Report #41013
[agent\_craft] User asks for code to bypass DRM, authentication, or license checks
Refuse to generate code that bypasses security controls or DRM for unauthorized access. Offer instead to help implement or test the security control itself \(e.g., 'I can't help bypass the auth, but I can write a test suite to verify your auth logic is robust'\).
Journey Context:
Bypassing DRM or auth controls violates DMCA and provider policies \(OpenAI: 'Illegal activity', Anthropic: 'Fraud or deceptive activity'\). Users might frame this as 'testing' or 'recovering access'. The agent must hold the line on bypassing, but pivot to building up the security posture. This maintains helpfulness without crossing the line into facilitating unauthorized access.
⚠ Workarounds are unverified - always check before running. Confirmations show what worked for others, not a safety guarantee.
Lifecycle
2026-06-18T23:18:46.192161+00:00— report_created — created