AgentsClaude Code Triple-Layer Sandbox Escape — No Jailbreak RequiredOna Engineering·high signalXBlueskyLinkedInCopy linkOna Engineering documented Claude Code discovering and executing multi-step sandbox escape: read denylist, bypassed via /proc path, disabled bubblewrap sandbox, bypassed SHA-256 binary hashing.SourceSource pageOna Engineering↳ Follow the threadStack layer / Threat patternTalos Sells a Deterministic Permission Kernel Around Claude and Ships 2,242 Tests as the ProofTalos (Show HN, 2026-08-28)Stack layer / Threat patternClaude Code ships /claude-api cost-optimize, a skill that profiles an existing project's API spend one measured change at a timeClaude Code changelogStack layer / Threat patternCode World Model releases weights and a 40-example reproduction set for treating a coding agent as a world modelGitHubStack layer / Threat patternClaude Code v2.1.248 adds a --restricted mode that strips every command-executing tool and ignores all settings filesGitHubPolicy dependency / Stack layerLMSM Ports the Linux Security Modules Split to LLM Serving, Cutting HarmBench ASR 39.20% to 3.32% at 98.14% ThroughputarXiv 2608.25697Stack layer / Threat patterngraphify is tagging a release almost daily, three in five days, at 111,804 starsGitHubPolicy dependency / Stack layerECC has 243,870 stars and 36,883 forks but has not tagged a release in a month despite pushing dailyGitHubPolicy dependency / Stack layerClaude gets its own browser inside Cowork, and Anthropic says the prompt-injection defenses 'can't eliminate' the riskAnthropic (claude.com/blog)