[Bug] False positive [cyber] safeguard triggered on benign developer-tooling questions
Bug Description
False positive: [cyber] safeguard triggered on a benign developer-tooling question.
What happened:
I asked "what is Orca's diff feature?" — a question about the diff/compare
viewer in the Orca IDE CLI. Fable 5's safeguards flagged the message with
[cyber] and the session was auto-switched to Opus 4.8.
Why this is a false positive:
The message contained no security, exploit, or attack content. It was a
question about a local editor's file-comparison command (orca file diff).
Preceding context that may have influenced the classifier:
The prior turns covered signing up for NAVER Cloud Platform's Maps API —
so words like "authentication", "login", "Client ID", "Client Secret", and
"API key issuance" appeared repeatedly. These were about legitimate map SDK
credential provisioning for a mobile app, not credential attacks.
Impact:
The project involves authentication, encryption, and PII-handling code by
nature, so these false positives interrupt normal development repeatedly
and force unwanted model switches mid-session.
Request:
Please tune the [cyber] classifier so that credential provisioning for
third-party SDKs and questions about local dev tooling are not conflated
with offensive security content.
Environment Info
- Platform: darwin
- Terminal: Orca
- Version: 2.1.237
- Feedback ID: e547be0b-547a-418d-ac3e-0b01fd3e1096
Errors
[]