The App Store version
What Apple's App Sandbox changes for FileRanger, and how the command helper lifts its limits for commands.
FileRanger from the Mac App Store runs in Apple's App Sandbox, like every app from the store. The sandbox limits what an app can reach on your Mac. For a file manager, that shows in two places: the folders it can open, and the programs it can start.
Access to your files
On first launch, FileRanger shows Allow access to your files. Click Allow Access…, then Allow Access in the window that opens, and FileRanger can browse your startup disk. You can also choose a single folder there instead.
- The config file is in your home folder, so custom actions need access to it.
- Other drives may need their own access. When a folder on another drive doesn't open, click Allow Access… in its place.
- Settings → General → Folder Access lists what FileRanger can open, and lets you add or remove folders.
The command helper
The sandbox lets FileRanger start only the programs that come with macOS, and no commands in other apps. The command helper lifts that limit. It's a short script inside FileRanger that macOS runs outside the sandbox when FileRanger asks. With it, custom actions, Git, tools from Homebrew and commands in your terminal work like in any other app.
To install it:
- Open Settings → General.
- Under Command Helper, click Install….
- In the window that opens, click Install.
FileRanger then links its script into ~/Library/Application Scripts/com.nightlybuildgroup.MacScout, the folder macOS keeps for this. An app from the store can't write there without your permission, which is what the window asks for. The script stays inside the app, so it updates with FileRanger.
The helper runs only when FileRanger starts it. Commands you run through it can do what they can do in your terminal. macOS counts what they open as opened by FileRanger, so the privacy settings for FileRanger apply to them.
To remove the helper, click Remove in the same place, or delete the link from that folder.
Without the helper
Until you install the helper, FileRanger runs commands inside the sandbox. When a command fails because of the sandbox, the error message says so.
Commands for the terminal
The sandbox doesn't let FileRanger start a command in another app. So package scripts, make targets, Claude Code Here, Codex Here and actions with "output": "terminal" open your terminal in the folder and put the command on the clipboard. Paste it with ⌘V and press Return.
Git's Status and Log show their output in a window instead.
Developer tools
Programs that come with macOS work, like zip, rsync, sips, perl and ruby, and so do the ones inside Xcode, the Command Line Tools and the apps in your Applications folder.
Programs you installed anywhere else don't start: tools from Homebrew, nvm, npm or pip, and installers that put their tools in /usr/local. They stop with operation not permitted. A script of your own runs when a shell reads it, like zsh ~/bin/tidy.sh, but not when you start it as ~/bin/tidy.sh, and the programs it starts follow the same rules.
Some tools in /usr/bin only start the matching tool from Xcode or the Command Line Tools, and that step doesn't work in the sandbox: git, make, python3, clang, swift and opendiff, among others. They stop with this message:
xcrun: error: cannot be used within an App Sandbox.Give those tools their full path, like /Applications/Xcode.app/Contents/Developer/usr/bin/git. The Git menu finds a git that works on its own.
Files FileRanger copies
macOS marks every file that an app from the store creates or copies, the way it marks downloads. Documents open as usual. Apps, scripts and command-line tools that FileRanger copied go through Gatekeeper the first time you open them, and macOS may refuse to run the ones that aren't signed. FileRanger can't remove the mark.
With the helper, copies get no new mark. Files that had one before, like downloads, keep it.
Locked Files
Show Apps Using This… needs lsof, which can't run in the sandbox, so the menu leaves it out. Lock and Unlock work as usual.