Skip to main content
在 Manus 中运行任何 Skill
一键导入

claude-sandbox-networking

星标3
分支1
更新时间2026年6月18日 19:21

Network egress, firewall, and lateral-movement design for this repo's bwrap Claude sandbox. The per-process egress jail (netns + pasta routing allowlist, ADR 0015, issue #56) is ON by default as of 2026-06-18, fail-closed, with a CLAUDE_SANDBOX_EGRESS_JAIL=0 escape hatch — overriding ADR 0005's earlier open-egress default. Surface BEFORE proposing or discussing ANY network change: egress filtering, firewall / nftables / iptables / DOCKER-USER, `--unshare-net`, netns / veth, pasta / slirp4netns, a CONNECT or SNI proxy, `HTTPS_PROXY` injection, VLAN / segmentation, Claude Code's native sandbox `allowedDomains`, or device-access networking (EPICS / Channel Access / pvAccess / PMAC).

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

SKILL.md
readonly