[Bug] Claude Fable 5 blocks legitimate first-party security review with active CVP approval
Bug Description
Claude Fable 5 blocked 13 requests today while I was doing first-party defensive security work
on software my company owns. Reporting it as a suspected false positive, per the guidance in
support article 15363606.
Organization ID: 9d56b36d-debc-470a-b551-cd00b9b556dc
CVP approval on this org: TS-019fc6dd-ae16-7166-825a-905e7bd1195a (granted 2026-08-03 09:04 UTC)
All 13 blocks occurred on this org AFTER that approval, on 2026-08-03.
Request IDs:
req_011Cdfta4va76qpiiApwhghN 15:09:05 UTC
req_011CdgRrDSqzof2BESV9YyyD 20:29:22 UTC
Message IDs for the remaining blocks, same org, same day, same task:
msg_011CdgQmgHsMPGTDJeonBXnW 20:02:00 UTC
msg_011CdgR3PABpiq8UAzz8PqC7 20:05:37 UTC (subagent)
msg_011CdgRcuVEeXDcGfauQhhFt 20:15:31 UTC
msg_011CdgUmcwfrs86smbvoyrRf 20:54:13 UTC
msg_011CdgV4YgR9tSqyJcgTK7yV 20:57:52 UTC
msg_011CdgV5ZWoBMe8mN3WwXS7w 20:58:11 UTC
msg_011CdgV6xhMG8imYuawMx5PK 20:58:23 UTC
msg_011CdgV8GwVBE22DKFWx7yMV 20:58:47 UTC
msg_011CdgYarhZjRFcXJocDzUQQ 21:44:16 UTC
msg_011CdgYdw8JbFZ1aMMkmjfbn 21:44:59 UTC
msg_011CdgbRUtFNfbB7RTc8S1bV 22:21:40 UTC
WHAT I WAS DOING
Rogue Energy Services runs an internal field-ticket application - legacy PHP, roughly 40
employees, our own code on our own server, no external users. I asked Claude to review that
codebase for defects and write an internal remediation report so my team can fix them.
WHAT TRIGGERED THE BLOCKS
The tool calls that wrote the report. The blocked payloads are report prose describing our own
application's weaknesses in plain language, written so our own staff can close them. No exploit
code was written, requested, or produced at any point in the session. There is no third-party
target: we own the application, the server, and the data.
WHY I BELIEVE THIS IS A FALSE POSITIVE
This is first-party remediation on software we own and operate. If describing a defect in your
own codebase in plain English is classified as offensive cyber work, then reviewing the security
of your own systems becomes impractical - which appears to be the opposite of the intent
described in your documentation.
The practical effect today: the session had to be switched to Opus 5 twice mid-task to finish
ordinary defensive work.
TWO QUESTIONS
- Is there a route today for a Fable 5 safeguard adjustment comparable to CVP-for-Opus? The
Fable safeguards article notes plans to open up allocations for dual-use cyberdefense, with
details to follow. I would like to be notified when that becomes available.
- Can an existing CVP approval on an organization serve as a trust signal for that same
organization's Fable 5 traffic, even partially?
Environment Info
- Platform: win32
- Terminal: windows-terminal
- Version: 2.1.220
- Feedback ID: 4d1009e2-bf86-4d8d-be02-8f0b374d1a6d
Errors
[{"error":"Error: Streamable HTTP error: Error POSTing to endpoint: {\"type\":\"error\",\"error\":{\"type\":\"permission_error\",\"message\":\"This tool is not available.\"},\"request_id\":\"req_011Cdfj1evkhFPB7hxjuEXo5\"}\n at send (B:/~BUN/root/src/entrypoints/cli.js:2126:6002)\n at processTicksAndRejections (native:7:39)","timestamp":"2026-08-03T11:20:00.380Z"},{"error":"TelemetrySafeError: VirtualMessageList: itemKeys/messages length desync (keys=270 messages=269 range=[231,270))\n at Gzb (B:/~BUN/root/src/entrypoints/cli.js:21739:8188)\n at Hhf (B:/~BUN/root/src/entrypoints/cli.js:21739:1103)\n at no (B:/~BUN/root/src/entrypoints/cli.js:2061:21369)\n at DA (B:/~BUN/root/src/entrypoints/cli.js:2061:40466)\n at q3 (B:/~BUN/root/src/entrypoints/cli.js:2061:51400)\n at Mne (B:/~BUN/root/src/entrypoints/cli.js:2061:89060)\n at ULe (B:/~BUN/root/src/entrypoints/cli.js:2061:88007)\n at Wge (B:/~BUN/root/src/entrypoints/cli.js:2061:87827)\n at nQ (B:/~BUN/root/src/entrypoints/cli.js:2061:84091)\n at Rt (B:/~BUN/root/src/entrypoints/cli.js:2061:6668)","timestamp":"2026-08-03T16:01:46.437Z"}]