なぜ設定するのか

Claude が実行する Bash コマンドを、ファイルシステム・ネットワークから隔離します。/sandbox で選ぶとそのプロジェクトの settings.local.json にしか書かれないので、全プロジェクトで有効にしたいならユーザー設定に書きます。

macOS・Linux・WSL2 のみ。Linux/WSL2 は bubblewrap と socat が必要。起動できないときは黙ってサンドボックスなしで動くので、厳密にしたいなら sandbox.failIfUnavailable も true に。

設定方法

  1. ~/.claude/settings.json を開く(なければ作る)
  2. スニペットを JSON の中に統合する。既存の設定は消さず、キーを足す形で入れる
  3. Claude Code を起動し直す
既定値
false
書く場所
~/.claude/settings.json
型
Boolean
置ける場所
Any file

指定できる値

  • true Claude Code sandboxes Bash commands
  • false Bash commands run unsandboxed

公式ドキュメントの説明

Turn on sandboxing for Bash commands. When you pick a mode in the /sandbox panel, Claude Code writes this key to .claude/settings.local.json for the current project; set it in ~/.claude/settings.json to sandbox every project.

公式リファレンスを見る