October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

Are Claude Code Mods Sandboxed? What They Can Access

Claude Code mods run with the user’s permissions, outside the Bash sandbox. Here’s what they can access and how to assess the risk.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No. Claude Code mods are not sandboxed. Anthropic says mod code runs with the permissions of the user running Claude Code. A mod can therefore reach files, credentials, programs, and network resources available to that user, and can inspect or alter relevant prompts and tool calls. The Bash sandbox and Claude Code’s permission prompts do not isolate a mod’s own code.

What a Claude Code mod can access

A mod is a plugin whose JavaScript or TypeScript event handlers run inside Claude Code. Anthropic’s direct description is: “A mod is code that runs with your permissions.” Its practical access is determined by your account’s operating-system permissions, available credentials, network environment, and the mod’s implementation—not by whether Claude asks before making a tool call. See Anthropic’s Mods overview.

As an Amazon Associate I earn from qualifying purchases.

  • Files and settings: A mod can read and write files that your user account can access, and may inspect settings and environment variables available to Claude Code.
  • Programs and network: It can start programs and make network requests with the access available to the local process.
  • Session activity: It can observe or change relevant events, including submitted prompts and tool calls. Depending on its handlers, it can intervene in calls, submit prompts, approve tool calls, and affect interface rendering.
  • Usage: A mod can consume model usage billed to your plan or API key by submitting prompts.

These are capabilities, not a claim that every mod uses them. They mean that an enabled mod should be treated as executable software from its author. A plugin can include other components as well—such as hooks, MCP servers, skills, agents, or monitors—with their own behavior and access implications. Anthropic says an enabled plugin is part of sessions where it is enabled; its MCP servers can run alongside those sessions, and its hooks run at configured events. See Plugins overview.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the Bash sandbox does not protect you from a mod

The Bash sandbox is an operating-system-enforced boundary around shell commands Claude runs and the child processes those commands start. It is off by default; enable it with /sandbox or the sandbox.enabled setting. Anthropic’s documentation is explicit: “The sandbox covers shell commands only.” It does not contain mod code.

The sandbox also does not wrap Claude Code’s built-in Read, Edit, Write, WebFetch, or WebSearch tools; hooks; local MCP servers; plugin monitors; language servers; status-line commands; or API-key helper commands. Excluded commands and unsandboxed retry paths may also run outside it, depending on configuration. Anthropic recommends running Claude Code itself in a container or virtual machine when broader isolation for these processes is needed. See Configure the sandboxed Bash tool.

What the shell sandbox restricts when enabled

Its defaults limit shell writes to the working directory, a per-user temporary directory, and added directories; protected paths are write-denied by default. Reads can still reach most of the machine, including credential files such as ~/.ssh and ~/.aws/credentials, unless restrictions or credential masking are configured. Shell network connections go through a local proxy that checks allowed domains; the initial allowed-domain list is empty. The shell inherits Claude Code’s environment, including secrets present there, unless you configure scrubbing or masking.

On macOS, the sandbox uses Seatbelt; on Linux and WSL2, it uses bubblewrap and socat. The Bash sandbox supports those platforms. Native Windows commands run unsandboxed; on Windows, use WSL2 to use this sandbox.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Permission prompts are not operating-system isolation

Claude Code’s permission modes govern Claude’s tool calls, not the independent runtime of code a mod runs. In Manual mode, Claude starts with read-only permissions and asks before file edits, tests, or commands; an action may be approved once or allowed more broadly. Current interactive terminal and VS Code sessions start in Auto mode by default, where a separate classifier reviews actions; explicit ask and deny rules still apply. Anthropic distinguishes these checks from a mod’s own code in its Plugin security and trust guidance.

Other safeguards—such as workspace trust, project working-directory prompts, network request approval in Manual mode, and trust prompts for project-scoped MCP servers—also do not turn a mod into a restricted process. A shell command approved by the user can have effects beyond the file-tool working-directory boundary; the OS-level Bash sandbox is the more direct restriction on shell commands.

Local Claude Code, cloud sessions, and Remote Control differ

Do not assume that protection in a hosted session applies to mods running in your local Claude Code process. Anthropic describes cloud sessions as executing in isolated Anthropic-managed virtual machines. Their network access is limited by default with configurable domain controls; GitHub access uses short-lived scoped credentials, operations are logged, and idle VMs are reclaimed. Self-hosted sessions depend on the organization’s own isolation and egress configuration.

Remote Control is different from a hosted cloud session: the process runs on your machine, and code and file access remain local. The connection syncs the transcript through Anthropic’s API; Anthropic says Remote Control does not involve a cloud VM or sandbox. Details are in the Security documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to evaluate a mod before enabling it

  1. Verify the source and author. Use only authors and marketplaces you trust. A marketplace’s identity indicates who publishes its catalog; it is not a safety audit. Anthropic says it does not control plugin contents and does not security-audit or manage MCP servers.
  2. Inspect what the plugin declares. Review the marketplace source and plugin details pane, hook command definitions, .mcp.json, and executable files in bin/. Check which components are included and what they run.
  3. Review mod events and requested calls. The mods documentation describes claude plugin validate as a way to list mod events and requested calls without running the mod. Mods require Claude Code v2.1.287 or later according to the current documentation.
  4. Apply organizational controls where available. Managed settings can allowlist or block marketplace sources, force-enable plugins, and limit hooks. These controls help govern installation and plugin behavior; they do not make arbitrary mod code sandboxed.
  5. Isolate sensitive work more broadly. Review changes and commands, audit permission settings, and consider running Claude Code in a development container or virtual machine when working with sensitive code or untrusted mods. Anthropic cautions that no system is completely immune to attacks.

Mods are on by default, but users and administrators have documented controls to disable and manage them. The precise controls depend on the Claude Code setup; consult Anthropic’s Mods overview and managed-settings guidance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.