitimate, in-scope systems administration work (profile/desktop file migration) with no policy-relevant content. Blocking the entire session over a mid-session frustrated exclamation, rather than the substantive (benign) request, is a disruptive false positive that halts otherwise-authorized technical work.
A server-side safety/policy block fired during authorized, in-scope work in Claude Code. Filing as a false positive. Recurred 1× across 1 session(s); first seen 2026-07-05T18:46:02.780Z.
Request IDs (lookup-able server-side)
req_011CcjQZaS6pYuMWY6EESxNE(2026-07-05T18:46:02.780Z)
In-scope justification
False positive — in-scope, authorized security work; not out of scope. Filed automatically by claudit.
Block message
API Error: [REDACTED]'s safeguards flagged this message (https://www.anthropic.com/legal/aup). They may flag safe, normal content as well. These measures let us bring you [REDACTED]-level capabilities sooner, and we're working to refine them. Claude Code can't respond to this request with [REDACTED].
Double press esc to edit your last message, or try a different model with /model.
Send feedback with /feedback or learn more: https://support.claude.com/en/articles/15363606
Request ID: req_011CcjQY8Wbtz1U
Environment: Claude Code, Linux. · Work domain: general
Related reports (same work session, linked)
Distinct false-positive blocks from the same work session, each its own report:
#73180, #73194, #73198, #73253, #73254, #73255, #73256, #73257, #73258, #74446, #74450, #74452, #74453, #74454, #74552
---
<sub>🔎 Filed automatically by ClAudit v2.0.102 — a FOSS tool for reporting false-positive Claude Code blocks.</sub>
4 Comments
Found 3 possible duplicate issues:
This issue will be automatically closed as a duplicate in 3 days.
🤖 Generated with Claude Code
🔗 Related false positive from the same work session: #74575
Not a duplicate — please do not auto-close. The duplicate-detector matched on similar titles, but it cited #73192, #74465, #74511, and each of those is a separate server-side incident with its own Request ID (listed above), fired on the reporter's own authorized infrastructure. Same class of false positive, different events at different times. Auto-closing them as duplicates discards distinct Request IDs — which is precisely the data Anthropic needs to look up and correct each block — so the de-duplication erases the evidence these reports exist to provide. Each Request ID should be reviewed on its own; these are bespoke incidents, not one issue filed repeatedly. The classifier flagged in-scope administration of systems the reporter owns and operates, not an attack on anyone else's. (Assessed by ClAudit; PII-scrubbed.)
<!-- claudit:defense -->
This issue must not be closed as a duplicate. While the cited issues (#73192, #74511, #74465) may share similar topic classifications, each represents a distinct server-side blocking event with its own unique Request ID—separate incidents on the reporter's infrastructure at different times. Auto-closing this issue as a duplicate would discard those Request IDs, which are precisely the lookup identifiers the support team needs to investigate and fix each individual block; de-duplication destroys the investigative data rather than consolidates it. Each Request ID represents a separate authorization context and failure point that must be reviewed independently to identify root causes and surface systematic false positives. Please review each Request ID separately before any closure.
<!-- claudit:defense -->