You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.281,
ImprovementsSection of the release
What
When Claude runs shell commands in a sandbox (a restricted space that limits which files a command can reach), some folders are allowed to be read. The sandbox now removes an allowed-read entry when it cannot check how that entry's path expands, for example a path containing a variable or wildcard. More entries are dropped as a result, and the sandbox refuses access rather than allowing it when in doubt.
A new MissingWorkingDirectoryError reports Path "…" does not exist when the working directory is missing. A helper to fix the working directory in place was also added.
Why
A path that cannot be checked no longer opens up reading by accident. Watch for commands that could read a folder before and are now refused because its allowed-read entry was dropped.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe finding does not say exactly which path expansions count as checked ("vetted").