Sandboxing
Isolate Claude's tool access so a compromised session can't escape.
Sandboxing restricts what Claude Code can read, write, and reach from its shell. Learn how macOS Seatbelt, Linux bubblewrap, and Claude's allow/deny rules work together to contain a session.