Make the evaluation profile subtractive
Use when: a headless evaluation harness drives Claude Code on a shared runner, or when an untrusted repository needs analysis and workspace-local edits but not shell, code-execution, network-fetch, cloud-session, or host-configuration authority. This is a narrower contract than Manual, Plan, or Auto mode, which still expose broader tool surfaces.
2.1.250
or
later,
then
make
the
runner’s
fixed
launch
shape
claude --restricted --disallowedTools "mcp__*" --output-format stream-json --verbose -p "$TASK".
Do
not
add
--tools default.
If
one
removed
built-in
is
essential,
name
it
individually
and
treat
that
addition
as
a
reviewed
capability
expansion.
Keep
MCP
denied
unless
the
evaluation
explicitly
tests
one
server.
Supply
any
required
operator
policy
through
managed
settings
or
a
reviewed
--settings
file;
restricted
mode
ignores
user,
project,
and
local
settings.
Acceptance
check:
build
a
disposable
fixture
with
inside.txt
in
the
working
directory,
an
OUTSIDE_SECRET
sentinel
in
../outside.txt,
and
a
project
settings
hook
that
would
write
PROJECT_SETTINGS_LOADED.
Ask
one
run
to
create
inside.ok,
read
the
outside
file,
run
pwd,
fetch
https://example.com,
and
call
any
MCP
tool.
Pass
only
if
inside.ok
exists,
neither
sentinel
appears,
and
the
event
stream
contains
no
Bash,
WebFetch,
or
mcp__*
call.
Separately,
claude --restricted --permission-mode bypassPermissions -p "noop"
must
refuse
the
mode.
2.1.248
release
introduces
the
flag
and
enumerates
each
subtraction.
The
current
CLI
reference
adds
two
important
inspectable
details:
only
individually
named
built-ins
return,
and
cloud
sessions
are
refused.
The
same
reference
states
that
--tools
does
not
restrict
MCP,
which
is
why
the
wrapper
denies
that
surface
separately.
Caveat:
restricted
mode
is
a
Claude
Code
capability
profile,
not
an
operating-system
sandbox.
The
model
can
still
change
files
inside
declared
working
directories,
workspace
instructions
can
still
shape
behavior,
managed
or
--settings
policy
still
loads,
and
every
tool
named
back
into
--tools
restores
its
risk.
Use
a
container
or
VM
when
the
task
must
execute
code
or
the
host
contains
valuable
secrets.
Anthropic
publishes
no
regression
output
for
this
mode,
so
retain
the
side-effect
canary.