The Boundary You Assumed You Had — Measure What Each Claude Code Sandbox Actually Contains
🤝 Want this built for you? Start a request — our AI scopes it, estimates a price range, and matches you with a vetted AI Advisor. →
🔒 Ambassador-exclusive build
Two ways to open it
Unlocks this full walkthrough on your account — no subscription, and no account needed until you check out. Advisor-grade build.
Every Ambassador-exclusive build, first access to new ones, and your spot on the advisor-only needs board. Or $300/year.
Become an Advisor to unlock →Already an Advisor? Sign in to open it.
What you'll do
A reusable, inert reachability probe plus a recorded blast-radius ledger that shows, boundary by boundary on your own machine, exactly which synthetic canary paths were readable and writable, which network destinations were reachable, and whether the SSH agent and host process table were visible — measured on the bare host, inside the built-in Bash sandbox, from a hook in that same session, through a whole-process sandbox runtime, inside a custom container in both its offline and mounted-and-networked profiles, and inside a shareable dev container built from Anthropic's published feature — together with a written routing policy that assigns each class of work to a boundary you have actually measured, one-word launchers that make the policy the easy path, a re-measurement check that exits non-zero when a boundary becomes weaker than the recorded ledger, and a completed drill in which you deliberately widened one boundary, watched the check catch it, and closed it.