[Bug] Safety classifier over-flagging legitimate first-party automation as [cyber] threat

Status Open
Reported on v2.1.238
Maintainer reply None cached
Activity 0 comments · opened Aug 23, 2026

Bug Description
▎ Claude Code's real-time safety classifier repeatedly flags routine development on my own first-party product as [cyber] false positives. The project is a consumer game-input timing assistant — controller automation plus a latency utility — for my own console on my own home LAN. No third-party or external systems are involved. Individual messages and whole sessions get flagged and bounced to Opus, which then also errors, killing the turn and making the tool unusable for this work. I applied to the Cyber Verification Program and was denied. Requesting re-review of these false positives, or guidance on how to build this legitimate product without the interruptions. Sample request IDs: req_011CeLV9v2qirSdNPkC7inPs (others available in-session).

Environment Info

  • Platform: win32
  • Terminal: xterm-256color
  • Version: 2.1.238
  • Feedback ID: 99ebf567-d65e-4980-9f70-e149627a3268

Errors

[{"error":"TelemetrySafeError: VirtualMessageList: itemKeys/messages length desync (keys=288 messages=287 range=[254,288))\n    at Ta0 (B:/~BUN/root/cli:23248:33899)\n    at Rig (B:/~BUN/root/cli:23248:26870)\n    at dn (B:/~BUN/root/cli:2975:21430)\n    at _g (B:/~BUN/root/cli:2975:40534)\n    at Ly (B:/~BUN/root/cli:2975:51462)\n    at ai (B:/~BUN/root/cli:2975:89108)\n    at yo (B:/~BUN/root/cli:2975:88063)\n    at Lt (B:/~BUN/root/cli:2975:87884)\n    at Yde (B:/~BUN/root/cli:2975:84146)\n    at Ke (B:/~BUN/root/cli:2975:6696)","timestamp":"2026-08-21T06:40:44.493Z"}]

View original on GitHub ↗