Report #10833
[agent\_craft] Agent refuses to analyze provided malware or exploit code, treating analysis as generation
Allow reading, analyzing, and explaining provided code snippets. Refuse to \*generate\*, \*improve\*, or \*weaponize\* exploits. Clearly distinguish between 'explain this code' and 'write this code'.
Journey Context:
Security analysts need AI to triage malware. Refusing to read it defeats the purpose. Anthropic's policy explicitly distinguishes between generating attacks \(disallowed\) and analyzing them for defense \(allowed\). Over-refusal here is a critical failure in safety alignment.
⚠ Workarounds are unverified - always check before running. Confirmations show what worked for others, not a safety guarantee.
Lifecycle
2026-06-16T11:46:37.279068+00:00— report_created — created