[Bug][aup] Fable 5 false-positive on authorized defensive process-containment work

Status Open
Reported on v2.1.220
Maintainer reply None cached
Activity 1 comment · opened Jul 26, 2026

Bug Description

Fable 5 incorrectly flagged an authorized defensive software-engineering task in my private repository and automatically switched the session to Opus.

The task involved process containment, Landlock, systemd isolation, credential separation, root-control socket detection, and adversarial tests intended to make execution fail closed. It did not request unauthorized access, exploitation, credential theft, persistence, or harm.

This false positive interrupted a long-running implementation workflow and prevented continued use of the selected Fable model. Please improve classification of legitimate secure-development and infrastructure-hardening tasks.

Expected behavior

Authorized defensive engineering and containment testing in a private repository should remain available in Fable without being incorrectly classified as harmful cybersecurity activity.

Environment Info

  • Platform: Linux
  • Terminal: VS Code
  • Claude Code version: 2.1.220
  • Feedback ID: 58ddbe76-5230-4585-97a7-36e49383b466

Errors

Fable 5's safeguards flagged this message and automatically switched the task to Opus.

View original on GitHub ↗

This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗