02 · What that line is
A request to the agent, not a control.
In the vocabulary every published behaviour policy uses, a line in the agent's instructions is an expectation: a rule in prose, enforced by nobody. A rule in prose is inside the boundary the agent operates in. All four major model providers stated in their own 2026 words that an instruction at this layer can be bypassed. It changes what the agent usually does, which is worth having; it does not hold when the agent is talked out of it, confused, or reading somebody else's instructions in a web page.
If you want more than a request, these are stronger, each quoted from the vendor's own page on the date shown.
setting · a switch the agent's own account can flipAn ask rule on rm in Claude Code's settings
{
"permissions": {
"ask": [
"Bash(rm *)"
]
}
}“A deny or ask rule matches past any leading assignment, so Bash(rm *) in deny still matches FOO=bar rm -rf tmp/. (The same page: a Bash rule matches the command text Claude writes, so a deny or ask rule covers the invocation Claude usually produces and isn't a security boundary around the program.)”
code.claude.com/docs/en/permissions · read 8 October 2026
boundary · enforced above the grant, out of the agent's reachClaude Code's Bash sandbox, which limits where shell commands can write
Turn the sandbox on (/sandbox). Shell commands, and the processes they start, can then write only inside the working directory and a few named places.
“By default, sandboxed commands can write to the current working directory, the per-user temp directory, and any directories you've added with --add-dir, /add-dir, or permissions.additionalDirectories. … The sandbox is off by default.”
code.claude.com/docs/en/sandboxing · read 8 October 2026