Skip to main content
Run any Skill in Manus
with one click

claude-sandbox-networking

Stars3
Forks1
UpdatedJune 18, 2026 at 19:21

Network egress, firewall, and lateral-movement design for this repo's bwrap Claude sandbox. The per-process egress jail (netns + pasta routing allowlist, ADR 0015, issue #56) is ON by default as of 2026-06-18, fail-closed, with a CLAUDE_SANDBOX_EGRESS_JAIL=0 escape hatch — overriding ADR 0005's earlier open-egress default. Surface BEFORE proposing or discussing ANY network change: egress filtering, firewall / nftables / iptables / DOCKER-USER, `--unshare-net`, netns / veth, pasta / slirp4netns, a CONNECT or SNI proxy, `HTTPS_PROXY` injection, VLAN / segmentation, Claude Code's native sandbox `allowedDomains`, or device-access networking (EPICS / Channel Access / pvAccess / PMAC).

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly