sandbox.credentials now treats a second kind of source as untrusted. The sandbox is the restricted environment Claude Code can run commands in, and this setting hides or masks credential files inside it. Before, only a disabled userSettings counted as untrusted. Now a source labelled eval-confined foreign tier ${X} counts too.
A file mask from either untrusted source is handled in one of two ways, and neither can grant proxy injection:
- It is downgraded to a plain deny.
- It is passed on as a sentinel only, a bare
{ path, mode: "mask", injectHosts: [] }that drops any extract options. The log says "extract options dropped" and "the source's fail-open extract semantics do not apply".
Path entries are also resolved differently:
- An entry that cannot be resolved is skipped with an "Ignoring unresolvable sandbox path entry from" message instead of stopping the whole setup.
- A deny entry from a non-trusted source that cannot be resolved raises an error instead of being skipped.
A settings file from a less trusted place cannot use a credential mask to switch on proxy credential injection or extraction. A single bad path entry no longer breaks the sandbox setup. A deny rule from an untrusted source that cannot be resolved is not silently ignored.
The finding does not say what an "eval-confined foreign tier" is or which settings files carry that label.