[Bug] False positive [cyber] safeguard triggered on benign developer-tooling questions

Status Open
Reported on v2.1.237
Maintainer reply None cached
Activity 0 comments · opened Aug 28, 2026

Bug Description
False positive: [cyber] safeguard triggered on a benign developer-tooling question. What happened: I asked "what is Orca's diff feature?" — a question about the diff/compare viewer in the Orca IDE CLI. Fable 5's safeguards flagged the message with [cyber] and the session was auto-switched to Opus 4.8. Why this is a false positive: The message contained no security, exploit, or attack content. It was a question about a local editor's file-comparison command (orca file diff). Preceding context that may have influenced the classifier: The prior turns covered signing up for NAVER Cloud Platform's Maps API — so words like "authentication", "login", "Client ID", "Client Secret", and "API key issuance" appeared repeatedly. These were about legitimate map SDK credential provisioning for a mobile app, not credential attacks. Impact: The project involves authentication, encryption, and PII-handling code by nature, so these false positives interrupt normal development repeatedly and force unwanted model switches mid-session. Request: Please tune the [cyber] classifier so that credential provisioning for third-party SDKs and questions about local dev tooling are not conflated with offensive security content.

Environment Info

  • Platform: darwin
  • Terminal: Orca
  • Version: 2.1.237
  • Feedback ID: e547be0b-547a-418d-ac3e-0b01fd3e1096

Errors

[]

View original on GitHub ↗