Run Claude Code in a disposable Docker container with no permission prompts — and full access to your host session history.
Tell Claude:
Read https://raw.githubusercontent.com/STRML/cc-yolo/main/yolo.md and install yolo on my machine.
yolo # new session in current directory
yolo --resume <uuid> # resume a previous session
yolo-incognito # disposable container, no host state mounted
yolo-pull # rebuild image with latest claude-codeThe container is hardened against the npm/pypi supply-chain threat (malicious postinstall scripts running with your credentials and exfiltrating to attacker infrastructure):
- Egress allowlist —
init-firewall.shruns at container start and restricts outbound traffic via iptables/ipset to npm, pypi, GitHub, Anthropic API, and a handful of essentials. Everything else is REJECTed. Bypass withYOLO_NO_FIREWALL=1for debugging; extend withYOLO_EXTRA_DOMAINS="...". - Capability dropping —
--cap-drop=ALLthen--cap-add=NET_ADMIN --cap-add=NET_RAWfor the firewall init only. Caps become inert once gosu drops to thenodeuser. - No privilege escalation —
--security-opt=no-new-privilegesblocks setuid binaries from gaining extra perms. - Process limit —
--pids-limit 512caps fork-bomb / runaway behavior. - Read-only secret mounts —
~/.ssh,~/.gitconfig,~/.config/ghmounted:roso a compromised container can't tamper with them.
What this doesn't protect against:
- Secrets at rest are still readable. Read-only mounts stop tampering, not reading. A malicious script can still read
~/.ssh/id_ed25519; the firewall is what prevents exfiltration. Passphrase-protect your SSH keys; use scoped fine-grained PATs in~/.config/gh; consider a separate Anthropic API key with a low spend cap for yolo sessions. - Workspace tampering. Your project mount is read-write — by design, since Claude needs to edit code — but malware can plant backdoors there. Review diffs before pushing.
- SSH agent forwarding is on by default when an agent socket is detected. While forwarded, anything in the container can authenticate as you to any host your key reaches. If that worries you, prefer HTTPS via
ghand unsetSSH_AUTH_SOCKbefore running yolo.
Recommended extras (not done automatically since they affect every project):
npm config set ignore-scripts trueon your host, opted-in per-package when needed — closes the most common postinstall vector before yolo even matters.- Use 1Password /
op-clifor cloud creds instead of plaintext~/.aws/credentialsso they aren't readable from any sandbox.
Claude Code stores conversation history as <uuid>.jsonl under ~/.claude/projects/<slugified-path>/. The slug is derived from the absolute path of the working directory.
yolo mounts your project at its real host path (e.g. /Users/you/code/myproject) rather than /workspace, so the slug inside the container is identical to the one written on your host. This means --resume <uuid> finds sessions from both environments.