Sandbox

April 2, 2026 ยท View on GitHub

This feature exists in the official Claude Code codebase but has not been fully released. cc-mini implements and ships it.

Runs Bash commands inside bubblewrap (bwrap) isolation on Linux.

How It Works

  • Filesystem mounted read-only (--ro-bind / /)
  • Only current working directory is writable (--bind $CWD $CWD)
  • Network isolated by default (--unshare-net)
  • Config files protected from modification
  • PID namespace isolated (--unshare-pid)

Modes

ModeBehavior
auto-allowSandbox on, bash auto-approved
regularSandbox on, bash needs confirmation
disabledNo sandbox (default)

REPL Commands

> /sandbox                     # interactive mode selector
> /sandbox status              # show status + dependency check
> /sandbox mode auto-allow     # enable with auto-allow
> /sandbox mode disabled       # disable
> /sandbox exclude "docker *"  # skip sandbox for matching commands

TOML Config

[sandbox]
enabled = true
auto_allow_bash = true
excluded_commands = ["docker *", "npm run *"]
unshare_net = true

[sandbox.filesystem]
allow_write = ["."]

Excluded Commands

Patterns: exact ("git"), prefix ("npm run"), wildcard ("docker *"). Excluded commands still need normal permission prompt.

Graceful Degradation

If bwrap is not installed (non-Linux, Docker), sandbox auto-disables. Check with /sandbox status.