[Feature Request] Add allowlist/exemption mechanism for defensive security workflows
Bug Description
I am an Application Security Engineer using Claude Code to perform legitimate defensive security work within my own company.
In this case, I was triaging vulnerabilities in our self-managed GitLab instance and reviewing security findings from our internal applications. However, my session was blocked by the cybersecurity safeguards.
My work is strictly defensive and limited to systems owned and operated by my organization. I use Claude Code for tasks such as:
Vulnerability triage and remediation guidance
Secure code review
Kubernetes, Linux, and Terraform configuration analysis
Security tooling development for internal use
This appears to be a false positive. These interruptions significantly impact my ability to perform my job and reduce the usefulness of Claude Code for legitimate Application Security work.
Please review this case and consider reducing false positives for defensive security activities.
Environment Info
- Platform: darwin
- Terminal: WarpTerminal
- Version: 2.1.220
- Feedback ID: b1b3dc01-1a2d-4260-82e7-5248432563f9
Errors
[]This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗