security
May 28, 2026
By Teun
Claude adds self-hosted sandbox and built-in code review
Anthropic has added two security features to Claude: a self-hosted sandbox for Managed Agents and a security-guidance plugin that reviews code for common flaws during work. The company said the plugin runs automatically, while Red Hat described the sandbox as keeping execution on customer infrastructure.
Anthropic has introduced two security-focused additions to Claude: a self-hosted sandbox for Claude Managed Agents and a security-guidance plugin that reviews code changes for common vulnerabilities while the model is working. The company said the plugin is designed to catch issues before code reaches a pull request.
According to Anthropic, the security-guidance plugin checks for problems such as injection flaws, unsafe deserialization, and unsafe DOM APIs. The review happens in the same session as the coding work, and the company said there is nothing to invoke manually and no separate command to remember.
⚡ New to this?
This matters because AI coding tools can introduce security bugs if they generate risky code or run in places companies do not control. A self-hosted sandbox keeps an agent’s execution inside the customer’s own infrastructure, and a pull request is the place where code changes are proposed for review before merging. In plain terms, Anthropic is trying to catch some problems earlier and keep more of the work on systems the customer owns.
🦞 OpenClaw angle
If you run self-hosted agents, put the agent’s execution environment behind your own logging, network rules, and secret controls instead of letting it run in a shared cloud context. Add the same checks Anthropic is aiming at here to your pipeline: scan agent output for injection, unsafe deserialization, and DOM misuse before anything reaches review. If your automation can create code or config changes, require a human approval step before merge and before deployment, even when the agent says the change is safe.
The second feature is a self-hosted sandbox for Claude Managed Agents. Red Hat described the setup as outsourcing the “thinking” while keeping the “doing” on the user’s own infrastructure, which matters for teams that want the agent to reason about tasks without sending execution outside their environment.
Anthropic said the changes are meant to reduce the amount of security review left to human reviewers downstream. That does not remove the need for review entirely, but it does shift some checks earlier in the development process.
The company also framed the release in terms of its own security requirements. Anthropic said core security code in its systems has to be treated carefully because a serious bug could affect a large number of apps and features that depend on it, so it applies conservative testing practices when adding new code.
The announcement comes as AI coding tools are being pushed deeper into software workflows, where small mistakes can become serious deployment risks. In that context, built-in code review and customer-hosted execution are aimed at reducing exposure without forcing teams to bolt on separate security steps later.
Anthropic’s new features are also likely to appeal to organizations that already limit where code can run and who can see it. A self-hosted sandbox gives those teams a way to keep agent actions inside their own environment while still using Claude for code-related work.
For now, Anthropic is positioning the plugin and sandbox as practical security controls rather than headline features. The company said the plugin runs automatically, and the sandbox is meant for Managed Agents that need to work on infrastructure controlled by the customer.