CC_SAFETY_NET_* prefix, and older SAFETY_NET_* names (without the CC_ prefix) are still accepted as legacy aliases where noted. Set them in your shell, your agent’s launch environment, or your .env file before starting your agent.
Protection modes
Setting
CC_SAFETY_NET_PARANOID=1 implies both CC_SAFETY_NET_PARANOID_RM=1 and CC_SAFETY_NET_PARANOID_INTERPRETERS=1.
Values are truthy when set to 1 or true (case-insensitive). See Modes for what each toggle changes and when to use it.
Debug output
Use
CC_SAFETY_NET_DEBUG=1 when investigating why a command was allowed or when filing a bug report. The doctor command reports whether it is set.
Config directory override
This is useful in sandboxed or non-standard
HOME setups (for example, when an agent runs with a different home directory than your shell). When unset, CC Safety Net uses ~/.cc-safety-net.
Checking your active configuration
Run the doctor command to see which variables are currently set and how they resolve:SAFETY_NET_* names that are in use. The Claude Code status line also reflects the active modes at a glance.