Claude Code and Codex both run untrusted commands. This post compares how their sandboxes protect your repo, secrets, and host machine.