Fetching from the wire…
Security2026-08-06 · source-backed
Seatbelt on macOS, Bubblewrap namespaces on Linux, WSL on Windows. Enforced boundaries: no writes outside the project directory, no modification of .git, no network without explicit permission. Zed's stated reasoning is that prompt injection overrides instructions, so restriction has to be enforced by the kernel. First mainstream editor to make agent sandboxing a default rather than a setting, and the "on by default" part is what makes it matter. Opt-in security is security that 4% of users have.
Each link below shares sources, entities, or timing with this story.
Claude Code uses Seatbelt / Shared entities / Earlier coverage
Linked by a graph relationship (Claude Code uses Seatbelt); both cover Linux, Windows, WSL; earlier Linux coverage from 2026-08-04.
Linked by a graph relationship (Claude Code uses Seatbelt); both cover Bubblewrap, Linux, Seatbelt; earlier Bubblewrap coverage from 2026-07-21.
Claude Code uses Seatbelt / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code uses Seatbelt); both cover Linux, Windows; overlapping topics (agent, editor).
Claude Code uses Seatbelt / Shared entities / Earlier coverage
Linked by a graph relationship (Claude Code uses Seatbelt); both cover Linux, Windows; earlier Linux coverage from 2026-07-30.
Linked by a graph relationship (Claude Code uses Seatbelt); both cover Linux, Windows; earlier Linux coverage from 2026-07-27.
Linked by a graph relationship (Claude Code uses Seatbelt); both cover Linux, Windows; earlier Linux coverage from 2026-07-21.
Linked by a graph relationship (Claude Code uses Seatbelt); both cover Linux, Seatbelt; earlier Linux coverage from 2026-07-16.
Claude Code uses Seatbelt / Shared entity: Linux / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code uses Seatbelt); both cover Linux; overlapping topics (agent, directory).