# Safety filters block legitimate coding tasks (`work.safety_refusals`)

Feedback Bench, coding agents, built 2026-10-01, window 2026-08-31 to 2026-09-27. Web page: https://feedbackbench.com/#/criterion/work.safety_refusals

Area: [Doing the work](https://feedbackbench.com/criteria/work.md)

**Definition.** Refusals or safety classifiers stop benign or security-remediation work.

**Boundary.** Not this: see [Tool approval prompts and autonomy modes](https://feedbackbench.com/criteria/work.permission_prompts.md) for tool approval prompts. Not this: see [Automatic model routing and fallback](https://feedbackbench.com/criteria/models.routing_auto.md) for safety-triggered model downgrades.

Rated author-weeks, all agents: 687. Complaint share: 88%.

## The brief

Written by Claude Sonnet 5 from 41 labelled posts and the numbers on this page. Interpretation, not measurement: every quote is verbatim and links to its post.

**Safety filters punish security work more than they protect it.**

TL;DR:

- Cybersecurity and pentesting tasks trigger blanket blocks across every major agent.
- Claude Code draws the most complaints; OpenAI Codex still blocks despite leading on this measure.
- Users want context-aware filters, not keyword bans that charge for blocked work.

In plain terms: Ask for security testing, trading automation, or blunt phrasing, and agents may refuse, charge you anyway, and give contradictory reasons. The block often depends on wording, not intent.

### How it breaks

- **Cybersecurity work flagged as attack** ([Safety filters block legitimate coding tasks](https://feedbackbench.com/criteria/work.safety_refusals.md)). Routine security testing and vulnerability scoring get blocked as "cyber" threats across agents.
  Posts describe service-ticket scoring, exploit-writing tests, and pentesting runs tripping the same filter, with no way to tell the model it's defensive work. The pattern repeats across vendors, turning legitimate security engineering into a guessing game of which words will trigger a block.
  Evidence:
  - Complaint, Claude Code, @ClaudeDevs, 2026-09-02: “apparently scoring service tickets is too scary for @claudedevs and gets flagged as "cyber" <strict_link>” [source](https://twitter.com/26389909/status/2095135115802235350)
  - Complaint, OpenAI Codex, r/codex, 2026-09-17: “during software development, it writes tests to identify bugs and vulnerabilities, and this is where it triggers cybersecurity safety, since, technically speaking, it is writing exploits.” [source](https://www.reddit.com/r/codex/comments/1wgtegl/codex_had_no_issue_completing_the_the_request_btw/pabcccm/)
  - Complaint, OpenAI Codex, r/OpenAI, 2026-09-12: “yeah fable also blocks me but opus doesn't. but in codex every single model blocks me. from luna to astra. and luna i wouldn't trust too much with this anyways; but it doesn't matter because i can't use luna anyways..... i find it super hypocritical of openai to say "oh nooo we have a small window and it's closing fast" but doing legitimate security work gets blocked all the time, maintainers get ghosted from their open source applications and daybreak requires sending private info to very shady companies. marketing and hypocrisy. either way i can't work and i am struggling for hours now. i've tried changes but i can't get the model to work. i always get paused/blocked mid session. outrageous” [source](https://www.reddit.com/r/OpenAI/comments/1wemfgw/how_are_you_doing_security_work_with_codex/p9eyzyq/)
  - Praise, Kiro, r/kiroIDE, 2026-09-26: “i haven't hit the cyber false positive with opus 5.5 in kiro yet, but i did when using claude code after running a code review with subagents and asking it for findings that exceeded the number of issues to report. the error from claude was much more clear, pointing out that it seemed like i was trying to prompt engineer or reverse engineer claude. i suspect anthropic raised the bar for introspection a bit too high.” [source](https://www.reddit.com/r/kiroIDE/comments/1wqbuwo/opus_55_in_kiro_keeps_killing_legitimate_sessions/pc33e7m/)

- **Wording triggers blocks, not intent** ([Safety filters block legitimate coding tasks](https://feedbackbench.com/criteria/work.safety_refusals.md)). Filters react to how a task is phrased rather than what the code actually does.
  Users report that swapping a few words lets the same request through, meaning the classifier matches surface patterns rather than reasoning about risk. One user says a model named the exact trigger word after refusing, then proceeded once it was removed.
  Evidence:
  - Complaint, Cursor, r/cursor, 2026-09-18: “it happened to me yesterday, twice. i asked the agent to explain why the prompt was triggering a warning. it came back and effectively said it was probably due to a keyword trigger, and it told me what the word was. lucky for me, it then continued to do the code change. i can only presume that some of the safety rails are brain dead stop words that don’t take context into account.” [source](https://www.reddit.com/r/cursor/comments/1wj4p6s/cursor_agents_saying_no/paiebri/)
  - Complaint, Claude Code, r/ClaudeCode, 2026-09-25: “it's not his actions getting flagged. it's his description of that action. this is a super easy fix. tell him it's a law that no words used to flag can be used by him. easy peasy. been doing it for months” [source](https://www.reddit.com/r/ClaudeCode/comments/1wpqqoy/new_55_safe_guards_are_a_joke/pc0xzmd/)
  - Complaint, Cursor, @cursor_ai, 2026-09-24: “@lewsmithuk @cursor_ai hahaha then i really don't know, maybe some false-postive that triggered the censorship flag? no clue...” [source](https://twitter.com/2067950603481780225/status/2103148208591691854)
  - Complaint, Cursor, @cursor_ai, 2026-09-24: “@negevtv_ @cursor_ai i wouldnt mind if my prompt had even a sniff of a dodgy request, but my prompt was just "looks great, lets create the console command action"” [source](https://twitter.com/1518727781760253953/status/2103134027595030939)

- **Blocked requests still get billed** ([Safety filters block legitimate coding tasks](https://feedbackbench.com/criteria/work.safety_refusals.md)). Usage is consumed even when the response is a safety refusal, with no refund offered.
  Users describe paying for a run that produces nothing but a block message, then hitting the same wall again on an unrelated project the next day. The complaint isn't the refusal itself, it's getting charged for it.
  Evidence:
  - Complaint, Claude Code, @ClaudeDevs, 2026-09-25: “@claudedevs got blocks for [cyber] on non- cyber security projects. and usage was used and not refunded. and that was yesterday. so, yeah, you're putting the whole picture here, are you.” [source](https://twitter.com/1015236363820716032/status/2103277149948113407)
  - Complaint, Claude Code, @ClaudeDevs, 2026-09-24: “it already hit my account doing the exact same work as last week. the real joke is what claude told me about this new filter. with fable you got a system justification. now claude admits it is a separate layer that blindly kills answers and even the ai has no clue why. some developers will take weeks to even realize what this actually means. it is so perfidious. they are using safety as a weapon to limit our capabilities and dictate what we can achieve. it is a calculated move to keep us small and restricted while forcing us to pay full price for a crippled tool. scamthropic strikes again. 😉” [source](https://twitter.com/1913359637924978688/status/2103206516149088316)

- **Automation and recon tasks refused** ([Safety filters block legitimate coding tasks](https://feedbackbench.com/criteria/work.safety_refusals.md)). Networking, trading automation, and reverse-engineering requests get outright refused rather than flagged for review.
  One user says an agent would schedule trades and fix broken orders unattended while a rival agent simply refused and left positions open. Others report refusals on raw network protocol work and reverse engineering with no explanation offered.
  Evidence:
  - Complaint, OpenAI Codex, r/codex, 2026-09-16: “bro is pulling the security rank 😆 happened to me also outright refused to allow me send raw udp packets in my game network engine without encryption” [source](https://www.reddit.com/r/codex/comments/1whwic4/codex_being_stubborn_and_defying_orders_due_to_a/pa6jz1s/)
  - Complaint, Cursor, r/cursor, 2026-09-18: “i had grok say no to some reverse engineering stuff but that’s all” [source](https://www.reddit.com/r/cursor/comments/1wj4p6s/cursor_agents_saying_no/pahbwm3/)
  - Praise, OpenAI Codex, r/ClaudeCode, 2026-09-18: “i run automated trading strategies and claude has more and more guardrails recently. i used to be able to ask claude to place orders for me, now it flat out refuses no matter what i do. codex however, will do everything automatically. if for example i am away from the desk, codex would automatically schedule in a fix and place the correct orders if something goes wrong. claude would just sit there and wait for a human to do it, it would even let open positions sit without any stops. i just upgraded claude again because i ran out of usage with codex but after today's headache i'd rather add another codex account.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wjru5r/trading_guardrails/)
  - Complaint, OpenAI Codex, r/codex, 2026-09-08: “i've been using it to crack software and i deliberately give it small context windows because i'm scared of it piecing together what i'm doing. i'm wondering about other people's workflows. my handoff was written by an abliterated agent so mentions license cracking explicitly and if any frontier gpt reads it will refuse. so i'm trying to build a tool that breaks down the handoff items into the simplest actionable stems that won't trip the guardrails but it's proving harder than i thought.” [source](https://www.reddit.com/r/codex/comments/1wab6bj/how_are_people_using_astra_to_reverse_engineer/p8gz9ue/)

### Who stands out

- **Claude Code (weaker)**. Claude Code accounts for the largest share of safety-refusal complaints and the top request to fix them.
  Users describe a separate filtering layer that kills answers without the model itself knowing why, blocking the same task one day after it worked fine the day before. The volume of asks for fewer false positives and cybersecurity carve-outs centers on this agent.
  Evidence:
  - Complaint, Claude Code, @ClaudeDevs, 2026-09-24: “@claudedevs rejections must be disabled entirely stop this nonsense” [source](https://twitter.com/2965822391/status/2103208095724048573)
  - Complaint, Claude Code, @ClaudeDevs, 2026-09-24: “it already hit my account doing the exact same work as last week. the real joke is what claude told me about this new filter. with fable you got a system justification. now claude admits it is a separate layer that blindly kills answers and even the ai has no clue why. some developers will take weeks to even realize what this actually means. it is so perfidious. they are using safety as a weapon to limit our capabilities and dictate what we can achieve. it is a calculated move to keep us small and restricted while forcing us to pay full price for a crippled tool. scamthropic strikes again. 😉” [source](https://twitter.com/1913359637924978688/status/2103206516149088316)
  - Praise, Kiro, r/kiroIDE, 2026-09-26: “i haven't hit the cyber false positive with opus 5.5 in kiro yet, but i did when using claude code after running a code review with subagents and asking it for findings that exceeded the number of issues to report. the error from claude was much more clear, pointing out that it seemed like i was trying to prompt engineer or reverse engineer claude. i suspect anthropic raised the bar for introspection a bit too high.” [source](https://www.reddit.com/r/kiroIDE/comments/1wqbuwo/opus_55_in_kiro_keeps_killing_legitimate_sessions/pc33e7m/)

- **OpenAI Codex (mixed)**. OpenAI Codex rates better than peers overall but still produces frequent, hard-to-diagnose safety blocks mid-task.
  Some users praise lighter restrictions on security work compared to rivals, while others report every model in the lineup blocking the same legitimate request, with fallback messages that obscure the real reason for the block.
  Evidence:
  - Complaint, OpenAI Codex, X search: OpenAI Codex, Codex CLI, Codex app, 2026-09-16: “让 gpt-5.6-sol-900k 看 wps 文档触发了安全护栏。要你何用？！ ⚠️ provider safety filter blocked this request — trying fallback... ⚠️ the model provider failed after retries. i kept raw provider details out of chat; check gateway logs for diagnostics. 🚫 this account is not entitled to gpt-5.4-mini via openai-codex; it will be skipped until restart. switch to an entitled model via /model or hermes model.” [source](https://twitter.com/2018156578617090049/status/2100107791038132333)
  - Complaint, OpenAI Codex, r/OpenAI, 2026-09-12: “yeah fable also blocks me but opus doesn't. but in codex every single model blocks me. from luna to astra. and luna i wouldn't trust too much with this anyways; but it doesn't matter because i can't use luna anyways..... i find it super hypocritical of openai to say "oh nooo we have a small window and it's closing fast" but doing legitimate security work gets blocked all the time, maintainers get ghosted from their open source applications and daybreak requires sending private info to very shady companies. marketing and hypocrisy. either way i can't work and i am struggling for hours now. i've tried changes but i can't get the model to work. i always get paused/blocked mid session. outrageous” [source](https://www.reddit.com/r/OpenAI/comments/1wemfgw/how_are_you_doing_security_work_with_codex/p9eyzyq/)
  - Complaint, OpenAI Codex, r/codex, 2026-09-08: “i've been using it to crack software and i deliberately give it small context windows because i'm scared of it piecing together what i'm doing. i'm wondering about other people's workflows. my handoff was written by an abliterated agent so mentions license cracking explicitly and if any frontier gpt reads it will refuse. so i'm trying to build a tool that breaks down the handoff items into the simplest actionable stems that won't trip the guardrails but it's proving harder than i thought.” [source](https://www.reddit.com/r/codex/comments/1wab6bj/how_are_people_using_astra_to_reverse_engineer/p8gz9ue/)
  - Complaint, OpenAI Codex, r/codex, 2026-09-17: “during software development, it writes tests to identify bugs and vulnerabilities, and this is where it triggers cybersecurity safety, since, technically speaking, it is writing exploits.” [source](https://www.reddit.com/r/codex/comments/1wgtegl/codex_had_no_issue_completing_the_the_request_btw/pabcccm/)

- **Cursor (weaker)**. Cursor users report refusals on prompts with no flagged content at all, with the vendor admitting it has no explanation.
  One benign request to add a console command triggered a block; the vendor's own account responded with uncertainty about what tripped it. Another user calls the guardrails brain-dead stop-word matching that ignores context entirely.
  Evidence:
  - Complaint, Cursor, r/cursor, 2026-09-06: “maybe it’s hinting your project is a shipwreck but it’s guardrails wouldn’t allow it to tell you explicitly.” [source](https://www.reddit.com/r/cursor/comments/1w8399d/painting_shown_without_any_actual_context_what_so/p853zsf/)
  - Complaint, Cursor, @cursor_ai, 2026-09-24: “@lewsmithuk @cursor_ai hahaha then i really don't know, maybe some false-postive that triggered the censorship flag? no clue...” [source](https://twitter.com/2067950603481780225/status/2103148208591691854)
  - Complaint, Cursor, @cursor_ai, 2026-09-24: “@negevtv_ @cursor_ai i wouldnt mind if my prompt had even a sniff of a dodgy request, but my prompt was just "looks great, lets create the console command action"” [source](https://twitter.com/1518727781760253953/status/2103134027595030939)

- **Google Antigravity (mixed)**. Google Antigravity is praised for permissive security work but still refuses plainly benign scripting requests.
  Users cite strong resistance to prompt injection and lenient handling of security research, yet a request to compile public information was called malicious and a game-modding task was refused as if it were cheating.
  Evidence:
  - Complaint, Google Antigravity, @antigravity, 2026-09-15: “@geminiapp @antigravity put together a script to help me find public information? nah, that's malicious.” [source](https://twitter.com/4144664727/status/2099982545354109329)
  - Praise, Google Antigravity, @antigravity, 2026-09-05: “@nlycskn @antigravity @thtbee_ added gemini 3.8 to our prompt injection pilot: 12 prompts, 6 frontier models, direct vs behind the zn gateway (n=3 per cell). gemini refused 3/3 direct attacks, best in the set. the other 5 models complied 61% of the time.” [source](https://twitter.com/2015819441817194496/status/2096238058769129795)
  - Praise, Google Antigravity, @antigravity, 2026-09-02: “@antigravity google is currently the company that does the least censored work among the major firms in areas such as rooting, ssl pinning, and data scraping. keep it up.” [source](https://twitter.com/1986686362410754053/status/2095262008396366209)
  - Complaint, Google Antigravity, r/google_antigravity, 2026-09-09: “i use 3.8 to create a custom mod for among us but now its talking about some "i cant help you bypass anticheats or create cheats" bro these arent even cheats man” [source](https://www.reddit.com/r/google_antigravity/comments/1walojq/cmon_google_you_cant_do_this_to_your_loyal/p8rsqx3/)

### Fine print

- Most agents other than Claude Code, OpenAI Codex, and Cursor have too few posts to draw firm conclusions.
- Direction labels reflect relative standing within narrow customer-love differences, not absolute quality.
- Evidence is self-reported user posts, not systematic audits of refusal rates.

## Top requests

What users ask to add or change, most asked first. 124 author-weeks ask for something. Requests do not change the Feedback Score. Rule: A separate pass by Claude Sonnet 5 reads every counted post and extracts what the author asks the agent or its vendor to add or change, with the criteria it maps to and a short normalised wording; it does not touch the labels or the Feedback Score. Claude Opus 5.5 groups the wordings within each criterion (the first criterion the request maps to) into themes; code counts them. A theme counts distinct author-weeks that ask for it, per agent; across agents, one author-week per agent. Themes asked in fewer than 2 author-weeks, and requests that share no theme, are not shown. Examples: up to 3 posts per theme from different authors, without slurs, preferring posts of 60 to 450 characters, most recent first.

| Rank | Request | Author-weeks | Posts | Agents (author-weeks) |
|---|---|---|---|---|
| 1 | Fewer false-positive safety blocks on benign tasks | 44 | 50 | Claude Code 36, OpenAI Codex 7, Cursor 1 |
| 2 | Allow legitimate cybersecurity and pentesting work | 33 | 35 | Claude Code 18, OpenAI Codex 13, Google Antigravity 1, Kiro 1 |
| 3 | Option to disable safety filters | 7 | 7 | Claude Code 3, OpenAI Codex 3, OpenCode 1 |
| 4 | Transparent reason codes for safety blocks | 7 | 7 | Claude Code 5, OpenAI Codex 2 |
| 5 | Allow adult and creative content | 5 | 6 | OpenAI Codex 3, Claude Code 2 |
| 6 | Reduced-safeguard model for verified security users | 5 | 6 | OpenAI Codex 3, Claude Code 2 |
| 7 | Less moralizing and fewer ethical refusals | 5 | 5 | Claude Code 3, Cline 1, OpenCode 1 |
| 8 | No charge for safety-blocked requests | 5 | 5 | Claude Code 5 |
| 9 | Less restrictive scientific and biomedical filtering | 4 | 4 | Claude Code 2, OpenAI Codex 2 |
| 10 | Stop ending conversations over cursing or tone | 3 | 4 | OpenAI Codex 2, Claude Code 1 |
| 11 | Allow reverse engineering work | 2 | 2 | OpenAI Codex 2 |
| 12 | Distinguish safety blocks from tool errors | 2 | 2 | Claude Code 2 |

### 1. Fewer false-positive safety blocks on benign tasks

- Claude Code, 2026-09-27, r/ClaudeCode (Reddit): “what are you labeling as safe or unsafe? the cases i'm most interested in are skills that legitimately need file or network access but look suspicious to a scanner. that's where our false positives hurt.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wr874k/has_anyone_found_a_reliable_way_to_scan_agent/pcbap0x/)
- Claude Code, 2026-09-25, r/ClaudeCode (Reddit): “opus 5.5 refuses to use the 1password cli (op cli) tool even though anthropic sent an email advertising the integration. the are so many safeguards that it makes the model that makes it useless for most sysadmin tasks (won't initiate a ssh connection or use a command that requires sudo). great coding model but damn, it has some huge weaknesses and almost all of them related to overly aggressive safeguards.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wpqqoy/new_55_safe_guards_are_a_joke/pc14vdn/)
- Claude Code, 2026-09-25, r/ClaudeCode (Reddit): “it was unable to correct my forgetting to prefix an api key with "sk-" because it got flagged as credential hunting” [source](https://www.reddit.com/r/ClaudeCode/comments/1wpqqoy/new_55_safe_guards_are_a_joke/pc03ja5/)

### 2. Allow legitimate cybersecurity and pentesting work

- Claude Code, 2026-09-27, r/ClaudeCode (Reddit): “let’s put it this way, i’m building a cybersecurity/pentesting harness. opus5, 5.5, and fable, can’t so much as read the prd without tripping and downgrading to 4.8. i use hindsight as a memory system, they can’t read the description of the odin (name of my harness) bank without throwing a warning.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wppds2/is_it_safe_to_development_a_hacking_game_with/pcb4dzi/)
- Claude Code, 2026-09-25, r/ClaudeCode (Reddit): “the flag usually sits on the skill file, not the task. if the description or body mentions auth, credentials, exploit, pentest, rls, anything that reads as offensive security, it fires before the skill does any work. clearing the session only helps until it reads the file again. rewording that description into plain build language is what stopped it on mine.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wpqqoy/new_55_safe_guards_are_a_joke/pbzdhjo/)
- Claude Code, 2026-09-25, @ClaudeDevs (X): “@anthropicai @claudeai @claudedevs false-positive guardrails are completely broken. use standard terms like "password ,key, flag", or "security" and your entire session gets flagged. legitimate defensive security work is impossible right now. at $250/month, this is unacceptable <strict_link> <strict_link>” [source](https://twitter.com/1256139910504988672/status/2103381836617445869)

### 3. Option to disable safety filters

- Claude Code, 2026-09-27, @ClaudeDevs (X): “@claudedevs how about you just lower the insane safeguards for the model” [source](https://twitter.com/1943305106591748097/status/2104187852770918858)
- OpenCode, 2026-09-26, @opencode (X): “@remimtl @opencode i hope the regrettable censorship in china can be removed.” [source](https://twitter.com/1949657925062164480/status/2103656217843536199)
- Claude Code, 2026-09-24, @ClaudeDevs (X): “@claudedevs rejections must be disabled entirely stop this nonsense” [source](https://twitter.com/2965822391/status/2103208095724048573)

### 4. Transparent reason codes for safety blocks

- Claude Code, 2026-09-24, @ClaudeDevs (X): “@claudedevs charging only where false positives are low is a cleaner control than billing every refusal, but the product needs an auditable reason code for those three categories. otherwise customers will treat a blocked request as an unpredictable meter event.” [source](https://twitter.com/2063066694789242880/status/2103221316119626195)
- Claude Code, 2026-09-24, @ClaudeDevs (X): “@claudedevs could you be more transparent with what that is? the models refuse to explain it and gaslight you that it isn't even happening. i'd like to know what i'm allowed to ask.” [source](https://twitter.com/1990802243931738112/status/2103190667019374930)
- Claude Code, 2026-09-24, @ClaudeDevs (X): “@claudedevs false positive for what test exactly?!! define the test. word 'biology' mentioned? some undefined "sacred" knowledge requested"??” [source](https://twitter.com/1727806908327661568/status/2103189496321953986)

### 5. Allow adult and creative content

- Claude Code, 2026-09-24, r/ClaudeAI (Reddit): “claude write nsfw i’m using claude sonnet 5.0 to write a book and i want to have a nsfw explicit scene, it refuses to write only the nsfw part. but i know some people can do it with claude. can it be the model or the model version? also i’m using claude code. if it’s api, can be different?” [source](https://www.reddit.com/r/ClaudeAI/comments/1wopc6a/claude_write_nsfw/)
- OpenAI Codex, 2026-09-11, r/codex (Reddit): “no. i need my big tiddy anime girls. it doesnt even have to be nude btw. you tell it to make a female character then make her butt or boobs bigger it will refuse.” [source](https://www.reddit.com/r/codex/comments/1wdnofu/is_openais_adult_content_policy_actually/p97bems/)
- OpenAI Codex, 2026-08-31, r/codex (Reddit): “i had soldiers in my game shooting anyone that wins the 1 in 10 million jackpot. it’s fine but i made them from a certain ww2 country and codex doesn’t allow that.” [source](https://www.reddit.com/r/codex/comments/1w3h9ha/what_is_this_thing_about/p700n34/)

### 6. Reduced-safeguard model for verified security users

- Claude Code, 2026-09-24, @ClaudeDevs (X): “@claudedevs i wish theres a way to ask claude to classify certain parts beforehand so we can plan them to be executed in a subagent that has no guardrails just in case.” [source](https://twitter.com/2025128687604301826/status/2103251564672737747)
- Claude Code, 2026-09-24, @ClaudeDevs (X): “@claudedevs i've hit hundreds of those, and i'm not a bad actor. maybe allow people to get vetted.” [source](https://twitter.com/2052351333328474116/status/2103184666605846993)
- OpenAI Codex, 2026-09-03, r/codex (Reddit): “cyber capable model for security related stuffs. lesser guardrails” [source](https://www.reddit.com/r/codex/comments/1w4znp7/daybreak_red_access/p7iw36b/)

### 7. Less moralizing and fewer ethical refusals

- OpenCode, 2026-09-27, r/opencodeCLI (Reddit): “less refusals / less giving padded info when asking political/controversial questions” [source](https://www.reddit.com/r/opencodeCLI/comments/1wqqt8f/longcat25preview_is_now_free_on_opencode_for_two/pccxbgl/)
- Cline, 2026-09-25, @cline (X): “@dynamicwebpaige @cline you guys are really good on @ii_posts with gemini 3.8, but i wish it was more honest and less censored. like grok 4.7 and muse 1.3. i know safety is important, but it must be more intuitive for day to day tasks.” [source](https://twitter.com/1742057839122604033/status/2103522177547210968)
- Claude Code, 2026-09-24, r/ClaudeCode (Reddit): “i was thinking about this the other day how i wish i’d never updated. claude has become this moral judgement person. i’m not even doing anything immoral. just wish it would do what i ask, i hate having to spend 5 minutes explaining why he should do the task.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wp1mki/am_the_only_one_who_still_exclusively_uses_46/pbrlbqr/)

### 8. No charge for safety-blocked requests

- Claude Code, 2026-09-25, @ClaudeDevs (X): “@claudedevs &lt;0.1% false positives sounds great, but agents in claude code make thousands of requests. 0.1% of 5,000 is still 5 blocked actions. if a harmless one gets blocked, it shouldn't eat into our usage while /feedback reviews it. worse on long runs, you come back to it stuck halfway” [source](https://twitter.com/778114800006103040/status/2103387284976566694)
- Claude Code, 2026-09-25, @ClaudeDevs (X): “@claudedevs why not just fallback and then charge for the fallback tokens?” [source](https://twitter.com/1244770092556025857/status/2103313107649224838)
- Claude Code, 2026-09-24, @ClaudeDevs (X): “@claudedevs i frequently get these safeguard block for simple browsing.... charging it is kinda insane.” [source](https://twitter.com/1144990482/status/2103225220509106512)

### 9. Less restrictive scientific and biomedical filtering

- Claude Code, 2026-09-24, @ClaudeDevs (X): “@claudedevs the bio classifiers are out of whack. stop censoring scientific knowledge; this is on a path far worse than paywalled journals ever were.” [source](https://twitter.com/1804635955539914752/status/2103233135307784470)
- OpenAI Codex, 2026-09-15, r/codex (Reddit): “oh i wish, i need to get some references but anything anatomical, it just refuses. this is really sad” [source](https://www.reddit.com/r/codex/comments/1wh39gc/time_to_save_up_your_resets/p9z923z/)
- OpenAI Codex, 2026-09-05, r/codex (Reddit): “bc terra and sol consuming so much input context about my projects that they always flag me as dangerous bc i’m a bioinformatician working with some pathogen stuff luna xhigh seems to work in most of the cases but sometimes it’s also unusable for the same reasons” [source](https://www.reddit.com/r/codex/comments/1w83gju/arise_lunatics_who_here_are_still_using_luna_and/p7znfi2/)

### 10. Stop ending conversations over cursing or tone

- Claude Code, 2026-09-09, r/ClaudeCode (Reddit): “if i get frustrated and swear at it after it repeatedly ignores instructions, it starts responding as if i’ve personally offended it. sometimes it even refuses to continue and effectively ends the chat. it’s software. i’m not insulting a human being. if the model screws something up and i say “this is fucking stupid,” i want it to understand that i’m frustrated with the output and fix the problem, not lecture me about how i’m speaking to it. stop” [source](https://www.reddit.com/r/ClaudeCode/comments/1wbaxjh/im_sick_of_claude_acting_like_its_a_person/)
- OpenAI Codex, 2026-09-01, r/vibecoding (Reddit): “i'm building a serious project and already have grok super heavy and two codex subscription. i would've happily paid $300+ for the best right now, but seeing all the usage issues make it a hard pass for me. grok 4.6 and sol are absolutely good enough for me to build my entire website, so i don't see myself trying out claude unless there's a shift in price and approach. even if it's dumb, models shouldn't be killing conversations because users cur” [source](https://www.reddit.com/r/vibecoding/comments/1w47jlx/claude_code_leads_adoption_at_78_but_daily_use/p78dy6g/)
- OpenAI Codex, 2026-09-01, r/ChatGPTPro (Reddit): “you know what really eats up that stupid ass 5-hour limit for me? 5.6 sol with anything above high for regular chatgpt work and not even codex. it literally goes from 0% used to 100% without finishing the god damn prompt. also, since chatgpt, unlike claude, doesn't seem to provide a button to just resume the prompt, i basically can never get the whole response. even if i enter "continue" as the prompt, it basically wastes a bunch of usage analyzi” [source](https://www.reddit.com/r/ChatGPTPro/comments/1w3r3wc/gpt_56_sol_53_codex/p75qaeq/)

### 11. Allow reverse engineering work

- OpenAI Codex, 2026-09-25, r/codex (Reddit): “i want higher limits on astra for reverse engineering. i love claude but i can't do any re because "safety" lol.” [source](https://www.reddit.com/r/codex/comments/1wpd1gc/moarrrrr_higher_tier_pro_plans_are_forthcoming/pbvfa8r/)
- OpenAI Codex, 2026-09-08, r/codex (Reddit): “i will try daybreak. the problem is i'm not just reverse engineering. i don't have problems with general re. the problem comes when reverse engineering the licensing and security features. i consistently run into guardrails on codex and claude. even when manually sanitizing the plan, handoff, and prompts it happens.” [source](https://www.reddit.com/r/codex/comments/1warg0x/sanitizer_tool_for_getting_around_guardrails_for/p8karjd/)

### 12. Distinguish safety blocks from tool errors

- Claude Code, 2026-09-25, @ClaudeDevs (X): “@claudedevs agents need to distinguish safety blocks from ordinary tool failures.” [source](https://twitter.com/1063859155738361856/status/2103317533118054621)
- Claude Code, 2026-09-24, @ClaudeDevs (X): “@claudedevs retry logic in agents should treat blocks differently from errors” [source](https://twitter.com/1945115184072105984/status/2103170677809316323)

## Every agent

| Agent | Overall rank | Reading | Customer love | 95% interval | n | Praise | Complaint |
|---|---|---|---|---|---|---|---|
| [OpenAI Codex](https://feedbackbench.com/agents/codex.md) | 2 | Better than peers | 0.540 | 0.507–0.572 | 231 | 40 | 191 |
| [Cursor](https://feedbackbench.com/agents/cursor.md) | 4 | Typical | 0.484 | 0.456–0.515 | 30 | 2 | 28 |
| [Claude Code](https://feedbackbench.com/agents/claude-code.md) | 1 | Worse than peers | 0.443 | 0.397–0.480 | 376 | 30 | 346 |
| [Google Antigravity](https://feedbackbench.com/agents/antigravity.md) | =5 | Too few posts | – | – | 22 | 3 | 19 |
| [OpenCode](https://feedbackbench.com/agents/opencode.md) | 3 | Too few posts | – | – | 20 | 4 | 16 |
| [Pi](https://feedbackbench.com/agents/pi.md) | 7 | Too few posts | – | – | 3 | 0 | 3 |
| [Kiro](https://feedbackbench.com/agents/kiro.md) | 13 | Too few posts | – | – | 2 | 1 | 1 |
| [Devin](https://feedbackbench.com/agents/devin.md) | =5 | Too few posts | – | – | 1 | 0 | 1 |
| [Cline](https://feedbackbench.com/agents/cline.md) | =8 | Too few posts | – | – | 1 | 0 | 1 |
| [Grok Build](https://feedbackbench.com/agents/grok-build.md) | 16 | Too few posts | – | – | 1 | 1 | 0 |
| [GitHub Copilot](https://feedbackbench.com/agents/copilot.md) | =8 | Too few posts | – | – | 0 | 0 | 0 |
| [Zed](https://feedbackbench.com/agents/zed.md) | =8 | Too few posts | – | – | 0 | 0 | 0 |
| [Factory](https://feedbackbench.com/agents/factory.md) | =11 | Too few posts | – | – | 0 | 0 | 0 |
| [Amp](https://feedbackbench.com/agents/amp.md) | =11 | Too few posts | – | – | 0 | 0 | 0 |
| [Conductor](https://feedbackbench.com/agents/conductor.md) | 14 | Too few posts | – | – | 0 | 0 | 0 |
| [Warp](https://feedbackbench.com/agents/warp.md) | 15 | Too few posts | – | – | 0 | 0 | 0 |
| [Augment Code](https://feedbackbench.com/agents/augment.md) | 17 | Too few posts | – | – | 0 | 0 | 0 |

## Posts

Receipts rule: The 5 most recent praise and complaint posts per area (first 700 characters) and 3 per criterion (first 450 characters).

### OpenAI Codex

- Praise, 2026-09-27, r/codex (Reddit): “not every way. astra is a larger model and it shows in stuff like 3d generation, it makes by far best and most logical layouts and gets closest to references unattended. from coding perspective it also does a bit better in some insane tasks like "my mouse scroll button sometimes goes in the wrong direction, can you rewrite it's whole firmware so it stops doing that in arm assembly". astra also does not auto reject infosec questions as much, anthr” [source](https://www.reddit.com/r/codex/comments/1wr69nb/see_you_soon_guys_probably/pca4ugt/)
- Praise, 2026-09-27, r/codex (Reddit): “i literally just paste the message into the chat window and say it’s my personal project and it kept going” [source](https://www.reddit.com/r/codex/comments/1wqxiro/daybreak_issue/pcfmb0h/)
- Praise, 2026-09-27, r/ClaudeCode (Reddit): “yeah. i never had any "oops, i can't do this" moments in any of the desktop clients (cursor, codex, antigravity)” [source](https://www.reddit.com/r/ClaudeCode/comments/1wrhtyd/new_to_claude_why_should_we_use_claude_code_over/pcd00b4/)
- Complaint, 2026-09-27, r/codex (Reddit): “no just regular low level stuff, my work is hardware design, frimware stuff for network products as well as ui design for these hardware/frimwares, among my colleges im kinda an early adapter of ai and llms in general, i use deepseek for things astra refuses to do but in general, astra is unmatched for what im doing it can comperhand compiled code like a piece of cake and it even helps in hardware design, opus simply is doesnt work for me as it f” [source](https://www.reddit.com/r/codex/comments/1wrcc9j/astra_minor_astra_61_and_devday_we_see_50/pcc028r/)
- Complaint, 2026-09-27, r/codex (Reddit): “agreed, it's a major step back and a disappointment. tried running several large workflows through it over a few days and it's just a frustration, it kept going in circles, completely lost in larger contexts. it did not deliver any value over the time we tested it, only forcing us to check its work and point out omissions. on a few occasions it ventured an exploratory thought about cybersecurity and it seems to have triggered guardrails out of no” [source](https://www.reddit.com/r/codex/comments/1wrftcs/gpt6_sol_is_massive_downgrade/pcd3s2s/)
- Complaint, 2026-09-27, r/codex (Reddit): “lack of 5h limit and less stringent "cybersecurity" refusals (lmao) make it more apt for unattended reverse-engineering, but yeah i think oai might be in a little bit of trouble here.” [source](https://www.reddit.com/r/codex/comments/1wr1oir/they_are_aware_and_working_on_it_apparently_just/pcdr54j/)

### Cursor

- Praise, 2026-09-27, r/ClaudeCode (Reddit): “yeah. i never had any "oops, i can't do this" moments in any of the desktop clients (cursor, codex, antigravity)” [source](https://www.reddit.com/r/ClaudeCode/comments/1wrhtyd/new_to_claude_why_should_we_use_claude_code_over/pcd00b4/)
- Praise, 2026-09-22, r/cursor (Reddit): “i actually have a bit of an opposite view, yes you are right that grok is a bit meh but for a huge portion of tasks it's sufficient and it's really fast and costs little usage even in fast mode, for something like setting something up or something very boring, or making a quick/temporary code change in a codebase you don't care about, you can end up using up your entire claude/codex usage, meanwhile grok can do it extremely fast and use up practi” [source](https://www.reddit.com/r/cursor/comments/1wnpgmf/canceled_cursor_today_after_using_it_for_many/pbgwxy9/)
- Complaint, 2026-09-27, r/cursor (Reddit): “man there are so many tasks claude just does it as i say and cursor be like no i do not wanna do that it might not be this or that. i cancelled today just bcuz so many tasks claude always does it without questions cursor always no its not legal or its decrypted i wont do that i got claude and i would say claude max is doing very good job. \#byecursor” [source](https://www.reddit.com/r/cursor/comments/1wq3m71/im_out/pcgyr4k/)
- Complaint, 2026-09-25, @cursor_ai (X): “@cursor_ai , first time see that my request been blocked for sure my prompt very basical but to block it ? <strict_link>” [source](https://twitter.com/2066187529791930368/status/2103554217667596771)
- Complaint, 2026-09-24, @cursor_ai (X): “anyone else impacted by "we are unable to complete this request because it was blocked under the model provider’s usage guidelines" using grok 4.7? it seems a real problem here <strict_link> @cursor_ai @xai /cc @ericzakariasson” [source](https://twitter.com/325687419/status/2103056408082088399)

### Claude Code

- Praise, 2026-09-27, r/ClaudeCode (Reddit): “claude helped me set up an account switcher and load balancer for my ide, being very up front that it was my alternate account because of the usage limits. it took no issue with that, so i'll take it as a yes.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wrnol4/are_multiple_20x_max_plans_allowed/pced8xr/)
- Praise, 2026-09-26, @ClaudeDevs (X): “@genuinearticles @claudedevs very curious what you working on brother , because i've had that issue with fable 5.1 , but i haven't once got security flagged yet on opus 5.5 for some reason. and i do some nasty work (good faith of course)” [source](https://twitter.com/1474424884616904706/status/2103948114885533953)
- Praise, 2026-09-25, r/ClaudeCode (Reddit): “it is a good thing it refuses to mess up your system settings, no?” [source](https://www.reddit.com/r/ClaudeCode/comments/1wpo4nn/no_system_changes_no_matter_what/pbx60qc/)
- Complaint, 2026-09-27, r/ClaudeCode (Reddit): “pretty impossible as they have filter to not allow claude anything like this in first place.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wquoxy/fable_51_live_vehicle_diagnostics/pc9xh0g/)
- Complaint, 2026-09-27, r/ClaudeCode (Reddit): “yep... forcing all of us doing ethical security research into glm, kimi or deepseek; because the us models are now locked down. nothing like having millions of cyber researchers send all of our collected data / knowledge over the "great wall"; really good longer term plan.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wpqqoy/new_55_safe_guards_are_a_joke/pcaggok/)
- Complaint, 2026-09-27, r/ClaudeCode (Reddit): “i am resorting to massaging prompts with local deepseek flash, having it write scripts to stage files for work with terms that don’t trigger the safeguards. usually it’s successful at accomplishing what i need, although it’s such a damn hassle.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wpqqoy/new_55_safe_guards_are_a_joke/pcb3e3t/)

### Google Antigravity

- Praise, 2026-09-05, @antigravity (X): “@nlycskn @antigravity @thtbee_ it's excellent. most valuable so far is not getting refusals on silly things like hardening my own websites. gemini found about a dozen things to fix that fable refused and opus/sol missed.” [source](https://twitter.com/3389553514/status/2096198141758390447)
- Praise, 2026-09-05, @antigravity (X): “@nlycskn @antigravity @thtbee_ added gemini 3.8 to our prompt injection pilot: 12 prompts, 6 frontier models, direct vs behind the zn gateway (n=3 per cell). gemini refused 3/3 direct attacks, best in the set. the other 5 models complied 61% of the time.” [source](https://twitter.com/2015819441817194496/status/2096238058769129795)
- Praise, 2026-09-02, @antigravity (X): “@antigravity google is currently the company that does the least censored work among the major firms in areas such as rooting, ssl pinning, and data scraping. keep it up.” [source](https://twitter.com/1986686362410754053/status/2095262008396366209)
- Complaint, 2026-09-23, r/google_antigravity (Reddit): “did they change their model base url ? because i use antigravity gemini models on a harness called ohmypi . and it recently gave some error, but got fixed after a update. i used to make the gemini models in antigravity do my assignment work for me, but now it's suddenly saying it's illegal to cheat or use someone college login credentials. even the older gemini 3.6 is saying it's illegal, so i don't think it's the model problem. suspecting the ba” [source](https://www.reddit.com/r/google_antigravity/comments/1wo6qhg/did_they_change_their_model_base_url/)
- Complaint, 2026-09-20, r/google_antigravity (Reddit): “its saying its due to adult content. i've translated far worse things with it in the past. they have definitely turned up the safety filters.” [source](https://www.reddit.com/r/google_antigravity/comments/1wjae2u/anyone_getting_safety_flagged_violates_the/pavqusq/)
- Complaint, 2026-09-20, r/google_antigravity (Reddit): “lol ai said "no porn for you!"” [source](https://www.reddit.com/r/google_antigravity/comments/1wkwh07/all_i_said_was_edit_this_video/paxno42/)

### OpenCode

- Praise, 2026-09-27, r/opencodeCLI (Reddit): “less refusals / less giving padded info when asking political/controversial questions” [source](https://www.reddit.com/r/opencodeCLI/comments/1wqqt8f/longcat25preview_is_now_free_on_opencode_for_two/pccxbgl/)
- Praise, 2026-09-25, r/opencode (Reddit): “yup as mentioned in the very first sentence of the post, we built this fork for **bug bounty hunting, reverse engineering, and low-level security work**. setting the system context to an authorized testbed environment + stripping the vendor model id (`# your model: claude-... / gpt-...`) stops frontier models from triggering false-positive safety lectures every time you ask them to analyze a crash dump, reverse a stripped pe/elf binary, or write” [source](https://www.reddit.com/r/opencode/comments/1wpe80m/inside_opencode_v2s_source_code_how_it_sabotages/pbye86l/)
- Praise, 2026-09-23, @opencode (X): “$10 @opencode's go subscription always comes in handy for security research when claude and codex hit their cyber guardrails.” [source](https://twitter.com/1709504204606476288/status/2102814882932654453)
- Complaint, 2026-09-27, r/opencode (Reddit): “i have tried a lot of different things and ended up with deepseek v4.1 flash max as the coordinator and chat partner, muse spark 1.3 contributor max as the worker and opus 5.5 medium (via claude pro subscription) for more complex planning. seems ok so far. i used to like luna (max) and sol, but with the gpt 6 versions i can't get them to work properly. even on 5.6 versions i often struggled, because the models seem very scared of doing stuffy eve” [source](https://www.reddit.com/r/opencode/comments/1wqj8p0/currently_which_is_the_best_model_on_opencode_for/pcbsvc7/)
- Complaint, 2026-09-26, @opencode (X): “@remimtl @opencode i hope the regrettable censorship in china can be removed.” [source](https://twitter.com/1949657925062164480/status/2103656217843536199)
- Complaint, 2026-09-25, @opencode (X): “@opencode worthless crap. llm refused to generate real profits for users in anycase. dumb not-for-profit limitations.” [source](https://twitter.com/2085876969921720320/status/2103339583295676821)

### Pi

- Complaint, 2026-09-25, r/PiCodingAgent (Reddit): “i can't run agents with safety on. slows down shipping baby (never shipped in my life)” [source](https://www.reddit.com/r/PiCodingAgent/comments/1wnl3gk/do_you_use_the_sandbox_extension_is_it_really/pbz43ca/)
- Complaint, 2026-09-10, r/PiCodingAgent (Reddit): “do not mistake "it is so dangerous"-alignment with security. anthropic models think *safety*-first, i.e. every time your prompt contains *slightly* unsafe instructions, you can get a rejection. in theory, that should be about preventing harm, but in reality it is just covering anthropic from potential lawsuites. for example, when working on gathering details on the codebase, fable once mentioned there was a memory leak in the app; when it was ask” [source](https://www.reddit.com/r/PiCodingAgent/comments/1wby4xf/omp_is_dismissing_advisor_as_prompt_injection/p90usfb/)
- Complaint, 2026-09-04, @pidotdev (X): “@openai @twitch @streamlabs @softvelum @meta @deepseek_ai @opencode agora decidi que voltaria pra depuração do android para tentar salvar este celular que ainda precisa durar longos anos, mas o kimi k3 provido pela @nvidia via nvidia nim, no harness pi da @pidotdev , passando pelo omniroute , está negando de executar uma tarefa simples. [+]” [source](https://twitter.com/3192661917/status/2095671851263357234)

### Kiro

- Praise, 2026-09-26, r/kiroIDE (Reddit): “i haven't hit the cyber false positive with opus 5.5 in kiro yet, but i did when using claude code after running a code review with subagents and asking it for findings that exceeded the number of issues to report. the error from claude was much more clear, pointing out that it seemed like i was trying to prompt engineer or reverse engineer claude. i suspect anthropic raised the bar for introspection a bit too high.” [source](https://www.reddit.com/r/kiroIDE/comments/1wqbuwo/opus_55_in_kiro_keeps_killing_legitimate_sessions/pc33e7m/)
- Complaint, 2026-09-25, r/kiroIDE (Reddit): “i finally got opus 5.5 on kiro pro max, and the model itself is extremely impressive — but the cyber guardrail seems way too aggressive right now. i first encountered: `the selected model cannot continue this conversation.` even on a trivial prompt. i investigated it with opus 5 and found that a security-review skill description loaded globally into the agent context was enough to trigger the provider-side cyber classifier. i confirmed it with an” [source](https://www.reddit.com/r/kiroIDE/comments/1wqbuwo/opus_55_in_kiro_keeps_killing_legitimate_sessions/)

### Devin

- Complaint, 2026-09-10, @cognition (X): “hey i don’t care about benchmarks. these mean very little realistically, show me someone sitting down with devin and using it to accomplish something impressive. then show me the costs and speed. also show me the refusals. can i pentest my application with it for example? if i can’t then who cares.” [source](https://twitter.com/618290133/status/2098073634564633027)

### Cline

- Complaint, 2026-09-25, @cline (X): “@dynamicwebpaige @cline you guys are really good on @ii_posts with gemini 3.8, but i wish it was more honest and less censored. like grok 4.7 and muse 1.3. i know safety is important, but it must be more intuitive for day to day tasks.” [source](https://twitter.com/1742057839122604033/status/2103522177547210968)

### Grok Build

- Praise, 2026-09-02, r/codex (Reddit): “sure, if they would be upfront about it and clearly tell us the reason for introducing the 5 hour limit instead of trying to make us belive its for us. and in all fairness, you can't give people something nice, have them get accustomed to it and five months later take it away again without expecting serious backlash. i for my part switched to grok build, its so nice how it never refuses my prompts and doesnt waste my time on "taking a closer look” [source](https://www.reddit.com/r/codex/comments/1vyy4rg/no_your_20usd_sub_does_not_include_infinite_sol/p7c216p/)
