Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.251 Home All releases olderv2.1.250
Claude Code v2.1.251

A stripped-down sandbox configuration path

Not switched on
Useful2 Signal4
Sandbox

The sandbox builder can produce a policy-only mode, but nothing visible switches it on.

A filesystem-grant-free sandbox mode exists with no visible caller in this build.

What

The sandbox configuration builder gained a mode that suppresses most filesystem grants, leaving a policy-only sandbox. Nothing in the code read for this build shows what turns the mode on.

Details
  • When active it drops permissions.additionalDirectories, allow entries derived from permission rules, and sandbox.filesystem.allowWrite/allowRead entries coming from anything other than a policy settings source.
  • It also drops the network fields allowUnixSockets, allowLocalBinding and httpProxyPort.
Evidence

...(u ? [] : e.permissions?.additionalDirectories || [])

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

See this entry in the whole of v2.1.251 →