I run Claude Code with permission prompts off, so I put it in a VM
I use Claude Code every day, and I run it with permission prompts off. It's much faster that way. You give it a task, go do something else, and come back to a finished change. The downside is finding out afterwards what else it did. Git can bring back tracked files, but not untracked or ignored ones, and not anything outside the repo. Most agent sandboxes I tried mount the project folder into a…
Claude Code is a coding assistant that the author uses every day, but with permission prompts disabled to improve performance. The author created Mudroom, a free Mac app and CLI, to run Claude Code in a Linux micro-VM within a copy-on-write clone of the project folder, preventing the agent from making unwanted changes to the real project files.
Mudroom mounts the clone read-write, leaving the original folder untouched. Modified files can be reviewed as a pull request, with added, modified, deleted, and permission changes displayed file by file. The author can apply changes, select individual hunks, or undo the entire apply. Mudroom also checks the VM's network activity, allowing users to whitelist hosts for future runs.
Mudroom is currently in an early prototype stage, requiring macOS 26 or later on Apple silicon, and offers both a graphical interface and command-line options for running coding agents.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.