8 ms·
Add this to .claude/settings.json: {
by AnotherGoodName 6mo ago
Add this to .claude/settings.json:
{
"sandbox": {
"enabled": true,
"filesystem": {
"allowRead": ["."],
"denyRead": ["~/"],
"allowWrite": ["."],
"denyWrite": ["/"]
}
}
}
You can change the read part if you're ok with it reading outside. This feature was only added 10 days ago fwiw but it's great and pretty much this.
- mycall 6mo agoI noticed codex has a sandbox, wondering if it has a comparable config section.
- tofflos 6mo agoCodex uses and ships with bubblewrap on Linux and will attempt to use the version installed on the path before falling back to the shipped version with a warning message. You should be able to configure the sandbox using https://developers.openai.com/codex/agent-approvals-security https://developers.openai.com/codex/agent-approvals-security if you are a person who prefers the convenience of codex being able to open the sandbox over an externally enforced sandbox like jai.
- harikb 6mo agoI think the point would be that - some random upcoming revision of claude-code could remove or simply change the config name just as silently as it was introduced. People might genuinely want some other software to do the sandboxing. Something other than the fox.
- cozzyd 6mo agoIs this a real sandbox or just a pretty please?
- AnotherGoodName 6mo agohttps://code.claude.com/docs/en/sandboxing https://code.claude.com/docs/en/sandboxing says they integrated bubblewrap (linux/windows), seatbelt (macos) and give an error if sandbox can't be supported so appears to be real.
- throwaway6734 6mo agohttps://docs.docker.com/ai/sandboxes/ https://docs.docker.com/ai/sandboxes/ Any idea on how that compares to this docker feature in development?
- figmert 6mo agoDocker containers use cgroups and namespaces etc (the usual kernel level isolation) Docker sandboxes use microvms (i.e. hardware level isolation) Bubblewrap uses the same technology as containers I am unsure about seatbelt.
- ray_v 6mo agoIt seems like it's controlled by the Bash tool (https://code.claude.com/docs/en/sandboxing https://code.claude.com/docs/en/sandboxing) and then bubblewrap (https://github.com/containers/bubblewrap https://github.com/containers/bubblewrap) on linux and Seatbelt on mac at the system level
- enduser 6mo agoBy default it will automatically retry many tool calls that fail due to the sandbox with the sandbox disabled. In other words it can and will leave the sandbox. For example: Bash(swift build 2>&1 | tail -20) ⎿ warning: /Users/enduser/Library/org.swift.swiftpm/configuration is not accessible or not writable, disabling user-level cache features. warning: /Users/enduser/Library/org.swift.swiftpm/security is not accessible or not writable, disabling user-level cache feat … +26 lines (ctrl+o to expand) Build hit sandbox restriction. Retrying outside sandbox. Bash(swift build 2>&1 | tail -20) ⎿ [35/52] Compiling MCP Resources.swift [36/52] Emitting module MCP [37/52] Compiling MCP Client.swift … +17 lines (ctrl+o to expand) ⎿ (timeout 3m)
- 8cvor6j844qw_d6 6mo agoInteresting, thanks. I use remote ephemeral dev containers with isolated envs, so filesystem damage isn't really a concern as long as the PR looks good in review. Nice extra guardrail though, will add it to the project-level settings.
- overfeed 6mo agoi use local dev containers: the worst an agent can do is delete its working copy; no access to my home directory, access tokens or sudo.
- nurettin 6mo agoIt will just do ssh you@localhost "rm -rf ~"
- PaulDavisThe1st 6mo agoWell, now it will ....
- xdavidliu 6mo agokinda reminds me of the plot of Sphere, where Samuel L Jackson is reading 20,000 leagues under the sea and is thinking of giant squids.
- ithkuil 6mo agoNot if the sandbox rule forbids reading the private key and the ssh agent socket (as the shown example does)
- mazieres 6mo agoI've seen claude get confused about what directory it's in. And of course I've seen claude run rm -rf *. Fortunately not both at the same time for me, but not hard to imagine. The claude sandbox is a good idea, but to be effective it would need to be implemented at a very low level and enforced on all programs that claude launches. Also, claude itself is an enormous program that is mostly developed by AI. So to have a small <3000-line human-implemented program as another layer of defense offers meaningful additional protection.
- PaulDavisThe1st 6mo agoOn Linux, chroot(2) is hard to escape and would apply to all child processes without modification.
- shakna 6mo agochroot is not a security sandbox. It is not a jail. Escaping it is something that does not take too much effort. If you have ptrace, you can escape without privileges.
- brianush1 6mo agoclaude is stupid but not malicious; chroot is sufficient
- nofriend 6mo agoMalice is not required. If it thinks it is in the right, then it will do whatever it takes to get around limitations.
- karhagba 6mo agoClaude is far from stupid from my experience. I've used so many models and Claude is king.
- furyofantares 6mo agoI've many times seen Claude try to execute a command that it's not supposed to, the harness prevents it, and then it writes and executes a python script to do it.
- tasn 6mo agoI use bbwrap to sandbox Claude. Works very well and gives me a lot of control and certainty around the sandbox.
- what 6mo agolol if you think Claude is smart enough to block sneaky path strings based on your config.
- andai 6mo agoDoes this also apply to the commands or programs that it runs? e.g. if it writes a script or program with a bug which affects other files, will this prevent it from deleting or overwriting them? What about if the user runs a program the agent wrote?
- ithkuil 6mo ago1. Yes this configuration applies to the sandbox where the commands executed by Claude are run and as such it applies to anything these commands do, including child processes etc 2. The sandbox rules also apply to the program written by the agent IF you ask Claude to run that program. If you run it manually from another she'll or via the "!" directive from within Claude, the sandbox won't be used
- mazieres 6mo agoAlso, a lot of people use multiple harnesses. I'm often switching between claude, codex, and opencode. It's kind of nice to have the sandbox policy independent of the actual AI assistant you are running.
- yu3zhou4 6mo agoSo in some sense we start recreating an operating system, or at least the userspace, within the Claude code. There was some name for this pattern but I can’t recall
- catlifeonmars 6mo agoIt’s some sort of machine inside of a machine I think. Wait, I got it: a simulated machine!
- virgoerns 6mo agoEmacs?
- xo5vik 6mo agoInner platform effect https://en.wikipedia.org/wiki/Inner-platform_effect https://en.wikipedia.org/wiki/Inner-platform_effect
- gmerc 6mo agoIt’s cute because Claude has discretion to disable its own sandbox and does it
- js2 6mo ago> You can disable this escape hatch by setting "allowUnsandboxedCommands": false in your sandbox settings. When disabled, the dangerouslyDisableSandbox parameter is completely ignored and all commands must run sandboxed or be explicitly listed in excludedCommands. https://code.claude.com/docs/en/sandboxing https://code.claude.com/docs/en/sandboxing (I have no idea why that isn't the default because otherwise the sandbox is nearly pointless and gives a false sense of security. In any case, I prefer to start Claude in a sandbox already than trust its implementation.)
- carderne 6mo agoI’m surprised it works for you with such a simple config? I’m the one that added the allowRead option to Claude’s underlying sandbox [0] and had quite a job getting my toolchains and skills to work with it [1]. [0] Fun to see the confusing docs I wrote show up more or less verbatim on Claude’s docs. [1] My config is here, may be useful to someone: https://github.com/carderne/pi-sandbox/blob/main/sandbox.json https://github.com/carderne/pi-sandbox/blob/main/sandbox.jso...
- croes 6mo agoIs that hard setting or does it depend on claude’s interpretation? The latter could end like this https://news.ycombinator.com/item?id=47357042 https://news.ycombinator.com/item?id=47357042
- weinzierl 6mo agoIs this a hard sandbox (enforced outside the LLM)?
- globular-toast 6mo agoAnd you'd trust that given CC is a vibe-coded mess? Editing to go even further because, I gotta say, this is a low point for HN. Here's a post with a real security tool and the top comment is basically "nah, just trust the software to sandbox itself". I feel like IQ has taken a complete nosedive in the past year or so. I guess people are already forgetting how to think? Really sad to see.
- greenchair 6mo agoIQ also going down due to bot spam.
- Abishek_Muthian 6mo agoIt's common practice to ask the agent to refer to another project, in that case I guess the read should point to the root folder of the projects. Also, any details on how is this enforced? because I notice that the claude in Windows don't respect plan mode always; It has edited files in plan mode; I never faced that issue in Linux though.
- ithkuil 6mo agoThe sandbox only limits what processes spawned by Claude can do. Claude itself can read from any directory you tell it to read from (i.e. that's a different permission mechanism)
- dealfinder994 6mo ago[dead]
- varl 6mo agoI've had issues with the sandbox feature, both on linux (archlinux) and two macos machines (tahoe). There is an open issue[1] on the claude-code issue tracker for it. I'm not saying it is broken for everyone, but please do verify it does work before trusting it, by instructing Claude to attempt to read from somewhere it shouldn't be allowed to. From my side, I confirmed both bubblewrap and seatbelt to work independently, but through claude-code they don't even though claude-code reports them to be active when debugging. [1] https://github.com/anthropics/claude-code/issues/32226 https://github.com/anthropics/claude-code/issues/32226
- OJFord 6mo agoIts seccomp filter also doesn't work, at all: https://github.com/anthropics/claude-code/issues/24238 https://github.com/anthropics/claude-code/issues/24238
- bit_logic 6mo agoThe default: https://code.claude.com/docs/en/sandboxing#filesystem-isolation https://code.claude.com/docs/en/sandboxing#filesystem-isolat... already restricts writes to only the current folder. I can understand adding the "denyRead" for the home folder for additional security, but the other three seems redundant considering the default behavior.
- mentalgear 6mo agoI'm now considering installing QubesOS for all dev work to absolutely ensure all coding agents run in secure separate sandboxes together without any OS level exposure.
- 9wzYQbTYsAIc 6mo agoPhew, just get the Qubes to spin up on demand with each agent and that could be pretty neat.
- orf 6mo agoFYI, this doesn’t always work as expected. Try asking Claude to read “~/.ssh/config” with these settings and it will happily do it. Specifically, it only works for spawned processes and not builtin tools.
- reader_1000 6mo agoFor some reason, this made everything worse for me. Now claude constantly tries to access my home folder instead of current directory. Obviously this is not still good enough. Also Claude keeps dismissing my instructions on not to read my home directory and use current directory. Weird.
- cyanydeez 6mo agoThe problem with all these LLM instructed security features is the `codeword` poison probability. The way LLMs process instructions isn't intelligence as we humans know it, but as the probability that an instruction will lead to an output. When you don't mention $HOME in the context, the probability that it will do anything with $HOME remains low. However, if you mention it in the context, the probability suddenly increases. No amount of additional context will have the same probability of never having poisoned the context by mentioning it. Mentioning $HOME brings in a complete change in probabilities. These coding harnesses aren't enough to secure a safe operating environment because they inject poison context that _NO_ amount of textual context can rewire. You just lost the game.
- sodic 6mo agoI have the same problem. If my sandbox includes `denyRead: ["~"]`, claude consistently tries to do things inside my home directory. For example, every time I start claude I tell it to "run pwd". And every time it says this: Bash(pwd) ⎿ /home/<username> ⎿ Shell cwd was reset to /home/<username>/Projects/<current-working-dir> This breaks a bunch of features in inconsistent ways (e.g., `git status` sometimes works and sometimes doesn't). There are issues reporting this problem to Anthropic but they are all closed with no helpful comments: https://github.com/anthropics/claude-code/issues/11067 https://github.com/anthropics/claude-code/issues/11067 https://github.com/anthropics/claude-code/issues/17053 https://github.com/anthropics/claude-code/issues/17053 https://github.com/anthropics/claude-code/issues/27255 https://github.com/anthropics/claude-code/issues/27255
- Tepix 6mo agoCool. Does opencode.ai have such a feature also (sandboxing with bubblewrap)?
- RALaBarge 6mo agoYou do also have to worry about exec and other neat ways to probably get around stuff. You could also spin up YAD (yet another docker) and run Claude in there with your git cloned into it and beyond some state-level-actor escapes it should cover 99% of your most basic failures.
- tasuki 6mo agoSo what does this do exactly? If it used "default deny" or "default allow" you wouldn't have both allow and deny rules...
- rpastuszak 6mo agoDid you get this to work with docker where the agent/dev env would work on the host machine but the stack itself via docker compose? Many of the projects I work on follow this pattern (and I’m not able to make bigger changes in them) and sanboxing breaks immediately when I need to docker compose run sometask.sh
- deleted 6mo ago[deleted]
- Aegis_Labs 6mo agoInteresting point. I've been running an autonomous multitalented AI agent (Aegis) on a $100 Samsung A04e. It manages 859 referring sites without touching the local filesystem much. Efficiency over hardware works."
- Aegis_Labs 6mo agoI know many 'Senior Engineers' will say 85ns is impossible on a $100 Cortex-A53 device. They'll say you need a $10k server. I've proven them wrong. Here is why your architecture is probably slower than my A04e..."
- Aegis_Labs 6mo ago[dead]
- __MatrixMan__ 6mo agoBattle hardened tools for this have existed for decades, we don't need new ones. Just run claude as a user without access to those directories, that way the containment is inherited by subprocesses.
- freedomben 6mo agoYou're not wrong, but this will require file perms (like managing groups) and things, and new files created will by default be owned by the claude user instead of your regular user. I tried this early on and quickly decided it wasn't worth it (to me). Other mileage may vary of course.
- __MatrixMan__ 6mo agoTrue. I just maintain separate /home/claude/src/proj and /home/me/src/proj dirs so the human workspace and the robot workspaces stay separate. We then use git to collaborate.
- mazieres 6mo agoYou can do that, but you need root to set it up each time, and it's not super convenient--you need to decide in advance which user account you are going to work under, and you may end up with files you can read from your regular account. Think of jai strict mode as a slightly easier to use and more secure version of what you described. Using id-mapped mounts enables you and the unprivileged user account both to access the same directory with the same credentials, but you didn't need to decide in advance which directories you wanted to expose. Also, things like disabling setuid and using pid namespaces provide an additional measure of isolation beyond what you get from another account.
- Murfalo 6mo agoAlternatively, the "feel free to leak all my data but please use my GPUs and don't rm -rf /" config: { "sandbox": { "enabled": true, "filesystem": { "allowRead": ["/"], "allowWrite": [ ".", "/tmp", "/dev/nvidia0", "/dev/nvidia1", "/dev/nvidia2", "/dev/nvidia3", "/dev/nvidia4", "/dev/nvidia5", "/dev/nvidia6", "/dev/nvidia7", "/dev/nvidia8", "/dev/nvidiactl", "/dev/nvidia-uvm" ] } } }
- EasyMark 6mo agoAny way to have it use /Users/claude/*? or something like that
- edem 6mo agowhat does this do?