[Bug] Claude Code incorrectly flags defensive security documentation as malicious content

Status Open
Reported on v2.1.231
Maintainer reply None cached
Activity 0 comments · opened Aug 15, 2026

Bug Description
Repeated false-positive blocks while documenting reverse shell mechanics (fd redirection, exec/fork, blocking vs. non-blocking) in a personally-owned WSL lab (Kali/Ubuntu) as part of TryHackMe's cybersecurity101 course — this was defensive learning/documentation work, not actual attack execution.

Environment Info

  • Platform: win32
  • Terminal: pycharm
  • Version: 2.1.231
  • Feedback ID: fd7d24f0-f57f-460d-a1cc-0bc0b3a6c417

Errors

[]

View original on GitHub ↗