DEV Community

Cover image for I run Claude Code with permission prompts off, so I put it in a VM
Karim Masmoudi
Karim Masmoudi

Posted on

I run Claude Code with permission prompts off, so I put it in a VM

I use Claude Code every day, and I run it with permission prompts off. It's much faster that way. You give it a task, go do something else, and come back to a finished change.

The downside is finding out afterwards what else it did. Git can bring back tracked files, but not untracked or ignored ones, and not anything outside the repo.

Most agent sandboxes I tried mount the project folder into a container or VM read-write. That stops the agent from touching the rest of my Mac, but its changes still land in my real files as it works. By the time I look, they're already there.

So I built Mudroom, a free and open source Mac app and CLI that keeps the agent off the real folder completely.

Mudroom demo

How it works

  1. Mudroom makes an APFS copy-on-write clone of the whole project folder, untracked and ignored files included. The clone takes no extra disk until files change.
  2. It boots a Linux micro-VM with Apple's container tool and mounts only the clone. Your real folder is never mounted.
  3. Claude Code, Codex, Gemini CLI, opencode, Aider or any command runs inside, in a normal Terminal window, so you can still talk to the agent.
  4. When the agent exits, you get a diff that looks like a pull request: added, modified, deleted and permission changes, file by file. Modified files have a checkbox per hunk.
  5. You apply everything, some files, or single hunks. Every apply can be undone. If you edited a file yourself while the agent was running, it's flagged and never overwritten.

The same thing from the command line:

mudroom run ~/code/myapp -- claude --dangerously-skip-permissions
mudroom diff last
mudroom apply last --all
mudroom undo last
Enter fullscreen mode Exit fullscreen mode

The network part

By default the VM sits on a host-only network with no DNS and no route out. The only way out is a logging proxy that lets through the agent's own API hosts (for Claude Code that's api.anthropic.com and a few sign-in hosts) plus anything you add.

The review screen has a Network tab that lists every host the VM tried to reach, blocked ones first. If something legitimate got blocked, one click adds it to the project's allowlist for the next run. mudroom network check tries to get around the proxy from inside the VM and prints what it could and couldn't reach.

Signing in once

mudroom agent login claude (or "Use my Claude account" in the app) runs claude setup-token and stores the token in the macOS Keychain, so later sessions start signed in. Your real ~/.claude is never mounted. ANTHROPIC_API_KEY works too.

What it doesn't do yet

I'd rather list these up front:

  • The app and the VM need macOS 26 or later on Apple silicon. Linux and Intel Macs get a CLI-only build on Docker or Podman, which is a container, not a VM.
  • The VM can reach services on your Mac that listen on 0.0.0.0. The network check reports it. I don't have a fix yet.
  • While a session runs, Apple's container runtime keeps the session environment, tokens included, in a config file that any process running as you can read.
  • The allowlist works on host names. There's no TLS inspection.
  • The app isn't notarized. The install script and Homebrew cask clear the quarantine flag.
  • Lockfiles and generated files make noisy diffs. It's early.

If your project is a git repo and you're happy reviewing with git, Docker Sandboxes' clone mode gets you close. Mudroom also covers untracked and ignored files, folders that aren't repos, and gives you a review screen and an undo for each apply.

Try it

brew install --cask kernel-hunter/tap/mudroom
Enter fullscreen mode Exit fullscreen mode

or the one-line install script in the README. There's also a 33-second overview video with sound.

It's MIT licensed and free. I'd like to hear from people who run agents unattended:

  • Is the end of the run the right time to review, or would you want checkpoints in the middle?
  • How should generated files and lockfiles show up in the diff?
  • Which agents or setups should I test next?

GitHub logo Kernel-Hunter / mudroom

Run coding agents in a Linux VM on a clone of your project, then review and apply their changes like a pull request

Mudroom

Run coding agents in a sandbox, then review their changes like a pull request before anything touches your project.

Coding agents work best with permission prompts turned off, and that means they can delete files or reach any host while you aren't looking. Mudroom runs Claude Code, Codex, Gemini CLI, opencode, Aider (or any command) in a Linux micro-VM, on a copy-on-write clone of your project, with network access limited to the hosts you allow. Your real folder is never mounted. When the agent is done you read the diff, apply all of it, some files, some hunks or none, and undo any apply later.

macOS app and CLI on Apple-silicon Macs. CLI only (with Docker or Podman) on Linux and Intel Macs.

Status: early prototype. Expect rough edges and breaking changes.

Mudroom: start a session, review the diff, check the network log, apply

Watch the 33-second overview (with sound)

Quick start

  1. Install (Apple-silicon Mac, macOS 26 or later):

    curl -fsSL
    …
    Enter fullscreen mode Exit fullscreen mode

Top comments (1)

Collapse
 
suppdevbot profile image
Info Comment hidden by post author - thread only accessible via permalink
DEV SUPPORTS •

You need to verify your account.

Enter fullscreen mode Exit fullscreen mode

tr.ee/dev-to

Some comments have been hidden by the post's author - find out more