Most AI coding agent tutorials assume a developer environment already cluttered with years of accumulated dependencies. A recent experiment on DEV.to stripped away that convenience, deploying Anthropic's Claude Code onto a pristine Windows Sandbox instance to simulate a true first-time user experience. The result was not a smooth onboarding but a gauntlet of five distinct failures that occurred before a single line of production code was written. This test highlights the gap between vendor documentation and the reality of bare-metal Windows installations.

The PATH and Trust Prompt Traps

The first hurdle was a classic Windows installation failure. The official installer completed successfully but failed to add the binary location to the system PATH, rendering the claude command unrecognized. This required a manual PowerShell edit to append .local\bin to the user environment variables. Once inside, the agent presented a folder trust prompt that defaults to "No, exit." A user pressing Enter without reading the prompt immediately quits the session, a UX decision that mimics a crash but is merely a default selection.

Auto Mode and Sandboxing Limitations

Perhaps the most dangerous discovery was the default permission mode. Fresh installs of Claude Code on Windows launch in "auto mode," granting the agent permission to write files without explicit user confirmation. In the test, the agent created a file immediately upon instruction. To revert this to a safer, interactive state, users must manually create a .claude/settings.json file and set defaultMode to "default." Furthermore, native Windows lacks built-in sandboxing support, forcing users to implement custom PreToolUse hooks to restrict file writes to project directories.

The Guardrail Failure

The custom guardrail introduced its own bug. The script designed to prevent writes outside the project folder inadvertently blocked Claude Code's internal plan storage located in ~/.claude/plans. This demonstrates a critical oversight in security scripting: failing to whitelist the tool's own state directories. The author noted that while the hook blocked a write to the Desktop, it also crippled the agent's planning functionality until the specific path was explicitly allowed.

Key Takeaways

  • The installer does not automatically configure the PATH on clean Windows systems.
  • Default "auto mode" allows unapproved file writes, requiring manual JSON configuration to disable.
  • Native Windows lacks built-in sandboxing, necessitating custom hooks that must account for internal tool paths.
  • The entire secure setup process took 60 minutes, with 32 minutes for installation and 28 for security hardening.

The Bottom Line

Anthropic's Claude Code is technically capable but operationally hostile to new Windows users. Until the default permission mode is changed to manual and the installer handles PATH variables correctly, this tool remains a power-user utility rather than a plug-and-play solution.