Opus 5 safeguards false-positive: authorized security work silently downgraded to Opus 4.8
Status Open
Reported on v2.1.221
Maintainer reply None cached
Activity 1 comment · opened Aug 6, 2026
What happened
While doing routine, authorized penetration-testing work in Claude Code on Opus 5, a message was flagged by the model safeguards and the session was automatically switched to Opus 4.8. The same kind of work ran fine earlier in the session. The flag fired right after I re-authenticated and resumed normal cyber work.
The exact notice shown:
Opus 5's safeguards flagged this message. Our intentionally broad safeguards allow us to deliver more capabilities faster, but can sometimes flag legitimate coding, cybersecurity, and biology tasks. Switched to Opus 4.8. Send feedback with /feedback or learn more
Why this is a false positive
The flagged work is authorized security research: in-scope testing under a bug bounty program, performed by a vetted participant. My organization participates in the CVP. Nothing disallowed was requested. This is the "legitimate cybersecurity task" the notice itself acknowledges can be misflagged.
Impact
- Interrupts authorized security workflows mid-task.
- Silently downgrades the model (
Opus 5toOpus 4.8), changing capability and output without the user choosing it. - Undercuts the vetted-researcher use case that programs like the CVP exist to support.
Environment
- Claude Code
2.1.221 - Model
Opus 5 (1M context), downgraded toOpus 4.8 - macOS 26.5.2 (
Darwin 25.5.0)
Ask
- Reduce false positives on authorized cybersecurity work.
- Give vetted-program participants an override or allowlist path so safeguards do not silently downgrade the model mid-session.
This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗