{"version":"2.1.282","anchor":"sandbox-more-claude-subdirectories-added-to-the-protecte","canonical_anchor":"sandbox-more-claude-subdirectories-added-to-the-protecte","heading":"Sandbox gives four more Claude config folders the same protection as existing ones","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282\/e\/sandbox-more-claude-subdirectories-added-to-the-protecte","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282","markdown":"### Sandbox gives four more Claude config folders the same protection as existing ones\n\nThe sandbox now treats the todos, statsig, logs and access-audit folders under the Claude config directory like the folders it already protected\n\n**Unclear.** It is not confirmed that this treatment means blocking writes rather than some other restriction.\n\n**What**\n\nThe sandbox is a restricted environment Claude Code can run commands in, with limits on which files and folders they may touch. When it builds its rules, it gives some folders inside the Claude config directory (usually `~\/.claude`) special treatment. That treatment already covered `mcp-skill-archives`, `mcp-discovery-cache` and `shares`. It now also covers:\n\n- `todos`\n\n- `statsig`\n\n- `logs`\n\n- `access-audit`\n\n**Why**\n\nCommands run inside the sandbox may no longer be able to write to these four folders, the same as for the three folders that were already on the list.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 2\/5"}