claude-code-devcontainer
Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.
A sandboxed Docker devcontainer that enables secure execution of Claude Code with bypass permissions turned on. Developed by Trail of Bits for security audit workflows, it isolates Claude's unrestricted command execution within a disposable container instead of your host filesystem. The solution provides filesystem isolation while preserving developer workflow through VS Code/Cursor integration or terminal-based operation. Ideal for reviewing untrusted codebases, conducting security audits, and working with experimental or client code without risking your local environment.
Key Features
Use Cases
- 01Conducting security audits on client code without exposing sensitive host credentials or filesystem
- 02Reviewing untrusted or unknown repositories safely in complete isolation
- 03Letting Claude Code modify experimental codebases freely without risk to production environment
- 04Working on multiple related repositories for client engagements with shared container workspace
- 05Running Claude Code in headless server environments with token-based authentication
- 06Analyzing malicious dependencies or telemetry-enabled software with strict network controls
Related Plugins
View moreandrej-karpathy-skills
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
claude-mem
Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Understand-Anything
Graphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.
rtk
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
claude-code-devcontainer — FAQ
What is claude-code-devcontainer and why would I use it?+
It's a Docker-based development container that lets you run Claude Code with bypassPermissions enabled safely by isolating execution to a disposable container. Running bypass mode on your host is risky because Claude can execute any command without confirmation; this container protects your host filesystem and credentials while maintaining full Claude Code functionality.
What are the prerequisites to use this devcontainer?+
You need a Docker runtime (Docker Desktop, OrbStack, or Colima) running on your machine. For terminal workflows, install the devcontainers CLI globally with npm install -g @devcontainers/cli, then clone and run the self-install script from the repository.
How do I install claude-code-devcontainer for a project?+
Navigate to your project directory and run devc . to install the template and start the container, then devc shell to open a shell inside it. For VS Code/Cursor, install the Dev Containers extension, run devc . in your project, then use the 'Reopen in Container' command.
Is claude-code-devcontainer free to use?+
Yes, the devcontainer itself is open source and free. You still need your own Claude Code subscription and API access to use Claude within the container.
Which AI clients work with this devcontainer?+
This devcontainer is specifically built for Claude Code and integrates with VS Code and Cursor through their Dev Containers extensions. It does not support other AI clients.
How do I enable network isolation for maximum security?+
Run the provided iptables commands inside the container (via devc shell) to create an allowlist of permitted destinations like api.anthropic.com and package registries. The rules use ipsets to allow only specific IPs while dropping all other outbound traffic, though DNS and IPv6 require additional configuration.
How do I install claude-code-devcontainer?+
Open the source repository on GitHub and follow its README. claude-code-devcontainer is a plugin — MCP Agents Market links you directly to the official repo.
Is claude-code-devcontainer free?+
claude-code-devcontainer is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.