Parent
#427
What to build
Refusals. A security session can be refused by a model's safeguard: Claude Code's [cyber] refusal, or Codex's cybersecurity turn.failed. The Security audit, reproduction and fix-publishing sessions are security sessions. A refused session fails its Security run, with a cause that names the refusal. So does one that ends without its final line.
Models. A progress line names the Model each security session actually answered on, so that a switch such as Opus 5.5 to Opus 4.8 shows in the Command log. For Claude Code, that's the Model its stream reports; for Codex, the one requested.
Acceptance criteria
Parent
#427
What to build
Refusals. A security session can be refused by a model's safeguard: Claude Code's
[cyber]refusal, or Codex's cybersecurityturn.failed. The Security audit, reproduction and fix-publishing sessions are security sessions. A refused session fails its Security run, with a cause that names the refusal. So does one that ends without its final line.Models. A progress line names the Model each security session actually answered on, so that a switch such as Opus 5.5 to Opus 4.8 shows in the Command log. For Claude Code, that's the Model its stream reports; for Codex, the one requested.
Acceptance criteria
[cyber]refusal fails the Security run, with that cause.turn.failedfails the Security run, with that cause.