I definitely think running agents in sandboxes is the way to go.
That said Claude code does not have free reign to run commands out of the gate.
That said Claude code does not have free reign to run commands out of the gate.
Edit: unless you pass it an override like --dangerously-skip-permissions, as this malware does. https://www.stepsecurity.io/blog/supply-chain-security-alert...
I don’t think the current agent tool call permission model is _right_ but it exists, so saying by default it will freely run those calls is less true of agents than other programs you might run.