I'm currently leaning on Docker for Mac for this, which seems robust enough - but it would be nice if sensible sandboxes were the default, not something you have to actively enable yourself.
Claude Artifacts and ChatGPT Code Interpreter are still the AI-assisted coding tools I use most often, mainly because I know their sandboxes are rock solid.
> Hi everyone - as a previous context I’m an AI Program Manager at J&J and have been using Cursor for personal projects since March.
> Yesterday I was migrating some of my back-end configuration from Express.js to Next.js and Cursor bugged hard after the migration - it tried to delete some old files, didn’t work at the first time and it decided to end up deleting everything on my computer, including itself. I had to use EaseUS to try to recover the data, but didn’t work very well also. Lucky I always have everything on my Google Drive and Github, but it still scared the hell out of me.
> Now I’m allergic to YOLO mode and won’t try it anytime soon again. Does anyone had any issue similar than this or am I the first one to have everything deleted by AI?
Between that and the utter lack of detail, feels like not worthy of HN front page.
Case in point.
"Bash(ceedling:*)",
"Bash(find:*)",
"Bash(grep:*)",
"Bash(ls:*)",
"Bash(rg:*)",
"WebFetch(domain:docs.anthropic.com)",
"Bash(git checkout:*)",
"Bash(gcc:*)",
"Bash(git add:*)",
"Bash(mkdir:*)"
I'm OK for now!It's a bit nerve wracking when it starts YOLO rebasing and force pushing, but it works out in the end.
Also with Claude Code I've never had it go outside the original folder I've started it, even when I've made it do it.
``` Based on the Claude Code documentation, it appears that command restrictions are handled internally by Claude Code's security system. However, I can help you understand how to work with this limitation:
Current Claude Code Security:
- Claude Code already has built-in protections against dangerous commands
- Commands like find / -exec rm would likely be blocked by the existing security measures
- The system sanitizes inputs to prevent command injection
```Seems that they already thought of that.