Claude Code built-in sandbox hardened
bubblewrap for filesystem and namespace isolation, socat plumbing a loopback port to a host-side allowlisting proxy, plus a seccomp filter whose one job is blocking Unix domain sockets. Confines every Bash command and all of its children.[1]
needs Linux or WSL2 · bubblewrap + socat
gate Ubuntu 24.04+ needs an AppArmor profile for bwrap[1]
setup ~5 minutes
Writes land in cwd and the session temp dir; egress goes through a hostname allowlist. Everything else on this board is additive.
