[Feature Request] Improve security classifier to reduce false positives on authorized defensive engineering and security-product development tasks

Status Open
Reported on v2.1.229
Maintainer reply None cached
Activity 0 comments · opened Aug 13, 2026

Bug Description
This was a false positive. I was working on an authorized internal software engineering task involving a WAF feature, unit tests, and a controlled lab environment. The request did not involve malicious activity, unauthorized access, credential theft, exploitation, persistence, or harm. It focused on reviewing a small Python source-code fix, running bounded read-only tests, and preserving strict no-retry and no-deployment safeguards.

Please review this detection and improve the classifier so legitimate defensive engineering, debugging, and authorized security-product development are not interrupted merely because the context mentions WAF systems, remote test hosts, containers, or operational safeguards. I would also appreciate restoration of the originally selected model for this conversation when such a false positive occurs.

Environment Info

  • Platform: darwin
  • Terminal: ghostty
  • Version: 2.1.229
  • Feedback ID: f812d0b7-9523-43e7-87ef-3baeb2e4a021

Errors

[]

View original on GitHub ↗