What
The sandbox is the protected area that limits what commands run by Claude can touch. It already blocks writes to certain settings files. Files you supply through the agents flag (flagAgentsFilePaths()) are now added to that list, so commands in the sandbox cannot change them.
The list of policy-limit files was also changed.
Why
Files that define your subagents cannot be rewritten by a command running in the sandbox, so their contents stay as you gave them.
Names in the bundle--agents
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Added since
A small documentation edit on CLI reference touched a line naming --agents after this was published.
| `--agents` | Define custom subagents dynamically via JSON. Accepts the [fields listed for CLI-defined subagents](/docs/en/sub-agents#choose-the-subagent-scope). With `--print`, the value can instead be the path to a JSON file holding the…cli-reference see the edit
Confirmed since
Anthropic's documentation has since written up --agents, on Deploy managed settings.
| [`disableSideloadFlags`](/docs/en/settings-reference#disablesideloadflags) | Reject the `--plugin-dir`, `--plugin-url`, `--agents`, and `--mcp-config` flags at startup. In cloud sessions, Claude Code drops the MCP servers the server deli…managed-settings see the edit
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
The finding does not say how the policy-limit file list was changed.
Anthropic's documentation agrees
Anthropic's documentation has since written up --agents, on Deploy managed settings.
Anthropic's release notes agree
Improved --agents to accept the path to a JSON file (with -p) as well as inline JSON, and to allow an empty prompt