Sandbox
bash commands run in the operating system's sandbox: Seatbelt (sandbox-exec) on macOS, and bubblewrap (bwrap) on Linux when installed.
On Windows, install Bash (for example, Git Bash) to use the bash tool. Larik has no Windows sandbox, so shell commands ask for approval.
Inside the sandbox, a command:
- Can read everything.
- Can write only to the project (the git root), its own private temp directory, and common build caches (Go, npm, Cargo,
~/.cache, on macOS also~/Library/Cachesand the per-user temp root). The literal/tmp, shared by every program on the machine, is never writable. - Can't write to
.git/hooks,.git/config, the other git files that point git at a config or hooks elsewhere (commondir,config.worktree,info/,modules/,worktrees/),.larik/,.claude/or.mcp.json, even inside the project, and can't move or replace.gititself, because any of these would let a later command or hook escape the sandbox. Commits still work. - Has no network access except localhost, so tests that start local servers still work.
- Can't reach other apps on macOS: LaunchServices and Apple Events are blocked, so
openandosascriptcan't be used to escape.
How it changes permissions:
- In
defaultandaccept-editsmode, sandboxed commands run without asking. - If a command needs more (installing packages, network access, writing elsewhere), the model re-runs it with
"sandbox": false. That asks you first, and the prompt says it runs outside the sandbox. - Deny rules still apply, and plan mode still blocks
bash. - Without a sandbox (for example on Linux without
bwrap), every command asks as before, and Larik says so at startup.
{ "sandbox": { "network": true, "writable": ["~/datasets"] } } // personal config only
{ "sandbox": { "enabled": false } } // turn it off
Loosening the sandbox (enabling network, adding writable paths, disabling it) is honored only from personal files: ~/.config/larik/config.json and private project settings under ~/.config/larik/projects/. A shared .larik/settings.json can only switch the sandbox on. /sandbox shows the current settings.