AI News HubLIVE
原文

How we contain Claude across products

Anthropic published a detailed overview of how they sandbox Claude across different products, using techniques like gVisor, Seatbelt, Bubblewrap, and full VMs to set hard boundaries and prevent exfiltration.

How we contain Claude across products

Simon Willison’s Weblog

Subscribe

30th May 2026 - Link Blog

How we contain Claude across products. A complaint I often have about sandboxing products is that they are rarely thoroughly documented, and in the absence of detailed documentation it's hard to know how much I can trust them.

Anthropic just published a fantastic overview of how their various sandbox techniques work across Claude.ai, Claude Code, and Cowork.

We constrain where and how an agent can act with process sandboxes, VMs, filesystem boundaries, and egress controls. The goal is to set a hard boundary on what an agent can reach. For example, if credentials never enter the sandbox, they can't be exfiltrated, regardless of whether the cause is a user, a model finding a “creative” path, or an attacker.

Claude.ai uses gVisor. Claude Code, run locally, uses Seatbelt on macOS and Bubblewrap on Linux. Claude Cowork runs a full VM (Apple's Virtualization framework on macOS, HCS on Windows).

There's a lot in here, including some interesting stories of risks they missed such as the api.anthropic.com/v1/files exfiltration vector covered here previously.

This reminded me it's time I took another look at Anthropic's open source srt (Anthropic Sandbox Runtime) tool - it's mature enough know that I'm ready to give it a proper go.

Recent articles

Claude Opus 4.8: "a modest but tangible improvement" - 28th May 2026

I think Anthropic and OpenAI have found product-market fit - 27th May 2026

Notes on Pope Leo XIV's encyclical on AI - 25th May 2026

This is a link post by Simon Willison, posted on 30th May 2026.

sandboxing 40

security 607

ai 2,045

generative-ai 1,807

llms 1,774

anthropic 288

claude 277

claude-code 115

Monthly briefing

Sponsor me for $10/month and get a curated email digest of the month's most important LLM developments.

Pay me to send you less!

Sponsor & subscribe

Disclosures

Colophon

©

2002

2003

2004

2005

2006

2007

2008

2009

2010

2011

2012

2013

2014

2015

2016

2017

2018

2019

2020

2021

2022

2023

2024

2025

2026