{"version":"2.1.292","anchor":"sandbox-masks-credential-files-for-deny-roots","canonical_anchor":"sandbox-masks-credential-files-for-deny-roots","heading":"Sandbox marks blocked credential locations as masked","tier":"internal","area":"Sandbox","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292\/e\/sandbox-masks-credential-files-for-deny-roots","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292","markdown":"### Sandbox marks blocked credential locations as masked\n\nWhen the sandbox masks credential files, the locations it blocks reading from are now flagged as masked, and a list of trusted blocked locations is added\n\n**Unclear.** It is not clear what turns on mask mode or what this changes for someone using the sandbox.\n\n**What**\n\nThe sandbox is a fenced-off environment that limits what commands Claude Code runs can touch. When it is set to mask credential files, such as files holding passwords or keys, the locations it blocks reading from are now flagged as masked. A separate list of trusted blocked locations has also been added.\n\n**Why**\n\nThis changes how the sandbox handles credential files.\n\n- Area: Sandbox\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 3\/5\n- Scope: individual\n- Heads-up: no"}