正在加载视频...
视频加载失败
Jev + Vercel Sandbox Mod in Claude Code This Mod spins up a sandbox on Vercel, while Jev classifies which commands should run inside the sandbox and which ones should run locally Install: npx claude-code-templates@latest --mod security/jev-vercel-sandbox Link: Mods are a great way to customize your Claude Code workflows... show more
16,889 次观看 • 5 天前 •via X (Twitter)
10 条评论

Full shell access on day one is how agents wipe folders.

Jev classifying sandbox vs local.

Splitting what runs in a sandbox versus locally based on command risk is a nice pattern. Saves you from sandboxing everything just to be safe.

claude code getting a whole sandbox mod is kinda sick

Keeping the bulk edits in a separate patch is useful when you've already got uncommitted work. Way easier to tell what the agent actually changed

A Jev sandbox mod on day one. The ecosystem is not waiting around.

dynamic command routing between local and sandbox is the cleanest security pattern: isolating only risky commands preserves local speed. in our pipeline targeting brazil, classifiers route untrusted fetches to sandboxes while ffmpeg and piper run on bare metal for $0. fast & safe

read the page. a default i'd flip: with confirmSandbox on, a claude -p run has nobody to answer, so even untrusted_code (curl | sh) falls through to local. headless runs are where nobody reads the command, so that case should go to the sandbox

Oh that’s sick

This is a clever way to use Jev for security. We actually went deeper on the Cloudflare Clef models that are also pushing the boundaries of decision models here:

