Anthropic · Claude Code

Local shell command execution

Claude Code can select and execute shell commands on the user's local computer. Commands run through the local operating-system environment and are mediated by Claude Code permission rules and permission modes, with optional OS-level sandboxing for filesystem and network restrictions. Depending on configuration, commands may require runtime approval or execute under previously granted or automated permissions.

Recorded characteristics

Function
Claude Code (the AI agent) selects shell commands and executes them through its Bash tool (and PowerShell where applicable) on the user's local computer, using the local operating-system/process environment. Anthropic describes Claude Code as a tool that "reads your codebase, edits files, runs commands, and integrates with your development tools." Persistent local change is established: shell commands can modify local files and invoke locally available programs and processes. Immediate outside boundary: Claude Code → local operating-system environment. External/network effects can additionally occur where locally executed commands have network access and appropriate downstream credentials; Anthropic documents, for example, creating pull requests by asking Claude ("create a pr for my changes"). This is not a claim of universal authority over external services: external authority depends on local network availability, locally available tooling, downstream credentials and target-system permissions. Authority distinction: permission controls whether execution is authorised; sandboxing constrains what an executing command or process can reach. Anthropic: "Permissions and sandboxing are complementary security layers." Boundary: this record covers AI-directed local shell command execution only. Excluded: Claude Code cloud sessions; Anthropic-hosted execution VMs; Claude Code routines or scheduled execution; Claude Code computer use; MCP/connectors; deterministic hooks; IDE-only/local-file editing as a separate authority; and unattended or service-account execution. Distinct from GitLab Duo Agent Platform → Software Development Flow (local project-file staging without established terminal-command execution) and from vendor-hosted shell execution recorded for AWS, GitHub, Snowflake and Databricks.
Data access
Whatever the local operating-system account and process environment running Claude Code can reach, constrained by Claude Code permission rules and, where enabled, the sandbox. Anthropic states that the working-directory boundary is a permission prompt for file tools, "so a Bash command you approve can still write anywhere your user account can"; approved unsandboxed Bash commands may therefore exercise authority available to the user's local account, subject to operating-system and downstream controls. When the sandbox is on, "the shell commands Claude runs start inside its boundary, and so do the processes they start," with OS-level filesystem and network restrictions. Not claimed: universal filesystem access, administrator/root authority, successful privilege escalation, universal network authority or universal credential access.
Actions
Can take actions
External actions
Yes
Human confirmation
Conditional
Permission basis
User permissions
Administrative control
Permission rules: allow, ask and deny rules, evaluated deny, then ask, then allow; a bare deny rule for Bash removes the tool from Claude's context. Permission modes: default (Manual; reads only without asking), acceptEdits (file edits and common filesystem commands), plan, auto (a background classifier checks actions such as shell commands before they run), dontAsk (auto-denies every call that would otherwise prompt; pre-approved tools still run) and bypassPermissions (skips permission prompts except for actions no mode auto-approves; Anthropic says to use it only in isolated environments such as containers or VMs). Administrators can block bypassPermissions or auto mode with permissions.disableBypassPermissionsMode or permissions.disableAutoMode, "most useful in managed settings where they can't be overridden"; managed settings can also enforce sandboxing for every developer in an organisation. Sandbox: enabled with /sandbox or sandbox.enabled; auto-allow mode approves sandboxed commands without a prompt, regular permissions mode keeps prompts; excludedCommands and the unsandboxed retry run commands outside the sandbox through the regular permission flow; strict sandbox mode turns off the retry. The optional sandbox is off by default.
Default state
Enabled
Availability
Claude Code is currently available from Anthropic on several surfaces (terminal, IDE extensions, desktop app, web); this record concerns local execution on the user's computer. Default-state qualification: local shell-command capability is available without an administrator first enabling the capability. Whether a particular command requires runtime approval is represented by human_confirmation=conditional, not by the default-state field. Separately, Claude Code's optional sandbox is off by default.
Licensing
Most surfaces require a Claude subscription or Anthropic Console account; the terminal CLI, VS Code and JetBrains also support third-party providers.
External model or provider
Anthropic Claude models; third-party providers supported on some surfaces.
Limitations and uncertainty
Human confirmation recorded as conditional: runtime human approval varies according to command, permission rules, permission mode and sandbox configuration. Commands may execute without contemporaneous human approval where previously authorised ("Yes, and don't ask again" saves Bash approvals "permanently per repository and command"), automatically permitted within configured sandbox boundaries (auto-allow mode), approved through Auto-mode controls (classifier review), or run under bypassPermissions. A built-in set of read-only commands runs without a prompt in every mode. Permission basis recorded as user_permissions for the scoped interactive local capability only: command execution derives from authority available to the person running Claude Code through their local operating-system/process environment; Claude Code permission rules and sandbox controls constrain that authority but do not establish a separate execution identity. This classification is not extended to unattended, service-account, cloud-session or routine execution, which are outside this record. Anthropic notes Bash allow/deny rules match command text and may not hold for the same program run by path or inside sh -c; it recommends pairing them with the sandbox. Failure and recovery, not publicly established: exactly-once shell execution; arbitrary-command rollback; duplicate-side-effect prevention; transactional rollback across multiple commands; reversal of external effects; universal recovery of partially completed actions. Checkpointing is not rollback for shell effects: Anthropic states "Checkpointing does not track files modified by Bash commands" and such changes "cannot be undone through rewind"; external changes are not tracked.

Evidence