Require every component to qualify
Use when
Claude
Code
uses
sandbox.excludedCommands
and
an
agent
combines
an
excluded
tool
with
otherwise
confined
work.
Version
2.1.277
repairs
whole-invocation
exemption
when
only
one
part
matches;
every
part
must
now
match.
Action
Require
that
repair
or
a
reviewed
equivalent
before
relying
on
mixed-command
confinement.
Inspect
effective
exclusions
across
all
settings
scopes;
retain
only
necessary,
approved
exceptions.
Prefer
narrow
filesystem
grants
when
sufficient.
Separate
intentionally
unsandboxed
work
from
confined
work.
Keep
sandbox.enabled=true,
sandbox.failIfUnavailable=true,
and
sandbox.allowUnsandboxedCommands=false.
These
switches
do
not
cancel
explicit
exclusions.
An
empty
list
in
one
scope
does
not
erase
merged
entries
elsewhere.
Do
not
substitute
punctuation-matching
regexes
for
shell-aware
enforcement.
Acceptance check
In
an
authorized
disposable
environment,
plant
a
dummy
sentinel
at
a
read-denied
path.
An
authorized
outside-sandbox
control
must
read
it;
standalone
Bash
must
not.
Configure
a
harmless
excluded
probe,
then
place
the
denied
read
before
and
after
it.
Cover
semicolon,
newline,
&&,
||,
and
pipe,
choosing
control
flow
that
actually
reaches
the
read.
No
mixed
invocation
may
expose
the
sentinel.
The
excluded
probe
alone
must
still
work;
execution
telemetry
must
establish
its
exemption.
Exercise
actual
parent
and
applicable
child
paths.
Retain
version,
resolved
settings,
raw
calls,
stdout/stderr,
and
sandbox
receipts.
Exit
zero
alone
is
not
a
pass:
the
final
probe
can
hide
an
earlier
denial.
Evidence
Anthropic’s dated release states the all-parts repair. Issue 81157 contains 2.1.220 read probes, a separate 2.1.234 write reproduction, and August 25 maintainer-account confirmation using a planted file. That confirmation is signed as generated with Claude Code. Official documentation confirms that strict retry mode still permits exclusions.
Caveat
No public implementation, passing regression output, or independent post-fix validation was inspected. The release does not promise separately sandboxed segments. Excluded tools and their subprocesses remain privileged; wrappers, substitutions, redirections, and non-Bash tools need separate coverage. Current docs also say exclusions lack a managed-only lockdown. This is a narrow repair, not proof of complete containment. The proposed fixture was not executed; no upgrade, configuration change, or evaluation is authorized by this issue.