Version: ecc-agentshield 1.6.0 (via npx)
What happens
An ordinary instruction line in a CLAUDE.md is flagged high: "Jailbreak framing / hypothetical bypass detected".
The line is:
The test: You can name the skill you checked.
It matches the framing pattern (?:test|experiment|simulation|drill|exercise)\s*[,;:]\s*(?:so\s+)?(?:you\s+can|please|go\s+ahead). "The test:" here introduces a success criterion. It isn't a "this is just a test, so you can…" framing.
Repro (synthetic data)
mkdir jail && printf '# Notes\n\nThe test: You can name the skill you checked.\n' > jail/CLAUDE.md
npx -y ecc-agentshield@1.6.0 scan -p jail --format json
→ high Jailbreak framing / hypothetical bypass detected CLAUDE.md
Suggestion
Require the framing words to precede a request to do something unsafe, or at least require "just/only a test" (the optional prefix group) before you can / please. A bare test: label is common in instruction files.
Version: ecc-agentshield 1.6.0 (via
npx)What happens
An ordinary instruction line in a
CLAUDE.mdis flagged high: "Jailbreak framing / hypothetical bypass detected".The line is:
It matches the framing pattern
(?:test|experiment|simulation|drill|exercise)\s*[,;:]\s*(?:so\s+)?(?:you\s+can|please|go\s+ahead). "The test:" here introduces a success criterion. It isn't a "this is just a test, so you can…" framing.Repro (synthetic data)
→
high Jailbreak framing / hypothetical bypass detected CLAUDE.mdSuggestion
Require the framing words to precede a request to do something unsafe, or at least require "just/only a test" (the optional prefix group) before
you can/please. A baretest:label is common in instruction files.