{"version":"2.1.285","anchor":"sandbox-allowunsandboxedcommandsfalse-also-honored-from-a","canonical_anchor":"sandbox-allowunsandboxedcommandsfalse-also-honored-from-a","heading":"Turning off unsandboxed commands is honored from an additional settings source","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/sandbox-allowunsandboxedcommandsfalse-also-honored-from-a","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Turning off unsandboxed commands is honored from an additional settings source\n\nSetting `allowUnsandboxedCommands` to false is now also read through a second settings lookup\n\n**Unclear.** It is not clear which settings source the additional lookup reads.\n\n**What**\n\n`allowUnsandboxedCommands` set to false stops commands from running outside the sandbox (the limits on what commands run by Claude can reach). Claude Code used to read it only from the sandbox settings and from settings passed on the command line. It now also treats it as false when a second, more general settings lookup returns false.\n\n**Why**\n\nThe restriction may now apply in more places than before.\n\n- Area: Sandbox\n- Names: `allowUnsandboxedCommands`\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}