What
The sandbox is a restricted environment that shell commands run inside, limiting what they can reach. Claude receives written instructions about it, and those instructions now include two paragraphs that only apply on macOS:
- Local port binding: this applies when a network proxy is configured and local binding is turned off. An
EPERMerror from bind or listen (the calls a program makes to open a port on your machine) means the sandbox blocked it. Claude can tell you to setsandbox.network.allowLocalBinding: true, which takes effect without a restart. In one variant of the instructions it can also suggest/sandbox exclude <pattern>or running the command yourself with the!prefix. openandosascript: these are blocked whenallowAppleEventsis not set to true, and Claude is told not to retry them withdangerouslyDisableSandbox: true.
Why
On a Mac, a local dev server that fails to start should now come with an explanation and a specific setting to change, instead of a bare permission error. Commands that open apps or run AppleScript will not be quietly retried outside the sandbox.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
The finding says the `/sandbox exclude` and `!` suggestions appear only in a "non-auto" branch but does not say what that mode is.
Anthropic's release notes agree
Improved sandbox guidance on macOS: when a local dev server can't bind a port, Claude now points to sandbox.network.allowLocalBinding