[Feature Request] Add allowlist/exemption mechanism for defensive security workflows

Status Fixed / completed
Reported on v2.1.220
Maintainer reply None cached
Activity 1 comment · opened Jul 30, 2026 · closed Aug 17, 2026

Bug Description
I am an Application Security Engineer using Claude Code to perform legitimate defensive security work within my own company. In this case, I was triaging vulnerabilities in our self-managed GitLab instance and reviewing security findings from our internal applications. However, my session was blocked by the cybersecurity safeguards. My work is strictly defensive and limited to systems owned and operated by my organization. I use Claude Code for tasks such as: Vulnerability triage and remediation guidance Secure code review Kubernetes, Linux, and Terraform configuration analysis Security tooling development for internal use This appears to be a false positive. These interruptions significantly impact my ability to perform my job and reduce the usefulness of Claude Code for legitimate Application Security work. Please review this case and consider reducing false positives for defensive security activities.

Environment Info

  • Platform: darwin
  • Terminal: WarpTerminal
  • Version: 2.1.220
  • Feedback ID: b1b3dc01-1a2d-4260-82e7-5248432563f9

Errors

[]

View original on GitHub ↗

This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗