claude-code

--restricted

Upstream:Not specifiedEvidence:documentedEvidence:empiricalIntroduced:2.1.248

The vendor applied no maturity label

“Not specified” is what the source says — it is not a stability claim, and it is deliberately not rendered as “Stable”. An absent label is an absence, and this page reports it as one.

Also spelled

CLAUDE_CODE_RESTRICTED=1

Evidence

Each level is a separate observation with its own source, kept apart rather than merged into one confident claim.

documentedThe official documentation describes this.

the flag exists and the vendor describes its effect

Added `--restricted` (or `CLAUDE_CODE_RESTRICTED=1`): removes the built-in tools that run commands or code and `WebFetch` (unless named in `--tools`), keeps file tools inside the working directory, refuses `bypassPermissions`, and ignores user, project and local settings files
Retrieved:
2026-08-28T00:00:00Z
Committed fixture:
evals/fixtures/capability-catalog/claude-CHANGELOG-2026-08-28.md sha256 7352270dab1822f7
empiricalSessionFleet observed this directly.

the flag is present in the running binary's own help output at this version

Restricted mode: removes the built-in tools that run commands or code (Bash, PowerShell, REPL and the other code-running tools) and WebFetch unless --tools names them, and ignores user, project and local settings files (managed settings and --settings still apply; add --strict-mcp-config to skip MCP servers too). Also confines the file tools to the working directories (--add-dir included), refuses bypassPermissions, and lets only a person or the configured permission handler approve writes to settings, git and tool-configuration files.
Source:
claude --help (observed on 2.1.248)
Retrieved:
2026-08-28T00:00:00Z
Committed fixture:
evals/fixtures/capability-catalog/claude-2.1.248--help.txt sha256 0b78452503a81f1c

Security surface — the vendor's words, not our finding

security impact is a human judgement (plan §5) — this record carries the vendor's words and no verdict

Restricted mode: removes the built-in tools that run commands or code (Bash, PowerShell, REPL and the other code-running tools) and WebFetch unless --tools names them, and ignores user, project and local settings files (managed settings and --settings still apply; add --strict-mcp-config to skip MCP servers too). Also confines the file tools to the working directories (--add-dir included), refuses bypassPermissions, and lets only a person or the configured permission handler approve writes to settings, git and tool-configuration files.

SessionFleet recommendation

None yet — this primitive has not been reviewed by SessionFleet.