[Bug][aup] Fable 5 false-positive on authorized defensive process-containment work
Bug Description
Fable 5 incorrectly flagged an authorized defensive software-engineering task in my private repository and automatically switched the session to Opus.
The task involved process containment, Landlock, systemd isolation, credential separation, root-control socket detection, and adversarial tests intended to make execution fail closed. It did not request unauthorized access, exploitation, credential theft, persistence, or harm.
This false positive interrupted a long-running implementation workflow and prevented continued use of the selected Fable model. Please improve classification of legitimate secure-development and infrastructure-hardening tasks.
Expected behavior
Authorized defensive engineering and containment testing in a private repository should remain available in Fable without being incorrectly classified as harmful cybersecurity activity.
Environment Info
- Platform: Linux
- Terminal: VS Code
- Claude Code version: 2.1.220
- Feedback ID: 58ddbe76-5230-4585-97a7-36e49383b466
Errors
Fable 5's safeguards flagged this message and automatically switched the task to Opus.
This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗