upvote
It seems unwise not to implement sandbox measures just because the chance of misuse has gotten lower.
reply
Plan was never a sandbox or a permissions system
reply
Plan mode does have different permission controls though? Its difficult for me to parse the docs on this but it does seem to imply more than just a prompt although less than a full sandbox. https://code.claude.com/docs/en/permission-modes#analyze-bef...
reply
The way it worked originally was it would trigger a different system prompt, and then the permissions system would prompt you (even on YOLO mode) before running any non-readonly actions.

Cursor would also write a plan document, which was useful when working on larger tasks (due to context size). I still find that part useful today.

reply
early plan mode would just refuse to make edits at all
reply
Plan forced the model to write down and outline what it was going to do before writing the code. As Boris said up thread, he created it to prevent it from just rushing into writing code. So that regard, it did act like a permission system.

It helps to think more abstractly when approaching problems like this.

reply
Yes, but plan mode wasn’t that.

You can use Docker’s sbx or similar VM/containers for that.

reply
What? Nothing to do with that
reply
It also doesn't allow leaving an audit trail of plans and decisions (by default, anyway). Most of my mutating prompts look like "Propose a plan for change X and write to file Y" and "Execute steps M-N from file Y".

RE the article: I don't think it's obvious why this process is worth following until you find your time and attention wasted. Conversationally-building is the express train to waste. I'm not sure why you would even be talking to claude if you don't understand what you want to build.

reply
Do you really trust it with a production code base or database? Telling it not to make changes feels an awful lot like "Make no mistakes". I also like how Plan mode on Codex asks clarifying questions. I'm in management now so I've used Work more than Code lately.
reply
I agree. Plan mode came about because earlier models were loose cannons, doing what they pleased. Today's models follow instructions better enough to not need a separate mode. However, there is still value in using a separate, smarter model for planning than execution, and persisting it for auditing on completion.

If you do use plan mode you might like https://plannotator.ai/

I typically converse with the default model to point the plan in the right direction, then have it iterate with a smarter reviewer to find flaws until the plan file is converged.

reply
true dat
reply