Independent use will determine whether BubbleClaude’s bubblewrap allowlist, which omits host files, credentials, and environment variables from the sandbox, provides practical isolation for unattended Claude Code sessions.
state: expiredheat: lowuncertainty: highknownscott: lowagentic-security agent-harnesses coding-agentsremileducAnthropic
What is this?
BubbleClaude is a single Bash script attributed here to remileduc that runs Anthropic’s Claude Code inside a Linux bubblewrap namespace, using an allowlist so the host home directory, credentials, and environment variables are absent rather than merely blocked by application-level permissions. The approach targets safer unattended or permission-skipping coding-agent sessions, aligning with broader guidance that native Claude Code controls alone are insufficient and that sandbox boundaries must explicitly protect secrets. The supplied snippets do not include an independent audit or hands-on test of BubbleClaude itself, so its practical isolation, network behavior, resource controls, compatibility, and failure modes remain unverified.
Why it matters to Scott
Scott’s Sandboxed Execution and SiloOS pages already prescribe structural, allowlisted, credential-separated containment for untrusted agents, while the radar’s agent-sandboxing and dirblock/envblock pages already track essentially the same isolation question. BubbleClaude is a relevant implementation candidate, but without independent testing or a demonstrated new control it does not yet extend or challenge Scott’s position.
ip:concept.sandboxed-executionip:framework.siloosip:framework.architecture-not-vibesdev:project.silo-osradar:concept.agent-sandboxingradar:dirblock-envblock-agent-guardsradar:claude-code-denied-read-secret-bypass
queries asked of Scott's wikis
- coding-agent harness sandbox boundaries
- unattended agents secrets isolation
- allowlist versus denylist security
- agent sandboxes fail-closed design
- bubblewrap local agent execution
- coding agents environment and credential exposure
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-08-20T01:23:28Z
The validation window has passed without independent use, adoption, escape findings, or containment results. BubbleClaude remains an unverified instance of a familiar sandboxing pattern, with no concrete follow-up expected.
2026-08-18T00:28:52Z
The refreshed discussion is repetitive and adds no independent BubbleClaude test, adoption, escape, or containment result. The artifact remains an unvalidated implementation of an already familiar isolation pattern.
2026-08-17T21:38:49Z
Discussion now includes a practitioner who moved from a similar bubblewrap setup to a microVM for stronger workload and Docker isolation, but this is comparative testimony rather than an independent BubbleClaude test. Practical containment, especially network exposure and boundary failures, remains unverified.
2026-08-17T20:36:50Z
Discussion identified localhost and link-local network reachability as an important untested escape path, sharpening the validation needed without supplying an independent result. The case remains an author-reported implementation of a familiar isolation pattern.
2026-08-17T15:34:08Z
No independent testing, adoption, or containment finding has arrived; this remains an author-reported implementation of an already familiar isolation pattern.
2026-08-17T15:28:49Z
grounded: known/low — Scott’s Sandboxed Execution and SiloOS pages already prescribe structural, allowlisted, credential-separated containment for untrusted agents, while the radar’s
2026-08-17T15:26:22Z
case created — The usable open-source artifact tests a concrete absent-by-default isolation model distinct from ordinary permission prompts.
Decision trace
- 08-20 11:23expireThe validation window has passed without independent use, adoption, escape findings, or containment results. BubbleClaude remains an unverified instance of a familiar sandboxing pattern, with no concr
- 08-20 11:23alert_silentThe staleness trigger carries no new evidence or consequential delta; reopening attention should wait for an independent test, demonstrated boundary failure, or meaningful adoption.
- 08-20 11:23alert_routeThe staleness trigger carries no new evidence or consequential delta; reopening attention should wait for an independent test, demonstrated boundary failure, or meaningful adoption.
- 08-18 10:28repriceThe refreshed discussion is repetitive and adds no independent BubbleClaude test, adoption, escape, or containment result. The artifact remains an unvalidated implementation of an already familiar iso
- 08-18 10:28alert_silentNo consequential new fact has emerged; comments continue to raise comparison and test criteria without reporting results, so this can wait for independent validation.
- 08-18 10:28alert_routeNo consequential new fact has emerged; comments continue to raise comparison and test criteria without reporting results, so this can wait for independent validation.
- 08-18 10:21sensor_dirtycomment_update
- 08-18 07:38repriceDiscussion now includes a practitioner who moved from a similar bubblewrap setup to a microVM for stronger workload and Docker isolation, but this is comparative testimony rather than an independent B
- 08-18 07:38alert_silentThe refreshed discussion adds implementation preference and possible validation criteria, not a demonstrated escape, containment result, adoption signal, or material capability change; it can wait for
- 08-18 07:38alert_routeThe refreshed discussion adds implementation preference and possible validation criteria, not a demonstrated escape, containment result, adoption signal, or material capability change; it can wait for
- 08-18 07:21sensor_dirtycomment_update
- 08-18 06:36repriceDiscussion identified localhost and link-local network reachability as an important untested escape path, sharpening the validation needed without supplying an independent result. The case remains an
- 08-18 06:36alert_silentThe new comment proposes a pentest criterion but reports no test, vulnerability, or containment finding; it can wait for evidence about network isolation, practical use, or adoption.
- 08-18 06:36alert_routeThe new comment proposes a pentest criterion but reports no test, vulnerability, or containment finding; it can wait for evidence about network isolation, practical use, or adoption.
- 08-18 06:21sensor_dirtycomment_update
- 08-18 01:34repriceNo independent testing, adoption, or containment finding has arrived; this remains an author-reported implementation of an already familiar isolation pattern.
- 08-18 01:34alert_silentThe reobservation is unchanged and adds no consequential delta; wait for an independent test, demonstrated escape or containment result, or meaningful adoption.
- 08-18 01:34alert_routeThe reobservation is unchanged and adds no consequential delta; wait for an independent test, demonstrated escape or containment result, or meaningful adoption.
- 08-18 01:31alert_silentBubbleClaude is a newly released implementation of familiar bubblewrap allowlisting and credential separation, but the available evidence is the author's announcement and self-directed testing. I
- 08-18 01:31alert_routeBubbleClaude is a newly released implementation of familiar bubblewrap allowlisting and credential separation, but the available evidence is the author's announcement and self-directed testing. I
- 08-18 01:28groundScott’s Sandboxed Execution and SiloOS pages already prescribe structural, allowlisted, credential-separated containment for untrusted agents, while the radar’s agent-sandboxing and dirblock/envblock
- 08-18 01:26createThe usable open-source artifact tests a concrete absent-by-default isolation model distinct from ordinary permission prompts.