You'll notice
Claude now refuses with a clear message when the sandbox can't run a command while still protecting credential files.
A new refused.sandbox_custody message covers the case where a local sandbox cannot run a command while also protecting its credential files. Claude Code now refuses to run and explains the situation, instead of silently failing or running the command unprotected.