{"version":"2.1.292","anchor":"write-toolagent-spawn-plugin-hooks-subagent-bash-restricti","canonical_anchor":"write-toolagent-spawn-plugin-hooks-subagent-bash-restricti","heading":"Some callers can no longer turn off the sandbox or run commands in the background","tier":"notice","area":"Bash Tool","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292\/e\/write-toolagent-spawn-plugin-hooks-subagent-bash-restricti","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292","markdown":"### Some callers can no longer turn off the sandbox or run commands in the background\n\nFor a restricted kind of caller, shell commands that ask to skip the sandbox or run in the background are refused or forced off\n\n**Unclear.** Which callers count as restricted, and so who is affected, is not clear.\n\n**What**\n\nThe Bash tool runs shell commands. A command can normally ask to run outside the sandbox (the protective boundary limiting what it can touch) with `dangerouslyDisableSandbox`, or to run in the background with `run_in_background`. For a restricted kind of caller, Claude Code now refuses those options with a message saying the option is not available and to run the command in the foreground. Otherwise both options are forced off.\n\n**Why**\n\nIt limits what these callers can do with shell commands.\n\n- Area: Bash Tool\n- Names: `dangerouslyDisableSandbox`, `run_in_background`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: no"}