Follow Discord
Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.268 ·

Sandbox system-prompt text rewritten to describe allowed_domains / auto-mode network review

Sandbox instructions shown to the model were rewritten to explain listing needed hosts and reacting to blocked-host violations

TierNothing to try yethow much it should matter to you
Useful3my rating, 1 to 5
Signal4worth watching, 1 to 5
AreaSandbox Networkwhat it touches
KindIn Developmentin v2.1.268,
Nothing to try yet

Sandbox instructions shown to the model were rewritten to explain listing needed hosts and reacting to blocked-host violations

What

The sandbox instructions built into the system prompt (under a 'command sandbox' heading) were substantially rewritten for when the new network-list capability is active. The model is now told to list every host a command needs, that the sandbox is applied per command at the operating-system level, and to check a <sandbox_violations> block for any denied hosts. If a host was denied, the instructions say to re-run the command with that host added to allowed_domains when in auto mode. Separately, the wording used when sandboxing is fully disabled by policy was softened from a blanket prohibition to language that tells the model to ask the user instead.

Why

This gives the model concrete steps to follow when a sandboxed command is blocked from reaching a network host, instead of leaving it to guess how to retry.

Read from
Names in the bundleallowed_domains
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up allowed_domains, on Claude Code changelog. * Added per-command `allowed_domains` to Bash, PowerShell and Monitor in auto mode with sandboxing: the hosts a command needs are reviewed with it and opened for it alone; other hosts are refused changelog see the edit
Confirmed since Anthropic's documentation has since written up dangerouslyDisableSandbox, on Monitoring. * For Bash tool: includes `bash_command`, `full_command`, `timeout`, `description`, and `dangerouslyDisableSandbox`, plus `git_commit_id` and `git_branch` when a `git commit` command succeeds. `git_commit_id` is the full commit SHA when th… monitoring-usage see the edit
What has happened since
Flag reading moved The flag server now returns on for tengu_flickering_rain, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
Flag reading moved The flag server now returns off for tengu_flickering_rain, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
Flag reading moved The flag server now returns on for tengu_flickering_rain, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.

See this across every release →

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhether this rewritten guidance is actually shown to any given user depends on the same unread tengu_flickering_rain setting.
Anthropic's documentation agreesAnthropic's documentation has since written up dangerouslyDisableSandbox, on Monitoring.

See this entry in the whole of v2.1.268 →

Feedback