Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Sandbox: file paths supplied through the agents flag are now write-denied

Inside the sandbox, files you pass through the agents flag can no longer be written to

You'll notice Improvements
JSON All of v2.1.281
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.281,
ImprovementsSection of the release
What

The sandbox is the protected area that limits what commands run by Claude can touch. It already blocks writes to certain settings files. Files you supply through the agents flag (flagAgentsFilePaths()) are now added to that list, so commands in the sandbox cannot change them.

The list of policy-limit files was also changed.

Why

Files that define your subagents cannot be rewritten by a command running in the sandbox, so their contents stay as you gave them.

Read from
Names in the bundle--agents
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Added since A small documentation edit on CLI reference touched a line naming --agents after this was published. | `--agents` | Define custom subagents dynamically via JSON. Accepts the [fields listed for CLI-defined subagents](/docs/en/sub-agents#choose-the-subagent-scope). With `--print`, the value can instead be the path to a JSON file holding the… cli-reference see the edit
Confirmed since Anthropic's documentation has since written up --agents, on Deploy managed settings. | [`disableSideloadFlags`](/docs/en/settings-reference#disablesideloadflags) | Reject the `--plugin-dir`, `--plugin-url`, `--agents`, and `--mcp-config` flags at startup. In cloud sessions, Claude Code drops the MCP servers the server deli… managed-settings see the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe finding does not say how the policy-limit file list was changed.
Anthropic's documentation agreesAnthropic's documentation has since written up --agents, on Deploy managed settings.
Anthropic's release notes agreeImproved --agents to accept the path to a JSON file (with -p) as well as inline JSON, and to allow an empty prompt

See this entry in the whole of v2.1.281 →

Feedback