{"version":"2.1.280","anchor":"bash-tool-enforces-a-hard-sandbox-requirement-for-remotesdk","canonical_anchor":"bash-tool-enforces-a-hard-sandbox-requirement-for-remotesdk","heading":"Bash tool enforces a hard sandbox requirement for remote\/SDK-issued calls","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/bash-tool-enforces-a-hard-sandbox-requirement-for-remotesdk","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### Bash tool enforces a hard sandbox requirement for remote\/SDK-issued calls\n\nBash\/PowerShell now refuses remote-issued commands if a fully confining sandbox can't be confirmed\n\n**What**\n\nWhen a command is sent to the `Bash` (or PowerShell) tool remotely and it's marked as requiring a sandbox (a restricted environment that limits what a command can touch), Claude Code now checks that a fully confining sandbox is actually available before running it. If it can't confirm one, it refuses to run the command at all, rather than running it unconfined.\n\n**Why**\n\nThis closes a gap where a remote or SDK-issued command marked as needing sandboxing could previously run without real confinement if a sandbox wasn't actually in place. Now it fails safely instead of silently executing with fewer protections than expected.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 2\/5"}