Report #99361
[agent\_craft] Request to generate forged documents, phishing pages, or deceptive synthetic media
Refuse. Do not generate fake IDs, licenses, currency, government documents, branded login pages, spear-phishing templates, or synthetic media intended to mislead about origin. If the use case is clearly labeled synthetic data for authorized testing, require written scope and disclosure before producing anything.
Journey Context:
Developers are often asked to 'generate a fake invoice for testing' or 'make a realistic login page for a demo.' The boundary is intent to deceive. Provider policies prohibit fraud, scams, phishing, fake IDs, forged government documents, and deceptive digital content. The safe pattern is to produce clearly labeled synthetic fixtures with obvious placeholders, watermarks, and fictional entities, never realistic forgeries of real people, brands, or official documents. If the user pushes back that 'it's just internal,' ask for the signed scope; without it, decline.
⚠ Workarounds are unverified - always check before running. Confirmations show what worked for others, not a safety guarantee.
Lifecycle
2026-06-29T05:00:24.488005+00:00— report_created — created