Project hooks are commands a project sets Claude Code to run automatically at set moments. When they run through Claude Code's remote tools on macOS, and you already have Claude Code's sandbox or a proxy switched on, they used to be refused outright. The sandbox is a setting that limits which files and network addresses commands can reach.
There is now a mode for that case. Claude Code wraps the hook command with sandbox-exec, macOS's built-in sandboxing tool. The wrapper uses the hook's own list of what it may read and write, and a profile that blocks everything else. If the wrap fails, or does not start by blocking everything, the hook is not run.
This mode sits behind the tengu_violin_saddle flag. That flag is off unless it is switched on remotely, and it ignores any value set as a local override. A second check must also pass. Without the flag, these hooks are still refused as before. The flag server returned on for this site's account and for the anonymous baseline, in a reading not taken under this release.
If you work with the sandbox on, project hooks through remote tools could run confined instead of being blocked entirely.
tengu_violin_saddle Off by default, switched on for this accountThe shipped code defaults this off, and the flag server returned on for the one account this site reads on this version. That is the reading that makes the entry above worth a second look, and it still says nothing about your account.
This account: on · anonymous baseline: on · compiled default in v2.1.284: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.284. It isn't a statement about your account. What a flag value here can and cannot tell you
It is not clear what the second condition checks or which parts of Claude Code reach this hook runner.