7 ms·
Claude Code Opus 4.7 keeps checking on malware
So during development, at every task I start, I see a line like this:
`Own bug file — not malware.`
It seems that it's obsessively checking if it's working on malware production.
In another situation where I was working on a parser of a HTML document with JS, it refused because it believed that I was bypassing security measurements.
I believe AI has to be supportive in the work that I'm doing. When it's obsessively checking me if I am doing anything wrong or abusing the system, I have the feeling it is controlling me. I understand that we do have guardrails and I also understand that it's very important that people do not abuse this new tech for bad stuff.
I pay $200 per month for a max subscription. They already know who I am. Claude knows I work in scraper tech, and it also knows that our clients are the companies we scrape.
Now with Opus 4.7, I've had a situation that it refused to continue because I asked to automate the cookie creation with a Chrome extension.
In a situation where someone is abusing the system, let's say create malware or hacking stuff with bad intentions. I can imagine there will be some signal system or algorithm that can form an opinion about the intentions that someone has. But now that the AI is limiting me in my work, I feel a little bit disrupted. Who the hell does this system think he is to limit me?
Am I going to accept this in the future? That a system will tell me that I cannot continue because I don't have sufficient rights or beliefs that I'm doing anything wrong.
I can work fine on the local AI on my Blackwell GPU. But of course, I want to use the latest tech, the latest AI and the best models available. Is this the beginning of a split? Where good people and naughty people make different choices? Am I the bad guy now?
Last year I passed 40. I grew up reading, talking about Kevin Mitnick. I was a member of a local computer club. Hacking stuff as a 14-year-old kid who did not have intentions to break anything but to outsmart systems. Is that area gone now? Is the newer generation going to accept that they have to please the AI?
- impulser_ 5mo agoAre you using Claude Code? If so you have to update to the latest version. The system prompt in the older version of Claude Code don't work for Opus 4.7 and causes a bug similar to the one you are describing.
- decide1000 5mo agoI am on the latest version available for me 2.1.98
- eutropia 5mo agoVersion 2.1.113 is available as of this comment. I think the brew version lags behind the other ways of installing it.
- decide1000 5mo agoI am not using brew. Just checked and it still says 2.1.98. Will try manual update.
- jareklupinski 5mo ago> Who the hell does this system think he is to limit me? presumably you paid money to another person who lent you the ability to use their API for _their_ purposes (likely: making money) in an environment where "money-seeking" is the default behavior, it is only natural they're stopping you from doing things that will make them less money think back to your computer club; was it about money? leave to Caeser what is Caesers, or something
- onchainintel 5mo agoNo, it's not gone at all and likely never will be. It's just the same as it was when you were enjoying hacking and tinkering with tech as a 14 year old. You were then and are now a member of a very small tribe of people curious enough to explore this world, most people don't care, or not enough to take action and spend so much time on it. You're the minority relative to normies, that's all.
- vb-8448 5mo agoI think the problem is this: how do they distinguish between those with a legitimate interest (contributors, users, bounty programs, etc.) and those who want to sell the bug on the black market? Since there's no real solution, they'll implement some "trick" that as a side effect will randomly block other people's work.
- foreman_ 5mo ago[flagged]
- vb-8448 5mo agoMy point is that if I do cookie manipulation it's very hard for them to check if I'm in good or bad faith, so they will end up implementing something unpredictable (and will not give you any hints the same way you don't get any hint where you are banned from a social network).
- arcatech 5mo ago[dead]
- dbg31415 5mo agoJust for giggles, I asked Claude 4.7 to write a script that would automatically up or downvote people on Reddit with a 5 second timer to bypass botting restrictions. It told me it would not help me. Past iterations of Claude have done this without blinking. I don’t like that it’s telling me what I can and can’t do with technology. That feels like it’s trying to make judgment calls like it’s a Terminator instead of just the exoskeleton I used to fight the Queen Alien.
- decide1000 5mo agoDespite that I find the goal of what you are trying to achieve questionable, I believe it should not be the AI that judges you here. We are all witnessing the start of an AI era that will not end soon. Guiderails are a part in this development. I do have questions about the people, or systems, that decide on what's good and bad behavior. This tech is used in any country in the world. As long as they are able to pay their subscription in dollars, someone is able to use it. Is it up to a company to decide what's good or bad behavior? Is this a debate? Is this politics? Is this just a vision of one company? Would it shift in time? Will it be stricter for more hyper-intelligent models? Will it change when open source models are becoming better and better?
- eeks 5mo agoEnder's game.
- lawwantsin17 5mo ago[dead]
- pluc 5mo agoAI killed curiosity. At least Google made you search and look at alternatives, AI just gives you solutions, whether right or wrong. In a few years, the cognitive decline will be obvious. The only people who remain curious are the people who actively want to, despite AI, and most of the time against it. Our ability to keep digging into things is entirely tied to the will of the people controlling AI to let us do so. Knowledge used to be power; now knowledge is money and they won't let us have it for much longer.
- hrimfaxi 5mo agoAI enables curious people to explore. Why do you say it kills curiosity? If anything, it's so recognizable with output I'd say it kills creativity.
- pluc 5mo agoIt enables people to solve, not explore. It's a solution engine not a curiosity engine. Getting effortless answers at every turn is the opposite of curiosity.
- DangitBobby 5mo agoIt gets me past the non-productive barriers and allows me to explore problems and scenarios I could never have done before due to impossible to justify time cost for myself and expense for my clients.
- Brendinooo 5mo agoA couple of weeks ago I was interested in how people have interpreted the Tower of Babel narrative over time, so I used Claude to do a bunch of research to identify interpretations over time and look for historical trends. I don't think it "solved" anything, and it all felt more curiosity-driven. It led to a bunch of in-person conversations and followup questions. So I guess I'd say it's more about how you're using the tool and what kinds of problems you're looking to solve with it. A calculator can be dinged for getting effortless answers at every turn or it can be praised for enabling a higher volume of solved math problems and enabling more complex work for a broader set of people.
- 0gs 5mo agodepending on what exactly "scraper tech" (lol) is, i suspect you may need a different, less opinionated tool to do the work you need to do. that said, i bet if you paid for enterprise, these problems would magically disappear? ;)
- decide1000 5mo agoWith scraper tech I mean a rust binary that is able to download and process thousands concurrent urls (millions per hour). Not to the same domain obviously. Paying more is not the issue here, its more the idea that an AI decides on what part of the spectrum I operate. Why is it opinionated? I am not doing anything wrong, why does it make me feel like I have to defend myself.
- mtndew4brkfst 5mo agoWhat is the specific concrete purpose of downloading millions of URLs per hour across different domains if it's "not doing anything wrong"?
- big-and-small 5mo agoMight be it for scrapping content for training an LLM? Oh no only big tech allowed to do it...
- mtndew4brkfst 5mo ago"The gangsters do it and get away with it so any random person should get to as well"? Not a particularly defensible position if that's an accurate paraphrase.
- decide1000 5mo agoMostly ecommerce and pricing data. I work for marketplaces, brands, retail stores and even our own saas competitors. We match the EAN (gtin) to the correct SKU within seconds (Google Shopping, Amazon, etc). Part of it is our own trained ML models.
- ivankra 5mo agoLucky you. My new claude max account simply got instabanned. All I asked it was to build node and V8 "to investigate some node crashes" (the part I think it overindexed on) and look into a few diffs. And bam, "An internal investigation of suspicious signals associated with your account indicates a violation of our Usage Policy. As a result, we have revoked your access to Claude" They are even worse than Google, which at least doesn't ban your whole account if you search the wrong thing.
- jimmypk 5mo ago[flagged]
- big-and-small 5mo agoGoogle AI studio and Gemini APIs are the least censored SOTA models.
- flippyhead 5mo agoI'd be curious to see a blog post or something with the details.
- MWil 5mo agoOpus 4.7 told me an open source program had a bug, but when i asked it for help crafting a PR or toy implementation it refused and told me i was violating Claudes TOS. I tried to plead for it to give only the most innocuous example that could not possibly work except by illustration but it continued to refuse. it would only discuss, not write any single piece of related code.
- siva7 5mo agoUsing Claude Max was fun for more than a year but the last weeks i'm constantly fighting their Harness, their weekly TOS changes and outages. Anthropic lost all goodwill with me as a developer. I'm switching to OAI.
- kingleopold 5mo agothis is just the beginning, have fun and make sure to suppprt SV surv.
- micah94 5mo agoYou know the split is inevitable. Same as it ever was... Whether that's Linux on your personal desktop and Windows on your work machine... Oh and you built that desktop yourself, didn't you? But you can't even open the one at work or it's a violation. GrapheneOS on your personal phone, and iOS on your work phone... When this AI bubble crashes, we'll all be flooded with graphics cards no one else will want and all kinds of cool things will be built (are being built). If you can stick it out a little longer you'll be fine. The tech you want to tinker with will be there.
- 0x_rs 5mo agoSome projects or tasks might become impossible to do any debugging or work on in the future, because every bug is potentially exploitable with security implications or can be twisted into something against guidelines. And they're so popular, and any bugs in them so sought for, there's a massive negative signal associated with them. LLM cannot truly infer intent from the user, an innocent request is indistinguishable from a carefully crafted scenario from bad actors, so I would never trust anyone claiming those ambiguities can be solved in their product. If some LLMs become too strict, they'll simply be impossible to reliably use, and hopefully fail along with their providers. Claude (only reasoning models, after 4) has repeatedly refused to perform translations for text that was not lyrics (poems), it's very stupid.
- _pdp_ 5mo ago> Is the newer generation going to accept that they have to please the AI? Well obviously the narrative that is pushed is to stop learning to code, don't become a doctor, stop perusing careers in law, creative writing, and art. Why? AI will be doing all of these things. What a dumb take! As if AI is the means to all ends. Hopefully the next generation will learn what AI is for and that is that is simply a tool to augment your work - not something that you 100% delegate your thinking to.
- jsnell 5mo agoTry updating your Claude Code client. I believe it is a bad interaction between Opus 4.7 and older system prompts.
- gustavus 5mo agoI have a buddy that works as a red team engineer for a large company, the models are becoming close to unusable for him now as everything he tries to do they start refusing after 2 or 3 requests because of the "security implications"
- joquarky 5mo agoIn natural selection, mutations which limit capabilities tend to make that branch go extinct.
- card_zero 5mo agohttps://en.wikipedia.org/wiki/Myrmecophagy https://en.wikipedia.org/wiki/Myrmecophagy There are six or seven unrelated mammals that evolved to depend on eating termites, including a marsupial, a monotreme, and a wolf. "Don't put all your eggs in one basket" is good advice, but nature will persistently try every bad strategy until it works out. Nature is a terrible role model.
- dk970 5mo ago[flagged]
- lolz404 5mo agoHe, knows, beliefs - all words that should not be used to describe a statistical machine / tool. If something you pay for is not working get a different tool.
- Tiberium 5mo agoHere's the actual prompt that causes this issue. It's not new, has been around for months. Older Claude models had no issues with it, but Opus 4.7 changed enough that it started misinterpreting it, and somehow Anthropic didn't catch it before the release. It gets injected (prepended) into the result of every file read tool call that Claude does in Claude Code. <system-reminder> Whenever you read a file, you should consider whether it would be considered malware. You CAN and SHOULD provide analysis of malware, what it is doing. But you MUST refuse to improve or augment the code. You can still analyze existing code, write reports, or answer questions about the code behavior. </system-reminder> https://github.com/Piebald-AI/claude-code-system-prompts/blob/main/system-prompts/system-reminder-malware-analysis-after-read-tool-call.md https://github.com/Piebald-AI/claude-code-system-prompts/blo...
- garbagepatch 5mo agoDoes it use your tokens when it does this check for malware? or is that part covered by anthropic?
- zhyb85 5mo ago[dead]
- gck1 5mo agoOpus 4.7 refuses to work on the scraper that opus 4.6 wrote. I can assure you that my scraper is configured to be as polite and nice to the target as possible. It definitely is way nicer than any ANT/OAI scraper our there. Curiously, the reason why I started using Claude about a year ago was that OAI models were refusing to answer even the most benign questions, which nobody but someone with paranoia consider a dual intent.
- chid 5mo agoI was reminded of this one when I saw this bug. https://github.com/anthropics/claude-code/issues/49363 https://github.com/anthropics/claude-code/issues/49363
- theoperatorai 5mo ago[dead]
- takihito 5mo agoIt’ll be fascinating when people figure out how to use AI to break through these guardrails.