Five minutes from install to first sandboxed AI run.
The recommended way is mise:
mise use -g github:zekker6/devsandboxmise is optional. Without it, download a release binary instead. Installation covers both, plus the platform requirements.
# cd into your project - this directory becomes the sandbox root
cd ~/projects/my-app
# Run Claude Code inside the sandbox
devsandbox claude --dangerously-skip-permissionsdevsandbox wraps any command. Everything after the binary name is passed through to the sandboxed program. The flag --dangerously-skip-permissions is a Claude Code flag that disables its permission prompts - safe to enable here because devsandbox provides the actual security boundary.
devsandbox --infoThis prints the sandbox configuration: which directories are mounted read-only, which are blocked, what network mode is active.
Typing devsandbox first is easy to forget. Shell wrappers make claude run as devsandbox claude in every new shell. They cover claude, pi, codex, opencode and copilot, whichever are installed. Add the line for your shell to its startup file:
# fish: ~/.config/fish/config.fish
if test -z "$DEVSANDBOX"; devsandbox shell-wrappers activate fish | source; end
# bash: ~/.bashrc
if [ -z "${DEVSANDBOX:-}" ]; then eval "$(devsandbox shell-wrappers activate bash)"; fi
# zsh: ~/.zshrc
if [ -z "${DEVSANDBOX:-}" ]; then eval "$(devsandbox shell-wrappers activate zsh)"; fiOpen a new shell, cd into a project and run claude as usual. claude-no-ds or command claude runs the real binary unsandboxed. --agents claude,codex wraps only the agents you name, and [shell_wrappers] in the config wraps other commands such as npm. See Shell wrappers.
~/projects/my-app(your CWD) became the project root with full read/write access.~/.ssh,~/.aws,~/.azure,~/.gcloud→ not mounted, invisible..envand.env.*files → masked with/dev/null, scanned up to 3 directory levels below the project root (node_modules,.git,vendor,.venvare skipped)..git/→ mounted read-only (no commits, no credentials).- mise-managed tools, your shell config, editor setup → mounted read-only so they work inside.
- Network → full access by default; add
--proxyto log HTTP requests (enforcement strength varies by backend - see per-backend behavior).
devsandbox wraps anything with a CLI:
devsandbox aider
devsandbox cursor
devsandbox npm install
devsandbox go test ./...Continue to First run for a guided walkthrough that shows what the sandbox actually does.