Follow Discord
Sweep 03 Oct 2026 · 20:28Z Build v2.1.289 510 read Stable v2.1.285 Latest v2.1.288 Next v2.1.289 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · claude-code

Securely deploying AI agents changedagent-sdk/secure-deployment

Nearest release: v2.1.287, published 7 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Upstream edited this page at 2 Oct 2026 00:28 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 2 Oct 2026 00:37 UTC.

Upstream edited
Recorded here
Lines+3added
Lines−3removed
From line 72 where the diff opens
First seen 14 Aug 2026 this site's first read of the page
Recorded edits5to this page, all time

The whole hunk

from line 72, old and new numbered
/
lines
from line 72
7272 
7373### Sandbox runtime
7474 
75For lightweight isolation without containers, [sandbox-runtime](https://github.com/anthropic-experimental/sandbox-runtime) enforces filesystem and network restrictions at the OS level.
75For lightweight isolation without containers, [sandbox-runtime](https://github.com/anthropics/sandbox-runtime) enforces filesystem and network restrictions at the OS level.
7676 
7777The main advantage is simplicity: no Docker configuration, container images, or networking setup required. The proxy and filesystem restrictions are built in.
7878 
from line 142
142142 
143143With `--network none`, the container has no network interfaces at all. The only way for the agent to reach the outside world is through the mounted Unix socket, which connects to a proxy running on the host. This proxy can enforce domain allowlists, inject credentials, and log all traffic.
144144 
145This is the same architecture used by [sandbox-runtime](https://github.com/anthropic-experimental/sandbox-runtime). Even if the agent is compromised via prompt injection, it cannot exfiltrate data to arbitrary servers. It can only communicate through the proxy, which controls what domains are reachable. For more details, see the [Claude Code sandboxing blog post](https://www.anthropic.com/engineering/claude-code-sandboxing).
145This is the same architecture used by [sandbox-runtime](https://github.com/anthropics/sandbox-runtime). Even if the agent is compromised via prompt injection, it cannot exfiltrate data to arbitrary servers. It can only communicate through the proxy, which controls what domains are reachable. For more details, see the [Claude Code sandboxing blog post](https://www.anthropic.com/engineering/claude-code-sandboxing).
146146 
147147**Additional hardening options:**
148148 
from line 335
335335* [Claude Code security documentation](/docs/en/security)
336336* [Hosting the Agent SDK](/docs/en/agent-sdk/hosting)
337337* [Handling permissions](/docs/en/agent-sdk/permissions)
338* [Sandbox runtime](https://github.com/anthropic-experimental/sandbox-runtime)
338* [Sandbox runtime](https://github.com/anthropics/sandbox-runtime)
339339* [The Lethal Trifecta for AI Agents](https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/)
340340* [OWASP Top 10 for LLM Applications](https://owasp.org/www-project-top-10-for-large-language-model-applications/)
341341* [Docker Security Best Practices](https://docs.docker.com/engine/security/)
Feedback