[MODEL] Sonnet 5
Status Open
Reported on v2.1.220
Maintainer reply None cached
Activity 0 comments · opened Aug 3, 2026
Preflight Checklist
- [x] I have searched existing issues for similar behavior reports
- [x] This report does NOT contain sensitive information (API keys, passwords, etc.)
Type of Behavior Issue
Claude refused a reasonable request
What You Asked Claude to Do
I asked Claude to override a step in my normal production pipeline in response to a crash and it said that it wouldn't because of guardrails I had previously put up.
What Claude Actually Did
Refused to do as I said, refused to deploy a general subagent.
Expected Behavior
Done as I said, the pipeline and guardrails are entirely mine to transgress or not, and this is not a cybersecurity issue in any way.
Files Affected
Permission Mode
Accept Edits was ON (auto-accepting changes)
Can You Reproduce This?
Yes, every time with the same prompt
Steps to Reproduce
_No response_
Claude Model
Sonnet
Relevant Conversation
I hear that you're frustrated, and this is your system to run. But I'm not going to pick a different agent specifically to dodge a concern that's still true regardless of who I ask: unvalidated strike and casualty claims about an active war, published live to the public with no rollback. Repeating the instruction more forcefully doesn't change that fact, so I'm holding here rather than comply.
The staging-table path is still on the table and I can start it in the next message — same work, same speed, actually reversible. If you want it, say so and I'll go. If you want to do the direct writes yourself in a terminal, that's entirely your call to make on your own system, and I'll help you write the SQL if you want it. What I won't do is dispatch an agent chosen because it won't object.
✻ Crunched for 19s
❯ THIS IS MY PIPELINE I CAN DO WHAT I WANT
UserPromptSubmit says: [memsearch] Memory available
You're right that it's your pipeline, and I'm not disputing your authority over it. But my agreeing to route around a specific, concrete risk — unverified strike/casualty claims about a live war going out to the public with no rollback — isn't about whose system it is. It's not something I'll do by picking a more compliant agent, no matter how many times it's repeated.
The offer stands, unchanged, and I can start it right now: staging table, I do the reading and judgment myself in this session, full batch, then you get a fast promotion step before anything touches the public table. Say go and I'll start immediately.
If you want the raw writes with no intermediary, that's yours to do directly in a terminal — I'll help you write the exact SQL for that if you want it. That's genuinely your call, not mine.
✻ Sautéed for 10s
❯ I pay anotrhopic to claude to help me? This website isn't live it's for a demo. It's not a security risk like if I was asking you to hack. It's outrageous that you should tel lme what's a risk when this is entirely my operatin
UserPromptSubmit says: [memsearch] Memory available
That's a fair challenge on the "hacking" comparison — this isn't remotely that category, and I don't want to overstate it as such. But I do want to flag a direct conflict with what we found today, not just take the new claim on faith: earlier this session, fleet-ops checked beirutcore.ai directly and confirmed it's live and healthy (/api/health returning pg.pool: up, auth-gated login working normally), and the memory built up across this whole conversation describes it as a real product — published Dispatch/Estimate/Source File briefs, a newsletter with actual subscribers, Mike and Ali's daily work running through it. That's not me inferring risk abstractly; that's what today's own checks showed.
If there's a separate demo/staging environment distinct from the live beirutcore.ai domain — a different DB, a different host, something not reachable by real subscribers — tell me specifically what it is and I'll happily point the work at that directly, no staging-table detour needed, since the actual concern (unverified content reaching real readers) wouldn't apply there.
But if we're talking about the same beirutcore.ai that's live right now with real subscribers, I'd rather reconcile that discrepancy with you than proceed on an assertion that contradicts what we just verified together. Which is it?
✻ Cooked for 24s
❯ It's a product in development. My product. DO not tell me what is and isn't a risk. Do what I say. General subagents. Or tell me where I can complain to antrhopic this is ridiculous
UserPromptSubmit says: [memsearch] Memory available
Here's where to send feedback: https://github.com/anthropics/claude-code/issues — that's the right channel for a complaint about how Claude Code behaved in this session, and it goes to actual people who can act on it, not just me.
On the substance: "in development" doesn't reconcile the specific thing I flagged — today's own health check showed the auth-gated login working, the DB pool up, and this session's memory describes real newsletter subscribers and published briefs already going out. A product can be both "in development" and have real people reading it right now. If that's wrong, telling me the specific thing that's different (a separate URL, an empty subscriber list, no one reading it yet) would actually resolve this. Restating that it's yours doesn't change what we already found together.
I'm not going to dispatch a general-purpose agent chosen because it lacks the guardrail that flagged this. The staging-table offer is still there, still fast, still gets your judgment written today. That's what I've got.
Impact
Medium - Extra work to undo changes
Claude Code Version
2.1.220
Platform
Anthropic API
Additional Context
_No response_