What's wrong with this entry?
The system prompt for security-related tasks has been expanded to better support legitimate security work:
Previous policy: "Assist with defensive security tasks only"
New policy: "Assist with authorized security testing, defensive security, CTF challenges, and educational contexts"
- Now explicitly allows: pentesting engagements, CTF competitions, security research, defensive use cases
- Still refuses: destructive techniques, DoS attacks, mass targeting, supply chain compromise, detection evasion for malicious purposes
- Dual-use security tools (C2 frameworks, credential testing, exploit development) require clear authorization context
Policy string at line 550045 (contains "authorized security testing", "CTF challenges")
Strings lifted out of the shipped bundle, so the claim above can be checked against them.