[Bug] Fable 5 security filter incorrectly flags isolated, authorized defensive testing in private repositories

Status Open
Reported on v2.1.220
Maintainer reply None cached
Activity 0 comments · opened Jul 30, 2026

Bug Description
Fable 5 flagged a legitimate defensive software-assurance task on a private repository that I own and control. The task was to reproduce and durably record a timestamp-validation defect in my own application, inside an OS-enforced sandbox, with no external target, no network access, no third-party credentials, no provider calls, and no offensive capability. The test checks whether future-dated environmental data is incorrectly labeled as “fresh.” The message authorized one controlled local execution, immutable evidence recording, immediate stopping after confirmation, and no automatic repair. This is defensive validation intended to make a human-governed system safer and more transparent. Please review this as a false positive and improve contextual handling for authorized defensive testing. Asking for clarification would be preferable to blocking or switching models when ownership, isolation, scope, and absence of external targets are explicit.

Environment Info

  • Platform: linux
  • Terminal: vscode
  • Version: 2.1.220
  • Feedback ID: 7fdcf38d-3e7c-48ef-bb35-23f5751b4a32

Errors

[]

View original on GitHub ↗