Turning command sandboxing off mid-session now tells the model the earlier sandbox instructions no longer apply.
What's wrong with this entry?
The sandbox description sent with each turn is re-rendered and compared with the last one in the transcript, so policy changes reach the model while the session is running. When sandboxing is turned off, the description goes empty and the model is told that the command sandbox has been disabled and the earlier instructions no longer apply.
- The description is produced only when the Bash tool is available and sandboxing is enabled locally; no remote flag is involved.
- The disabled notice is a fixed sentence built around the Bash tool name.
- The attachment type is stripped before token-count caching, as the agent listing delta already was.
command sandbox has been disabled. Commands now run without sandbox restrictions; the earlier sandbox instructions no longer apply.
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox