What
The sandbox is a restricted environment that shell commands run inside, which limits what they can reach. Each tool Claude can use comes with a schema, a description of the inputs Claude is allowed to fill in. The Bash and PowerShell tools have an input called dangerouslyDisableSandbox, which asks to run a command outside the sandbox.
The schemas are now trimmed to match your sandbox settings:
dangerouslyDisableSandboxis removed from the Bash and PowerShell input schemas when the sandbox settings reportunsandboxedCommandsDisabled.run_in_backgroundis still removed separately from the Bash schema when background tasks are disabled.- For another schema, the same trimming also removes
run_in_backgroundand_simulatedSedEdit. - The setup that turns off both background tasks and unsandboxed commands is applied where the tool schemas are listed.
Before this release, the schemas kept dangerouslyDisableSandbox in these cases. It was only listed as an input that would be refused if Claude used it.
Why
If your setup does not allow commands to run outside the sandbox, Claude is no longer shown an option it cannot use. It therefore cannot try to escape the sandbox and then be refused.
It is not clear which way of running Claude Code turns unsandboxed commands off in this way.