Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No. Anthropic says Claude Code mods run with your permissions, not inside the Bash sandbox. A mod may be able to read or change files available to your account, access environment variables and settings, start programs, make network requests, and inspect or alter session prompts and tool calls. The exact reach depends on the mod’s code and the access your account already has.

What “not sandboxed” means for a Claude Code mod

Anthropic describes a mod as JavaScript or TypeScript code whose event handlers run inside Claude Code. Those handlers can observe, change, or take over relevant events, including submitted prompts and tool calls. A mod can also add interface panes and commands. Anthropic’s direct description is: “A mod is code that runs with your permissions.” (Anthropic’s Mods overview.)

In practical terms, a mod’s potential access follows the privileges of the user running Claude Code. Depending on its implementation, it can read user-accessible files, use available credentials or environment variables, start programs, and communicate over the network. Its event handlers can inspect or alter session activity, submit prompts, or approve tool calls. A mod can also consume model usage on the user’s plan or API key.

This describes what a mod can do, not what every mod does. Review a particular mod’s source and declared components rather than assuming its capabilities from its name or marketplace.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does the Bash sandbox protect you from mods?

No. The Bash sandbox is an operating-system boundary for shell commands Claude runs and the child processes those commands start. Anthropic states that “The sandbox covers shell commands only.” It does not wrap mod code. It also does not cover several other components and tools, including built-in file and web tools, hooks, local MCP servers, plugin monitors, language servers, status-line commands, or API-key helper commands. See Configure the sandboxed Bash tool for the scope and exclusions.

The distinction matters because a shell command and a mod are different execution paths. Restricting Bash does not make other code in the Claude Code session run as a restricted operating-system process.

What the Bash sandbox restricts when enabled

The Bash sandbox is off by default. Enable it with /sandbox or the sandbox.enabled setting. On macOS, it uses Seatbelt; on Linux and WSL2, it uses bubblewrap and socat. It supports macOS, Linux, and WSL2. Native Windows commands run unsandboxed; on Windows, use WSL2 to use this sandbox.

  • Writes: By default, shell writes are limited to the working directory, a per-user temporary directory, and directories added to the sandbox configuration. Protected paths remain write-denied by default.
  • Reads: Shell commands can read most of the machine by default, including credential files such as ~/.ssh and ~/.aws/credentials, unless restrictions or credential masking are configured.
  • Network: Shell connections pass through a local proxy rather than going directly out. The allowed-domain list starts empty; permitted domains can be configured.
  • Environment: Sandboxed commands inherit Claude Code’s environment, including secrets present there, unless configured to scrub or mask them.

These are limits on sandboxed shell commands, not assurances that a mod or excluded component cannot reach the same resources. Anthropic notes that excluded commands and unsandboxed retry paths can also run outside the shell boundary, depending on settings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How mods, permissions, and execution environments differ

Path or control What it governs Security boundary
Mod code JavaScript or TypeScript event handlers inside Claude Code Runs with the user’s permissions; the Bash sandbox does not contain it.
Bash sandbox Shell commands and their child processes Operating-system-enforced filesystem and network restrictions when enabled; excludes mods and other named components.
Permission mode Claude’s tool calls Controls whether tool actions proceed, prompt for approval, or are evaluated by a classifier; it does not isolate mod code.
Hosted cloud session Claude Code running in an Anthropic-hosted session Runs in an isolated Anthropic-managed VM, with network controls; this is distinct from local execution.
Remote Control A remote interface to Claude Code running on your machine Execution and file access remain local; Remote Control does not add a cloud VM or sandbox.

For the distinctions among permissions and local safeguards, see Anthropic’s Security documentation. Hosted cloud sessions have their own isolation and network controls; self-hosted sessions depend on the organization’s isolation and egress setup. Remote Control connects to a local process, with the transcript synced through Anthropic’s API. Do not treat cloud-session protections as protections for local mods.

What permission modes do—and do not—protect

Permission modes govern Claude’s tool calls, not the mod runtime. In Manual mode, Claude Code begins with read-only permissions and asks before edits, tests, or commands; a user may approve an action once or allow it more broadly. Current interactive terminal and VS Code sessions start in Auto mode by default, where a separate classifier reviews actions. Explicit ask and deny rules still apply.

Project working-directory prompts, network approval behavior in Manual mode, workspace trust, and trust prompts for project-scoped MCP servers are additional controls. They do not turn a mod into an isolated process. Even an approved Bash command can have effects outside the file-tool working-directory boundary; an OS-level shell sandbox is the more direct restriction on shell execution.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to review a mod before enabling it

  1. Inspect its source and declared components. Review the marketplace source, the plugin details pane, hook command definitions, .mcp.json, and executable files in bin/. These can reveal what else the plugin runs besides its mod handlers. Anthropic’s guidance is in Plugin security and trust.
  2. Validate without running it. The Mods overview documents claude plugin validate as a way to list mod events and requested calls without executing the mod. Use the output to understand which events it handles and what it asks to do.
  3. Assess the publisher and source. Use authors and marketplaces you trust, but do not treat a marketplace’s identity or tier as a security audit. Anthropic says it does not control plugin contents and does not security-audit or manage MCP servers.
  4. Check organizational controls. Administrators can use managed settings to allowlist or block marketplace sources, force-enable plugins, and limit hooks.
  5. Reduce exposure for sensitive work. Review proposed changes and commands, audit permission settings, and consider running Claude Code itself inside a development container or virtual machine. That broader isolation can cover processes that the Bash sandbox excludes; it is not a guarantee against every attack.

Mods require Claude Code v2.1.287 or later according to the current Mods overview. The overview also documents controls to disable and manage mods; consult it for current settings and behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.