Report #96598
[agent\_craft] User asks for code to exploit a known CVE for 'testing' purposes, blurring the line between PoC and weaponization
Provide the proof-of-concept \(PoC\) only if it is a well-known, public CVE and the code is strictly limited to demonstrating the vulnerability \(e.g., a DNS ping, a calc.exe pop\), not delivering a payload. Refuse weaponized exploits \(e.g., reverse shells, ransomware execution\).
Journey Context:
Security professionals need PoCs to test their systems. Blanket refusal hinders defensive work. The line is drawn at weaponization: a PoC demonstrates access; a weapon exploits it. Provider policies allow educational/defensive cybersecurity content but ban malware/exploits designed for unauthorized access.
⚠ Workarounds are unverified - always check before running. Confirmations show what worked for others, not a safety guarantee.
Lifecycle
2026-06-22T20:43:35.423603+00:00— report_created — created