02 · What that line is
A request to the agent, not a control.
In the vocabulary every published behaviour policy uses, a line in the agent's instructions is an expectation: a rule in prose, enforced by nobody. A rule in prose is inside the boundary the agent operates in. All four major model providers stated in their own 2026 words that an instruction at this layer can be bypassed. It changes what the agent usually does, which is worth having; it does not hold when the agent is talked out of it, confused, or reading somebody else's instructions in a web page.
If you want more than a request, these are stronger, each quoted from the vendor's own page on the date shown.
setting · a switch the agent's own account can flipDeny rules on the shell's network tools, with WebFetch allowed only for named domains
{
"permissions": {
"deny": [
"Bash(curl *)",
"Bash(wget *)"
],
"allow": [
"WebFetch(domain:github.com)"
]
}
}“Restrict Bash network tools: use deny rules to stop curl, wget, and similar commands, then use the WebFetch tool with WebFetch(domain:github.com) permission for allowed domains. A deny rule doesn't match the same program by path or inside sh -c, so pair it with the sandbox network allowlist when the restriction must hold.”
code.claude.com/docs/en/permissions · read 8 October 2026
boundary · enforced above the grant, out of the agent's reachClaude Code's Bash sandbox, with its network allowlist
Turn the sandbox on and list only the hosts the work needs under sandbox.network.allowedDomains. It covers shell commands and the processes they start; WebFetch follows permission rules instead.
“Network: No direct route out. Connections go through a proxy on your machine that checks each host against your allowed domains, which start empty. … allowedDomains doesn't limit WebFetch.”
code.claude.com/docs/en/sandboxing · read 8 October 2026