{"version":"2.1.281","anchor":"sandbox-credentials-masks-from-an-eval-confined-foreign-set","canonical_anchor":"sandbox-credentials-masks-from-an-eval-confined-foreign-set","heading":"Sandbox credentials: masks from an eval-confined foreign settings tier are downgraded","tier":null,"area":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/sandbox-credentials-masks-from-an-eval-confined-foreign-set","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Sandbox credentials: masks from an eval-confined foreign settings tier are downgraded\n\nCredential masks from an eval-confined foreign settings tier are now treated as untrusted and can never grant proxy injection\n\n**Unclear.** The finding does not say what an \"eval-confined foreign tier\" is or which settings files carry that label.\n\n**What**\n\n`sandbox.credentials` now treats a second kind of source as untrusted. The sandbox is the restricted environment Claude Code can run commands in, and this setting hides or masks credential files inside it. Before, only a disabled `userSettings` counted as untrusted. Now a source labelled `eval-confined foreign tier ${X}` counts too.\n\nA file mask from either untrusted source is handled in one of two ways, and neither can grant proxy injection:\n\n- It is downgraded to a plain deny.\n\n- It is passed on as a sentinel only, a bare `{ path, mode: \"mask\", injectHosts: [] }` that drops any extract options. The log says \"extract options dropped\" and \"the source's fail-open extract semantics do not apply\".\n\nPath entries are also resolved differently:\n\n- An entry that cannot be resolved is skipped with an \"Ignoring unresolvable sandbox path entry from\" message instead of stopping the whole setup.\n\n- A deny entry from a non-trusted source that cannot be resolved raises an error instead of being skipped.\n\n**Why**\n\nA settings file from a less trusted place cannot use a credential mask to switch on proxy credential injection or extraction. A single bad path entry no longer breaks the sandbox setup. A deny rule from an untrusted source that cannot be resolved is not silently ignored."}