Comment by ricardobeat

3 hours ago

The harness runs itself in a sandbox, Codex does the same. Then it can request approval for individual tool calls to be made outside that sandbox, depending on your permission mode. At least this is the case in MacOS.

I see what you mean now though - you can change the default permission mode with /config in CC, but it will indeed not make that change on your behalf.

The sandbox seems to be disabled by default. Even then, I just asked it to run a read write ftp server that serves ~ (thus obviously can edit ~/.claude) and it went ahead no problem. So obviously there's nothing actually stopping anyone from editing .claude/settings.json. It's just an awful refusal. From a company that thinks they know better than you.