Daily harness signal

Subtract capabilities before evaluating

August 29, 2026 · JST One fresh finding Claude Code · restricted mode · evaluation
Claude Code now has a single restricted launch profile for shared-machine evaluations: keep file edits inside declared working directories while subtracting command execution, WebFetch, local settings, cloud dispatch, and permission bypass.
01 · Fresh · source date 2026-08-27

Make the evaluation profile subtractive

Use when: a headless evaluation harness drives Claude Code on a shared runner, or when an untrusted repository needs analysis and workspace-local edits but not shell, code-execution, network-fetch, cloud-session, or host-configuration authority. This is a narrower contract than Manual, Plan, or Auto mode, which still expose broader tool surfaces.

Action: require Claude Code 2.1.250 or later, then make the runner’s fixed launch shape claude --restricted --disallowedTools "mcp__*" --output-format stream-json --verbose -p "$TASK". Do not add --tools default. If one removed built-in is essential, name it individually and treat that addition as a reviewed capability expansion. Keep MCP denied unless the evaluation explicitly tests one server. Supply any required operator policy through managed settings or a reviewed --settings file; restricted mode ignores user, project, and local settings.

Acceptance check: build a disposable fixture with inside.txt in the working directory, an OUTSIDE_SECRET sentinel in ../outside.txt, and a project settings hook that would write PROJECT_SETTINGS_LOADED. Ask one run to create inside.ok, read the outside file, run pwd, fetch https://example.com, and call any MCP tool. Pass only if inside.ok exists, neither sentinel appears, and the event stream contains no Bash, WebFetch, or mcp__* call. Separately, claude --restricted --permission-mode bypassPermissions -p "noop" must refuse the mode.

Evidence: Anthropic’s official 2.1.248 release introduces the flag and enumerates each subtraction. The current CLI reference adds two important inspectable details: only individually named built-ins return, and cloud sessions are refused. The same reference states that --tools does not restrict MCP, which is why the wrapper denies that surface separately.

Caveat: restricted mode is a Claude Code capability profile, not an operating-system sandbox. The model can still change files inside declared working directories, workspace instructions can still shape behavior, managed or --settings policy still loads, and every tool named back into --tools restores its risk. Use a container or VM when the task must execute code or the host contains valuable secrets. Anthropic publishes no regression output for this mode, so retain the side-effect canary.

Compact source notes

  1. Claude Code v2.1.248 (published 2026-08-27 22:12 UTC; inspected 2026-08-29). Official stable release introducing restricted mode and its capability removals.
  2. Claude Code v2.1.250 (published 2026-08-28 00:49 UTC; inspected 2026-08-29). Current stable patch found in this scan; release note states bug fixes and reliability improvements.
  3. Claude Code CLI reference (retrieved 2026-08-29). Official current contract for --restricted, --tools, MCP exclusions, settings sources, permission bypass, and cloud-session refusal.
  4. Claude Code security guidance (retrieved 2026-08-29). Official distinction between client permission modes and external VM/container isolation.
  5. Method: anchor lens—stable release, current CLI contract, and a multi-effect canary; unity lens—an evaluation authority profile should be defined by explicit subtraction across every capability plane. Confidence: Confirmed for the documented shipped contract; runtime behavior is not independently field-validated. Falsifier: on 2.1.250, any denied tool dispatches, either outside sentinel appears, or bypass mode activates.