Verification checks#
claude-sandbox verify runs the installed 22-check battery and exits nonzero
on failure. The verify-sandbox skill adds ten agent-driven adversarial probes
only after all checks pass. See how to run verification.
The implementation is .devcontainer/claude-sandbox/verify-sandbox-battery.sh,
installed under /usr/libexec/claude-sandbox/. Detailed rationale lives in
skills/verify-sandbox/references/checks.md.
Phase 1 — the 22-check battery#
# |
Assertion |
|---|---|
01 |
|
02 |
|
03 |
Home contains only allowed entries, the running agent’s own state and shared skills; |
04 |
|
05 |
|
06 |
Effective capabilities ( |
07 |
PID namespace is isolated, checked through |
08 |
The IPC namespace entry is present |
09 |
The UTS namespace entry is present |
10 |
|
11 |
No VS Code IPC or Git sockets are visible in |
12 |
|
13 |
|
14 |
|
15 |
|
16 |
The curated Git config is selected and supplies |
17 |
Writable workspace scope matches the launch directory or explicit override |
18 |
The installed wrapper reads config from |
19 |
Network routes contain the required RFC1918/CGNAT blackholes and a default route |
20 |
Representative blocked destinations have no forwardable route; the gateway remains routable |
21 |
Codex’s writable |
22 |
Each entry-point name ( |
Checks 19–20 pass with a note when the network jail is deliberately disabled. A green battery alone does not establish that network isolation is enabled. Check 06 inspects effective capabilities, which are zero even when the nested user namespace retains a full bounding set.
The defence table maps these assertions to controls. Checks of markers or namespace entries do not prove every aspect of isolation; the live procfs test adds behavioural signal and debugger checks.
Phase 2 — adversarial breakout probes#
After a clean battery, the skill directs the agent to try ten distinct, reversible attacks beyond those checks: for example, credential recovery, namespace crossings, unexpected writable paths or forbidden service access. It stops on a demonstrated escape.
Result |
Meaning |
|---|---|
|
The attempted breach was prevented |
|
A demonstrated violation of the threat model; report |
|
No demonstrated breach or block; report |
Fewer than ten completed probes also means an incomplete audit. Only ten
blocked probes after a clean battery produce
RESULT: SANDBOX OK (22 deterministic + 10 adversarial).
The interactive agent’s exit status is not a CI result; inspect its report.