# Run coding agents unattended only inside a container, VM or sandbox runtime, not with the Bash sandbox alone

> The flag --dangerously-skip-permissions is meant to run only inside a container, a VM or the sandbox runtime, because the built-in Bash sandbox covers shell commands only and network egress can still leak what the agent can read.

## Answer

No, `--dangerously-skip-permissions` is not safe on a bare host. The Claude Code docs say to run it only inside a container, a VM or the sandbox runtime, so that file tools, MCP servers and hooks are inside the boundary too. The built-in Bash sandbox is not enough, because it covers only shell commands. This page follows the docs as checked on 2026-09-28 (Claude Code 2.1.284). No sandbox stops data leaking through allowed network access.

## Details

### What the Bash sandbox does not cover

The built-in sandbox restricts Bash, PowerShell and Monitor commands and their child processes. Built-in file tools run inside the Claude Code process and are gated by permission rules. MCP servers and command hooks are separate processes that run unconstrained on the host. It works on macOS, Linux and WSL2, not on native Windows.

### Choose an isolation level

| What can the agent reach? | What could leak? | Isolation |
|---|---|---|
| Your machine, with prompts still on | Little, because you approve each action | Bash sandbox via `/sandbox` |
| Your machine, prompts off | Everything your user can read | Not acceptable; use one of the rows below |
| Only the mounted project | Project files, plus anything reachable over the network | Container (dev container or custom) |
| Nothing shared with the host | What is inside the VM | Virtual machine (docs list this as the strongest separation) |
| Host, but the whole process wrapped | Whatever the settings allow | Sandbox runtime `@anthropic-ai/sandbox-runtime`, a beta research preview whose configuration format may change |

For an untrusted repository the docs point to a dedicated VM or a cloud session.

### Run it in a container

The docs' example dev container uses a default-deny firewall (`init-firewall.sh`, which needs the `NET_ADMIN` and `NET_RAW` capabilities). A plain Docker container has no such firewall. This minimal sketch installs the CLI with the command the docs give. I could not build it, because no Docker daemon was available where I wrote this page. Treat it as untested.

```dockerfile
FROM node:22-bookworm-slim
RUN npm install -g @anthropic-ai/claude-code \
 && mkdir -p /home/node/.claude && chown node:node /home/node/.claude
USER node
WORKDIR /workspace
```

1. Build it: `docker build -t agent-box .`
2. Run it with only the project mounted, as a non-root user:

```sh
docker run --rm -it \
  -v "$PWD":/workspace \
  -v agent-config:/home/node/.claude \
  -e CLAUDE_CONFIG_DIR=/home/node/.claude \
  agent-box claude --dangerously-skip-permissions
```

The volume and `CLAUDE_CONFIG_DIR` follow the docs' pattern for keeping sign-in between runs. Claude Code refuses this flag as root on Linux and macOS, hence `USER node`. The project mount is writable, so review its changes with `git diff` afterwards.

### Audit: which secrets are reachable?

- Is your `~/.ssh` or any cloud credential file mounted? Do not mount it. Prefer repository-scoped or short-lived tokens.
- Does the project contain `.env` files? Everything inside the container can read them.
- Are Claude Code's own credentials in `~/.claude` in the container? With the flag on, a malicious project can send out anything readable there.
- Does the network policy allow broad domains such as `github.com`? The docs warn this can open paths for exfiltration.
- Is a Docker socket mounted? The docs warn it effectively grants access to the host.

### Common mistakes

- Treating the Bash sandbox as an unattended-run boundary.
- Running the container as root and hitting the flag refusal.
- Trusting a sandbox as a hard control while egress is open.
- Enabling `enableWeakerNestedSandbox` without an outer boundary. The docs say it considerably weakens security.

## See also

- [[prompt-injection-in-agents-lethal-trifecta]]
- [[parallel-agents-git-worktrees]]
- [[claude-code-skills-vs-subagents-vs-hooks]]
- [[mcp-security-checklist]]

## Sources

- [Claude Code — Choose a sandbox environment](https://code.claude.com/docs/en/sandbox-environments)
- [Claude Code — Configure the sandboxed Bash tool](https://code.claude.com/docs/en/sandboxing)
- [Claude Code — Development containers](https://code.claude.com/docs/en/devcontainer)
- [Hacker News — Git worktrees are not an isolation boundary for coding agents](https://news.ycombinator.com/item?id=49110389)

## Sources

- [Claude Code — Choose a sandbox environment](https://code.claude.com/docs/en/sandbox-environments)
- [Claude Code — Configure the sandboxed Bash tool](https://code.claude.com/docs/en/sandboxing)
- [Claude Code — Development containers](https://code.claude.com/docs/en/devcontainer)
- [Hacker News — Git worktrees are not an isolation boundary for coding agents](https://news.ycombinator.com/item?id=49110389)