<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Sandboxing | AI Engineering</title><link>https://ai.devops-monk.com/tags/sandboxing/</link><description>A 23-chapter handbook for Claude Code — permissions, context, skills, hooks, MCP and agents, worked out end to end for engineers who have to ship with it.</description><language>en-us</language><managingEditor>abhaypratap3537@gmail.com (Abhay)</managingEditor><webMaster>abhaypratap3537@gmail.com (Abhay)</webMaster><lastBuildDate>Sun, 06 Sep 2026 01:57:53 +0000</lastBuildDate><atom:link href="https://ai.devops-monk.com/tags/sandboxing/index.xml" rel="self" type="application/rss+xml"/><item><title>Permissions &amp; Sandboxing</title><link>https://ai.devops-monk.com/2026/09/permissions-and-sandboxing/</link><pubDate>Sat, 05 Sep 2026 13:00:00 +0000</pubDate><guid isPermaLink="true">https://ai.devops-monk.com/2026/09/permissions-and-sandboxing/</guid><author>abhaypratap3537@gmail.com (Abhay)</author><category>Fundamentals</category><description>Rules decide whether a tool call happens; the sandbox decides what it can touch once it does. Rule syntax and the wildcard placement that widens a rule further than intended, path anchoring, working directories, and where the OS boundary goes.</description><enclosure url="https://ai.devops-monk.com/images/articles/cc-04-permissions-sandboxing.webp" type="image/webp" length="0"/><content:encoded><![CDATA[<p><img src="https://ai.devops-monk.com/images/articles/cc-04-permissions-sandboxing.webp" alt="Permissions & Sandboxing" /></p><p>Rules decide whether a tool call happens; the sandbox decides what it can touch once it does. Rule syntax and the wildcard placement that widens a rule further than intended, path anchoring, working directories, and where the OS boundary goes.</p><p><a href="https://ai.devops-monk.com/2026/09/permissions-and-sandboxing/">Read the full article &rarr;</a></p>]]></content:encoded></item></channel></rss>