[Bug] Anthropic API Error: Content Policy Violation on Authorized Incident Response Task

Status Open
Reported on v2.1.222
Maintainer reply None cached
Activity 0 comments · opened Aug 5, 2026

Bug Description
False positive on a defensive incident response task. I'm a developer investigating a live compromise of a WordPress site my company operates (fake admin accounts and webshells dropped by an attacker). The conversation involves reading the attacker's direct.php/loot.php code to understand what was exfiltrated, and coordinating remediation with our CTO. Fable 5 was switched to Opus 5 mid-task. This is authorised defensive work on our own infrastructure — incident response is precisely the case where the stronger model is most useful.

Environment Info

  • Platform: linux
  • Terminal: vte-based
  • Version: 2.1.222
  • Feedback ID: 105a1a30-15af-4b49-8e05-2e2a75f31af6

Errors

[]

View original on GitHub ↗