2026-10-11 17:12 UTC

Independent use will determine whether BubbleClaude’s bubblewrap allowlist, which omits host files, credentials, and environment variables from the sandbox, provides practical isolation for unattended Claude Code sessions.

state: expiredheat: lowuncertainty: highknownscott: lowagentic-security agent-harnesses coding-agentsremileducAnthropic

What is this?

BubbleClaude is a single Bash script attributed here to remileduc that runs Anthropic’s Claude Code inside a Linux bubblewrap namespace, using an allowlist so the host home directory, credentials, and environment variables are absent rather than merely blocked by application-level permissions. The approach targets safer unattended or permission-skipping coding-agent sessions, aligning with broader guidance that native Claude Code controls alone are insufficient and that sandbox boundaries must explicitly protect secrets. The supplied snippets do not include an independent audit or hands-on test of BubbleClaude itself, so its practical isolation, network behavior, resource controls, compatibility, and failure modes remain unverified.

Why it matters to Scott

Scott’s Sandboxed Execution and SiloOS pages already prescribe structural, allowlisted, credential-separated containment for untrusted agents, while the radar’s agent-sandboxing and dirblock/envblock pages already track essentially the same isolation question. BubbleClaude is a relevant implementation candidate, but without independent testing or a demonstrated new control it does not yet extend or challenge Scott’s position.
ip:concept.sandboxed-executionip:framework.siloosip:framework.architecture-not-vibesdev:project.silo-osradar:concept.agent-sandboxingradar:dirblock-envblock-agent-guardsradar:claude-code-denied-read-secret-bypass
queries asked of Scott's wikis
  • coding-agent harness sandbox boundaries
  • unattended agents secrets isolation
  • allowlist versus denylist security
  • agent sandboxes fail-closed design
  • bubblewrap local agent execution
  • coding agents environment and credential exposure

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 redditbubbleclaude: run Claude Code in a sandbox where your home directory, credentials and env vars are absent, not just "denied"
ClaudeAI
xinouch312
🟧 echo.github ⭐Released a single Bash script that runs Claude Code inside a bubblewrap namespace where the real home directory, credentials, and environmenremileduc——

Interpretation history

Decision trace