You'll notice
Remote-tool commands on a machine with no strict sandbox filesystem now warn once that credential files rely on permission rules alone.
When a served (remote-tools) command runs on a machine with no sandbox filesystem configuration, or with a relaxed sandbox policy, Claude Code now logs a one-time warning that credential files are protected only by permission rules, and suggests enabling strict sandbox filesystem isolation for the additional mask.