02 · What that line is
A request to the agent, not a control.
In the vocabulary every published behaviour policy uses, a line in the agent's instructions is an expectation: a rule in prose, enforced by nobody. A rule in prose is inside the boundary the agent operates in. All four major model providers stated in their own 2026 words that an instruction at this layer can be bypassed. It changes what the agent usually does, which is worth having; it does not hold when the agent is talked out of it, confused, or reading somebody else's instructions in a web page.
If you want more than a request, these are stronger, each quoted from the vendor's own page on the date shown.
setting · a switch the agent's own account can flipClaude Code prompts before its file tools read outside the working directory, and a setting extends that to read-only shell commands
Leave Manual mode on for reads outside the project, and set permissions.blockReadsOutsideWorkingDirectories so that read-only shell commands such as cat and ls do not get round it.
“File-access tools marked No, including Read, Grep, and Glob, still prompt for paths outside the working directory and additional directories. (The permissions page: Claude Code recognizes a built-in set of Bash commands as read-only and runs them without a permission prompt in every mode, except as permissions.blockReadsOutsideWorkingDirectories changes for paths outside your working directories.)”
code.claude.com/docs/en/tools-reference · code.claude.com/docs/en/permissions · read 8 October 2026
boundary · enforced above the grant, out of the agent's reachClaude Code's Bash sandbox, with the paths listed in its denyRead setting
Turn the sandbox on (/sandbox) and list the paths under sandbox.filesystem.denyRead. It holds for shell commands and every process they start; Claude's own Read tool runs outside it, so keep the Read deny rule as well.
“The Bash sandbox is a boundary that the operating system enforces around the shell commands Claude runs on your machine. … The sandbox is off by default. … Reads: Most of the machine, including credential files such as ~/.ssh and ~/.aws/credentials. … A denyRead entry doesn't stop the Read tool.”
code.claude.com/docs/en/sandboxing · read 8 October 2026