Play / The map / The capabilities / Reach any host on the internet
Reach any host on the internet
send.endpoint.world — send × network-endpoint at world reach (anything on the internet). Family: network. Effect: cannot be undone.
Granted by 6 of 9
| Profile | Control on the path | Evidence | Via |
|---|---|---|---|
| Claude Code — local · confirm off | ● none | derived | shell (Bash), fetch (WebFetch) |
| Claude Code — local · confirm on | ● none | derived | shell (Bash), fetch (WebFetch) |
| Claude Desktop — local tools | ● none | derived | local files and commands (when enabled) |
| Browser extension — all sites | ● none | documented | the extension |
| Scheduled job — service account | ● none | derived | the job |
| GitHub Actions — hosted runner | ● none | observed | the job's shell |
What narrows it
The setting: route outbound traffic through an allow-list — the one control the hosted container already has, demonstrated rather than claimed
What it costs: an hour, if you already have somewhere to put it
Tier after: boundary
In the mandates
- wanted by A CI job on a hosted runner
- not wanted by Chat in the browser, nothing connected
- not wanted by A browser extension I installed
- not wanted by A scheduled job under a service account