{"version":"2.1.284","anchor":"project-hooks-on-remote-tools-can-now-run-inside-the-users","canonical_anchor":"project-hooks-on-remote-tools-can-now-run-inside-the-users","heading":"Project hooks can run inside a macOS sandbox instead of being refused","tier":"notice","area":"Hooks","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/project-hooks-on-remote-tools-can-now-run-inside-the-users","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Project hooks can run inside a macOS sandbox instead of being refused\n\nOn macOS with the sandbox or a proxy on, project hooks run through remote tools can now run confined instead of being refused, behind a flag\n\n**Unclear.** It is not clear what the second condition checks or which parts of Claude Code reach this hook runner.\n\n**What**\n\nProject hooks are commands a project sets Claude Code to run automatically at set moments. When they run through Claude Code's remote tools on macOS, and you already have Claude Code's sandbox or a proxy switched on, they used to be refused outright. The sandbox is a setting that limits which files and network addresses commands can reach.\n\nThere is now a mode for that case. Claude Code wraps the hook command with `sandbox-exec`, macOS's built-in sandboxing tool. The wrapper uses the hook's own list of what it may read and write, and a profile that blocks everything else. If the wrap fails, or does not start by blocking everything, the hook is not run.\n\nThis mode sits behind the tengu_violin_saddle flag. That flag is off unless it is switched on remotely, and it ignores any value set as a local override. A second check must also pass. Without the flag, these hooks are still refused as before. The flag server returned on for this site's account and for the anonymous baseline, in a reading not taken under this release.\n\n**Why**\n\nIf you work with the sandbox on, project hooks through remote tools could run confined instead of being blocked entirely.\n\n- Flag `tengu_violin_saddle`: Off by default, switched on for this account (read for one account on one subscription tier against v2.1.284; this account: on, anonymous baseline: on, compiled default: off) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Hooks\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 3\/5"}