The sandbox limits what commands run by Claude Code can reach. Claude Code refuses to offer its device tools for remote use when the sandbox is missing or has been weakened. Two things changed in how it decides.
It now refuses with the reason sandbox_seccomp_unavailable when seccomp cannot be used. Seccomp is a Linux feature that limits which system operations a program may perform.
The sandbox_weakened reason now also covers these settings:
sandbox.enableWeakerNetworkIsolationsandbox.network.allowLocalBinding- a
sandbox.ripgrepoverride set anywhere other than managed policy settings
Before, it covered only sandbox.allowAppleEvents, sandbox.enableWeakerNestedSandbox and sandbox.network.allowMachLookup. The refusal message tells you to open /sandbox and check its Dependencies tab.
Some devices that used to serve these tools will now be refused. If that happens, the Dependencies tab in /sandbox shows what is missing.
It is not confirmed which remote feature uses these device tools.