Skip to content

The runner's sandbox

On macOS, work on your runner runs in a sandbox. It can write only its own task folder and reach only the model vendor and allowed package registries.

Where work happensLink to Where work happens

Each task gets its own folder under ~/.agent-runner/sandbox. For code work, the runner clones the repository there with your own git access and removes the clone's remote. Work comes back to Agent as a diff. The runner never pushes, opens a pull request or changes a tracker. Agent checks the diff, then applies, verifies and delivers it.

The macOS sandboxLink to The macOS sandbox

On macOS, the CLI and everything it starts run in a sandbox that denies by default:

  • It writes only the task folder and the CLI's own login location.
  • It cannot change the clone's .git folder or your settings.
  • Its only network is the runner's proxy. The proxy reaches the CLI's vendor and, when the repository allows installs, the package registries Agent names.
  • It keeps only the environment variables its CLI needs. Your other tokens stay out.
  • It cannot use the keychain or other secret stores, except Claude Code's own sign-in item.

Shell commandsLink to Shell commands

A runner started with --allow-shell lets work use the CLI's shell. Where there is no sandbox, such as Linux, such a runner takes no shell work. See Runner platforms.

A result with a secret in itLink to A result with a secret in it

When a result contains something shaped like a token, the whole result is refused. Only the reason goes back.

Checked against the product on 2026-10-05.

Was this helpful?