なぜ設定するのか
サンドボックスの既定の読み取り範囲には ~/.aws/credentials のような認証ファイルも含まれます。読ませる必要のないものは明示的に塞いでおきます。
認証情報を使わせつつ中身は見せたくない場合は sandbox.credentials の mask を使います。
設定方法
~/.claude/settings.jsonを開く(なければ作る)- スニペットを JSON の中に統合する。既存の設定は消さず、キーを足す形で入れる
- Claude Code を起動し直す
- 既定値
- 未設定(~/.aws/credentials なども読める)
- 書く場所
~/.claude/settings.json- 型
- array of path strings, using the sandbox path prefixes
- 置ける場所
- Any file
公式ドキュメントの説明
Block sandboxed commands from reading specific paths, such as credential files that the default read policy would otherwise expose. To protect a credential file and keep it usable through the sandbox proxy, see sandbox.credentials instead.