One read of Claude Documentationclaude-docs-20260930T180709Z
2 pages moved out of 258 read.
Pages moved
2
significant first
Pages read
258
in this capture
Captured
18:07 UTC
Corpus hash
e1f51c0eba8f
corpus-hash
What this read moved
1-2 of 2government/security/security-and-data-handling Changed · +3 / -3 lines
from line 46
4646
4747Exempting git commands such as `git commit` with `sandbox.excludedCommands` is not a safe way around the socket restriction. A sandboxed command can still change files that git runs during a commit, such as hook scripts kept in the working tree, and an exempted `git commit` would then run that code outside the sandbox. On macOS, git also cannot reach remotes over SSH from inside the sandbox, so a user who needs to push can use an HTTPS remote whose host is on the **Allowed network hosts** list, or push from a terminal outside the Code session.
4848
49In container-based Linux environments, such as cloud development workspaces, the sandbox can fail to start, and shell commands in Code sessions then fail with a `bwrap` error. To run Code sessions there, deploy Claude Code's own [managed settings file](https://code.claude.com/docs/en/managed-settings) at `/etc/claude-code/managed-settings.json`, set [`parentSettingsBehavior`](https://code.claude.com/docs/en/settings-reference#parentsettingsbehavior) to `"merge"` in it so that your organization's other settings for Code sessions stay in force, and add one of the two settings that follow.
49In container-based Linux environments, such as cloud development workspaces, the sandbox can fail to start, and shell commands in Code sessions then fail with a `bwrap` error. To run Code sessions there, turn off the **Shell command sandbox** switch under **Advanced settings** in the **Claude Code** section of the [Config](/docs/government/config/settings) page, at the level that applies to the members who work in those environments, such as a [directory group](/docs/government/config/overview#group-specific-settings).
5050
51In that managed settings file, setting `sandbox.enableWeakerNestedSandbox` to `true` runs the sandbox in the [weaker mode that Claude Code documents for containers](https://code.claude.com/docs/en/settings-reference#sandbox-enableweakernestedsandbox), which keeps the network and filesystem restrictions but lets sandboxed commands see the container's other processes. Use it only where the container already provides the isolation you need. If the sandbox still cannot start with that setting, or you prefer to rely on the container's own controls alone, set `sandbox.enabled` to `false` instead. Shell commands then run directly in the container under the permission mode the user selects for the session, as they do on Windows, and the **Allowed network hosts** and **Allowed workspace folders** settings no longer confine what those commands can reach or change.
51The **Shell command sandbox** switch applies to those members on every device they use, not only in the container workspaces. Shell commands in their Code sessions then run without the sandbox, under the permission mode the user selects for the session, as they do on Windows, and the **Allowed network hosts** and **Allowed workspace folders** settings no longer confine what those commands can reach or change. The switch reaches Code sessions in Claude Desktop 2.9939.2 or later. The switch also turns the sandbox off in those members' sessions in the Claude Code command-line tool.
5252
5353On Windows, there is no operating-system-level sandbox for Code sessions. Shell commands run directly on the device under the permission mode the user selects for the session and under your agency's own endpoint and network controls. The **Allowed network hosts** and **Allowed workspace folders** settings do not confine what those commands can reach, read, or change.
5454
government/config/plugins-and-connectors Changed · +1 / -1 lines
from line 40
4040
4141The upload preview marks any plugin that declares components that can run code on the member's machine, for example hooks or an [MCP server](/docs/connectors/getting-started), and you confirm that you trust such a package before it is added. For a marketplace archive, one confirmation covers every marked plugin in the batch. After you add it, the plugin's row on the **Plugins** card keeps a **Runs code** marker, so you can see at a glance which of the plugins you have added contain these components.
4242
43The marker reflects what a plugin declares. In Claude for Government, a marked plugin's hooks run on the member's machine at defined points during a session. Claude Desktop can also run a local MCP server that the plugin declares on the member's machine, or connect to a remote one.
43The marker reflects what a plugin declares. In Claude for Government, a marked plugin's hooks run on the member's machine at defined points during a session. Claude Desktop can also run a local MCP server that the plugin declares on the member's machine, or connect to a remote one. If a plugin's remote MCP server does not connect, check the **Member-added connectors** setting on the **Connectors** card, described under **Claude Code** in [Available settings](/docs/government/config/settings).
4444
4545Treat the marker as a prompt to review the package yourself. You are responsible for the plugins you distribute to members, so read each plugin's contents before you upload it.
4646