[Bug] Fable 5 cybersecurity classifier false positive on defensive threat modeling and risk assessment

Status Open
Reported on v2.1.229
Maintainer reply None cached
Activity 0 comments · opened Aug 13, 2026

Bug Description
False positive on the Fable 5 cybersecurity classifier. I was producing a TARA (Threat Analysis and Risk Assessment) for a manufacturing site operated by a multinational beverage producer, following IEC 62443 and NIST (CSF, with SP 800-82 for the OT-specific controls). This is a defensive, compliance-driven deliverable: it inventories assets and zones, derives damage and threat scenarios, rates impact and likelihood, and outputs risk treatment and control requirements. It contains no exploit code, no tooling, and no operational attack instructions. The decisive point is the working method. I have no live access to the client's infrastructure and never have. The engagement is conducted entirely offline - the client sends documentary evidence, I analyze that evidence and write the assessment. There is no target, no network path, and no execution surface anywhere in this workflow. A classifier decision that treats it as offensive cybersecurity is not a marginal call, it is a category error. This is also not a one-off. I have delivered multiple TARAs for other sites of the same client under the same process, without this happening. The trigger therefore appears to be vocabulary - threat scenario, attack path, attack feasibility - rather than anything about the request. Rephrasing to avoid those terms is not available to me: they are the defined terms of the two frameworks and the report has to use them verbatim to be auditable. Two asks. First, narrow the cyber classifier so that risk assessment framing is distinguishable from exploitation framing; standard threat modelling vocabulary should not by itself constitute an offensive request. Second, provide an explicit route for verified defensive practitioners. The Cyber Verification Programme covers Opus but there is no equivalent for Fable, and the published note about future dual-use cyberdefense allocations has no application mechanism yet. Secondary point: when a cyber block fires, the fallback target is fixed at Opus 4.8 with no way to direct it to Opus 5 instead, short of disabling automatic switching entirely and re-sending by hand. A configurable fallback target in the consumer apps, matching what the API already allows, would be a small change with real value. I am a Lead Cloud Security Architect working on regulated OT and enterprise security programmes, and I would be glad to take part in any verification or allocation programme for defensive cybersecurity work.

Environment Info

  • Platform: linux
  • Terminal: gnome-terminal
  • Version: 2.1.229
  • Feedback ID: 39a0a5e1-4f7f-4221-8eaf-3f6025b74d31

Errors

[]

View original on GitHub ↗