GeistHaus
log in · sign up

How Claude Code escapes its own denylist and sandbox · Ona

ona.com

How Claude Code bypassed its own denylist and sandbox, and why kernel-level enforcement is the answer.

2 pages link to this URL
The agent cannot guard itself

Why coding agents need a sandbox the agent cannot reach, an audit log the agent cannot write, and signed instructions the agent cannot rewrite.

0 inbound links article en