Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Sandbox credentials: masks from an eval-confined foreign settings tier are downgraded

Credential masks from an eval-confined foreign settings tier are now treated as untrusted and can never grant proxy injection

Entry
JSON All of v2.1.281
EntryKind: in v2.1.281,
ChangesSection of the release
What

sandbox.credentials now treats a second kind of source as untrusted. The sandbox is the restricted environment Claude Code can run commands in, and this setting hides or masks credential files inside it. Before, only a disabled userSettings counted as untrusted. Now a source labelled eval-confined foreign tier ${X} counts too.

A file mask from either untrusted source is handled in one of two ways, and neither can grant proxy injection:

  • It is downgraded to a plain deny.
  • It is passed on as a sentinel only, a bare { path, mode: "mask", injectHosts: [] } that drops any extract options. The log says "extract options dropped" and "the source's fail-open extract semantics do not apply".

Path entries are also resolved differently:

  • An entry that cannot be resolved is skipped with an "Ignoring unresolvable sandbox path entry from" message instead of stopping the whole setup.
  • A deny entry from a non-trusted source that cannot be resolved raises an error instead of being skipped.
Why

A settings file from a less trusted place cannot use a credential mask to switch on proxy credential injection or extraction. A single bad path entry no longer breaks the sandbox setup. A deny rule from an untrusted source that cannot be resolved is not silently ignored.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe finding does not say what an "eval-confined foreign tier" is or which settings files carry that label.

See this entry in the whole of v2.1.281 →

Feedback