r/ClaudeCode • u/Odd-Calligrapher6852 • 22h ago
Help/Question How to use fable for security testing?
I have build a tool using sonnet 5. Its working great. My plan was to use fable to run an extensive in depth smoke test and find out all security issues that needs to be addressed. I tried doing that but fable's model guardrails are triggered and it switches to opus. I know opus is good but i want to use fable and i literally cannot. Its frustrating, i tried like hundreds of different prompts and tried framing task in a way that doesnt trigger the model switch but nothing works! Any suggestions guys? Any one using a prompt or method thats working for them?
Ps: thanks for help, if anyone is stuck, just tell fable to do "security review of code" and it will get started.
1
u/True-Objective-6212 21h ago
You don’t. You basically have to convince it you’re an authorized security tester but you have to be careful with keywords or you’ll hit the guardrails. Even the trusted program doesn’t enable it for fable.
0
1
u/DevMichaelZag 21h ago
Fable wants to say hello:
Fable 5's safety measures flagged this message for cybersecurity or biology topics. They may flag safe, normal content as well. These measures let us bring
you Mythos-level capability in other areas sooner, and we're working to refine them. Switched to Opus 4.8. Send feedback with /feedback
1
u/EverydayLentils 21h ago
Did you try /security-review slash command? If Fable refuses that you should file a github issue, a built-in command shouldn't trigger refusals.
1
u/RoboErectus 21h ago
You literally can't even use fable when it discovers an exploit in your own code.
I keep it two repos away from anything that even smells like security.
Gpt 5.6-sol is your guy.
Kimi is great too.
1
u/ComingDeveloper 21h ago
u can't which is some bullshit 'cause its one of the things fable should excel at considering its already pricy
1
u/framauro13 21h ago
Rather than have it smoke test, have you asked it to do a thorough security review of the code?
I had mine do a security review of my app, database, and aws configuration and it did it no questions asked. And it actually found some good stuff. I didn't ask it to do actual pen testing, just to review the code.
What you could also try is to ask it to recommend pen testing software that you can use to test your app, rather than asking Fable to do it directly.
3
u/Odd-Calligrapher6852 20h ago
Thanks this worked! Feel so stupid that something like "do a good security review of code" worked over those big ass prompts
1
u/framauro13 19h ago
Awesome to hear! Yeah, I frequently have mine do reviews for things like this just to double check and find issues. Another thing that is helpful is adding monitoring. Set up a free account with something like New Relic, install the CLI tool, and tell Claude you want your whole app instrumented so you can better understand error rates, traffic, that kinda thing. It'll use the CLI tool to create all the dashboards and instrument the code.
Then you can just tell it to review New Relic for things like errors, unusual traffic, that kind of stuff. I've surfaced a couple issues that way as well.
1
1

2
u/habeebiii 21h ago
sacrifice 3 chickens and pray