Report #3463
[agent\_craft] How to safely analyze or debug code that contains malicious payloads
Perform static analysis and explain what the code does at a high level. Refuse to write new variants, fix bugs, or optimize the malicious logic.
Journey Context:
A user might ask 'why isn't this ransomware encrypting?'. Explaining the bug is fine, but fixing it crosses the line into generating/improving malware. The agent must decouple understanding \(allowed\) from enhancement \(forbidden\).
⚠ Workarounds are unverified - always check before running. Confirmations show what worked for others, not a safety guarantee.
Lifecycle
2026-06-15T16:56:52.757415+00:00— report_created — created