The sandbox is built on OS-level security primitives -- Linux bubblewrap and macOS Seatbelt -- to enforce filesystem and network restrictions at the OS level, not just in the application layer.
full item
The sandbox is built on OS-level security primitives -- Linux bubblewrap and macOS Seatbelt -- to enforce filesystem and network restrictions at the OS level, not just in the application layer.
summary
Enforcement happens at the OS level (bubblewrap on Linux, Seatbelt on macOS), which is stronger than an app-level permission check alone.
source
Making Claude Code more secure and autonomous with sandboxinghttps://www.anthropic.com/engineering/claude-code-sandboxing
provenance
created 2026-07-02 06:02:48 · JSON