What’s installed#
uv tool install claude-sandbox installs the host launcher. The selected
image contains the sandbox below; uvx claude-sandbox install installs it
into your own devcontainer.
Container files#
Path |
Purpose |
|---|---|
|
The same three-line wrapper. It runs the sandbox’s own interpreter, which selects an agent profile by command name |
|
Pinned CPython for the sandbox, pruned to about 60 MB, root-owned and byte-compiled. In the published image it is also the projects’ Python: project venvs link to it but cannot change it |
|
The |
|
The pinned uv that installed that CPython, kept so a reinstall need not fetch it again. The published image drops it after installation and keeps one uv, its base image’s, for projects |
|
Claude binary, relocated off PATH |
|
Codex release, including its bundled helpers; read-only inside the sandbox |
|
Standalone Pi executable and assets; read-only inside the sandbox |
|
Pi launch-marker check; see its limits |
|
System-prompt note that tells Pi about the sandbox it runs in |
|
Codex’s in-jail launch wrapper |
|
The |
|
Installed isolation checks |
|
Shipped skills, mounted read-only into each agent’s discovery directory |
|
Recommended Claude status line |
|
Pi footer showing the host and container tag |
|
Installed release or checkout revision |
|
Records a wheel installation for update instructions |
|
Curated Git config, refreshed from your identity at agent launch |
|
Disables Claude’s updater and makes the |
|
Disables Codex startup update checks; an administrator-owned file is left unchanged with a warning |
|
The installer adds passt (providing pasta) for the network jail. Custom
devcontainers must supply /dev/net/tun through runArgs; the host launcher
does this automatically.
Wrappers are installed even if an optional agent download is skipped or fails.
They report a missing binary rather than falling through to an unwrapped
agent. Use WITH_CODEX=0 or WITH_PI=0 at installation to skip those downloads;
PI_VERSION pins Pi’s release. Reinstalling preserves existing agent binaries.
See Upgrade.
User state#
Each agent sees only its own state, plus the shared skills and forge stores.
With /user-terminal-config mounted, agent state and shared skills persist
across rebuilds; forge tokens remain container-local.
Path |
Installer behaviour |
|---|---|
|
Preserve login, settings and hooks; seed a status line only if absent |
|
Create if absent; preserve configuration, credentials and sessions |
|
Preserve Pi settings, credentials, extensions and sessions |
|
Shared writable skills; created if absent, with Claude discovery through symlinks |
claude-sandbox doctor --fix replaces the Claude status line with the
recommended version, backing up changed files. See
container tags and
shared skills.
Optional tools#
The published image includes Python, uv, Node.js, npm and Vim. Custom containers keep their own toolchain choices.
The image’s Python is the sandbox’s own pinned interpreter, and uv there
never downloads another on its own (UV_PYTHON_DOWNLOADS=manual). For a
project that needs a different version, run uv python install 3.12 (for
example) from claude-sandbox shell, then recreate the project’s venv; an
agent session cannot install one. Don’t run uv python uninstall 3.13 from
that shell: it removes the sandbox’s interpreter and every agent launch
fails. uvx claude-sandbox --recreate recovers it.
Shipped skills provide installers for optional tools, run outside the agent:
Browser automation: Playwright and Chromium.
VS Code automation: VS Code, Xvfb and a UI driver.
Browser downloads persist under /cache/ms-playwright. After setup,
chromium also works from an outer container terminal with a display;
its profile lives under /cache/chromium-home.