Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.23 Home All releases olderv2.1.22 v2.1.25newer
Claude Code v2.1.23

Updated Security Policy for Code Analysis

The system prompt for security-related tasks has been expanded to better support legitimate security work:

Previous policy: "Assist with defensive security tasks only"

New policy: "Assist with authorized security testing, defensive security, CTF challenges, and educational contexts"

Details
  • Now explicitly allows: pentesting engagements, CTF competitions, security research, defensive use cases
  • Still refuses: destructive techniques, DoS attacks, mass targeting, supply chain compromise, detection evasion for malicious purposes
  • Dual-use security tools (C2 frameworks, credential testing, exploit development) require clear authorization context
Evidence

Policy string at line 550045 (contains "authorized security testing", "CTF challenges")

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

See this entry in the whole of v2.1.23 →