Local shell command execution
Claude Code can select and execute shell commands on the user's local computer. Commands run through the local operating-system environment and are mediated by Claude Code permission rules and permission modes, with optional OS-level sandboxing for filesystem and network restrictions. Depending on configuration, commands may require runtime approval or execute under previously granted or automated permissions.
Recorded characteristics
- Function
- Claude Code (the AI agent) selects shell commands and executes them through its Bash tool (and PowerShell where applicable) on the user's local computer, using the local operating-system/process environment. Anthropic describes Claude Code as a tool that "reads your codebase, edits files, runs commands, and integrates with your development tools." Persistent local change is established: shell commands can modify local files and invoke locally available programs and processes. Immediate outside boundary: Claude Code → local operating-system environment. External/network effects can additionally occur where locally executed commands have network access and appropriate downstream credentials; Anthropic documents, for example, creating pull requests by asking Claude ("create a pr for my changes"). This is not a claim of universal authority over external services: external authority depends on local network availability, locally available tooling, downstream credentials and target-system permissions. Authority distinction: permission controls whether execution is authorised; sandboxing constrains what an executing command or process can reach. Anthropic: "Permissions and sandboxing are complementary security layers." Boundary: this record covers AI-directed local shell command execution only. Excluded: Claude Code cloud sessions; Anthropic-hosted execution VMs; Claude Code routines or scheduled execution; Claude Code computer use; MCP/connectors; deterministic hooks; IDE-only/local-file editing as a separate authority; and unattended or service-account execution. Distinct from GitLab Duo Agent Platform → Software Development Flow (local project-file staging without established terminal-command execution) and from vendor-hosted shell execution recorded for AWS, GitHub, Snowflake and Databricks.
- Data access
- Whatever the local operating-system account and process environment running Claude Code can reach, constrained by Claude Code permission rules and, where enabled, the sandbox. Anthropic states that the working-directory boundary is a permission prompt for file tools, "so a Bash command you approve can still write anywhere your user account can"; approved unsandboxed Bash commands may therefore exercise authority available to the user's local account, subject to operating-system and downstream controls. When the sandbox is on, "the shell commands Claude runs start inside its boundary, and so do the processes they start," with OS-level filesystem and network restrictions. Not claimed: universal filesystem access, administrator/root authority, successful privilege escalation, universal network authority or universal credential access.
- Actions
- Can take actions
- External actions
- Yes
- Human confirmation
- Conditional
- Permission basis
- User permissions
- Administrative control
- Permission rules: allow, ask and deny rules, evaluated deny, then ask, then allow; a bare deny rule for Bash removes the tool from Claude's context. Permission modes: default (Manual; reads only without asking), acceptEdits (file edits and common filesystem commands), plan, auto (a background classifier checks actions such as shell commands before they run), dontAsk (auto-denies every call that would otherwise prompt; pre-approved tools still run) and bypassPermissions (skips permission prompts except for actions no mode auto-approves; Anthropic says to use it only in isolated environments such as containers or VMs). Administrators can block bypassPermissions or auto mode with permissions.disableBypassPermissionsMode or permissions.disableAutoMode, "most useful in managed settings where they can't be overridden"; managed settings can also enforce sandboxing for every developer in an organisation. Sandbox: enabled with /sandbox or sandbox.enabled; auto-allow mode approves sandboxed commands without a prompt, regular permissions mode keeps prompts; excludedCommands and the unsandboxed retry run commands outside the sandbox through the regular permission flow; strict sandbox mode turns off the retry. The optional sandbox is off by default.
- Default state
- Enabled
- Availability
- Claude Code is currently available from Anthropic on several surfaces (terminal, IDE extensions, desktop app, web); this record concerns local execution on the user's computer. Default-state qualification: local shell-command capability is available without an administrator first enabling the capability. Whether a particular command requires runtime approval is represented by human_confirmation=conditional, not by the default-state field. Separately, Claude Code's optional sandbox is off by default.
- Licensing
- Most surfaces require a Claude subscription or Anthropic Console account; the terminal CLI, VS Code and JetBrains also support third-party providers.
- External model or provider
- Anthropic Claude models; third-party providers supported on some surfaces.
- Limitations and uncertainty
- Human confirmation recorded as conditional: runtime human approval varies according to command, permission rules, permission mode and sandbox configuration. Commands may execute without contemporaneous human approval where previously authorised ("Yes, and don't ask again" saves Bash approvals "permanently per repository and command"), automatically permitted within configured sandbox boundaries (auto-allow mode), approved through Auto-mode controls (classifier review), or run under bypassPermissions. A built-in set of read-only commands runs without a prompt in every mode. Permission basis recorded as user_permissions for the scoped interactive local capability only: command execution derives from authority available to the person running Claude Code through their local operating-system/process environment; Claude Code permission rules and sandbox controls constrain that authority but do not establish a separate execution identity. This classification is not extended to unattended, service-account, cloud-session or routine execution, which are outside this record. Anthropic notes Bash allow/deny rules match command text and may not hold for the same program run by path or inside sh -c; it recommends pairing them with the sandbox. Failure and recovery, not publicly established: exactly-once shell execution; arbitrary-command rollback; duplicate-side-effect prevention; transactional rollback across multiple commands; reversal of external effects; universal recovery of partially completed actions. Checkpointing is not rollback for shell effects: Anthropic states "Checkpointing does not track files modified by Bash commands" and such changes "cannot be undone through rewind"; external changes are not tracked.
Evidence
- Configure permissions - Claude Code Docs
Supports: Actions · Human confirmation · Permission basis · Admin controls · Limitations · Primary source
Bash commands (shell execution) require approval except a built-in set of read-only commands; "Yes, and don't ask again" saves permanently per repository and command.
Allow rules run without manual approval; ask rules prompt; deny rules block; evaluated deny, then ask, then allow. Modes: auto (classifier), dontAsk (auto-denies prompts), bypassPermissions (skips prompts).
Permissions control which tools Claude Code can use; sandboxing provides OS-level enforcement restricting shell commands' filesystem and network access; complementary layers.
permissions.disableBypassPermissionsMode and permissions.disableAutoMode; most useful in managed settings where they can't be overridden.
Bash rules match command text; the same program by path or inside sh -c may not match; pair with the sandbox network allowlist.
- Configure the sandboxed Bash tool - Claude Code Docs
Supports: Default state · Human confirmation · Data access · Admin controls · Primary source
"The sandbox is off by default." Enabled via /sandbox or sandbox.enabled.
Auto-allow mode approves sandboxed commands with no prompt; commands outside the sandbox (excludedCommands, unsandboxed retry) go through the regular permission flow.
While the sandbox is on, shell commands and the processes they start run inside its filesystem and network boundary.
Managed settings can enforce sandboxing for every developer in an organisation; strict sandbox mode turns off the unsandboxed retry.
- Choose a permission mode - Claude Code Docs
Supports: Human confirmation · Admin controls · Primary source
default (Manual) runs reads only without asking; acceptEdits adds file edits and common filesystem commands; auto uses a classifier before shell commands and network requests.
Permission modes trade convenience against oversight; mode can be set per session or as default.
- Security - Claude Code Docs
Supports: Data access · Permission basis · Primary source
The working-directory boundary is a permission prompt, so a Bash command you approve can still write anywhere your user account can; turn on sandboxing to restrict Bash at OS level.
"You and your organization configure these permissions directly"; sandboxed bash tool defines boundaries where Claude Code can work autonomously.
- Checkpointing - Claude Code Docs
Supports: Limitations · Primary source
Checkpointing does not track files modified by Bash commands; those changes cannot be undone through rewind; external changes not tracked.
- Overview - Claude Code Docs
Supports: Function · Availability · Licensing · Primary source
Claude Code reads your codebase, edits files, runs commands and integrates with development tools; available in terminal, IDE, desktop app and browser.
Runs on terminal, IDE extensions, desktop app and web.
Most surfaces require a Claude subscription or Anthropic Console account; terminal CLI, VS Code and JetBrains support third-party providers.
- Common workflows - Claude Code Docs
Supports: External actions · Primary source
Users can create pull requests by asking Claude directly ("create a pr for my changes").