なぜ設定するのか

サンドボックスの既定の読み取り範囲には ~/.aws/credentials のような認証ファイルも含まれます。読ませる必要のないものは明示的に塞いでおきます。

認証情報を使わせつつ中身は見せたくない場合は sandbox.credentials の mask を使います。

設定方法

  1. ~/.claude/settings.json を開く(なければ作る)
  2. スニペットを JSON の中に統合する。既存の設定は消さず、キーを足す形で入れる
  3. Claude Code を起動し直す
既定値
未設定(~/.aws/credentials なども読める)
書く場所
~/.claude/settings.json
型
array of path strings, using the sandbox path prefixes
置ける場所
Any file

公式ドキュメントの説明

Block sandboxed commands from reading specific paths, such as credential files that the default read policy would otherwise expose. To protect a credential file and keep it usable through the sandbox proxy, see sandbox.credentials instead.

公式リファレンスを見る