Agent skill

Isolated Linux Agent Workspace

by agent-sh in agent-sh/agent-workspace-linux

Drives a hidden, agent-owned Linux desktop and browser over MCP for GUI testing and web automation without touching the user's real desktop.

MITAuto-check passedProductivity & Automation

Install Isolated Linux Agent Workspace

skills CLI
$ npx skills add agent-sh/agent-workspace-linux --skill agent-workspace-linux -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agent-sh/agent-workspace-linux agent-workspace-linux --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agent-sh/agent-workspace-linux.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agent-workspace-linux .claude/skills/agent-workspace-linux && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-workspace-linux
GitHub stars
185
Token cost
~2.1k tokens
SKILL.md length
981 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Drives a hidden, agent-owned Linux desktop and browser over MCP for GUI testing and web automation without touching the user's real desktop.

  • Works in 6 steps: Orient: call mcp_agent_context or… → Check permissions: call mcp_permissions… → Start: use workspace_start with… → …
  • Testing a GUI application in a disposable desktop
  • SKILL.md covers Critical Boundaries, When To Use, Permission Model and Phase Router, plus 5 more sections
  • Calls cursor and codex

What it does

Apps, browser automation, screenshots, clipboard and input all run inside the workspace's own hidden display, never on your real desktop, focus or Chrome profile. The skill is a light entry point to the `agent-workspace-linux` MCP server: because the server exposes many tools, the agent routes by phase and asks the host to load only the tool schemas needed next.

It fits GUI application QA in a throwaway desktop, browser, web and shopping automation that must not hijack host Chrome, observing sandboxed windows, logs, events, screenshots and artifacts, and cleaning up stale or orphaned workspaces. It is not for the host desktop or Chrome, generic MCP setup, or pure code and file edits. Setup on Codex for Linux belongs to its Agent Workspaces page, covering binary path, permission rules, reconnecting and smoke tests, profiles, starting and stopping workspaces and the viewer, not generic MCP settings. The installer puts the skill under `~/.codex/skills` and leaves the Codex MCP config alone unless `--codex-configure` or `--permissions` is chosen.

When your agent uses it

  • Testing a GUI application in a disposable desktop
  • Automating a web or shopping task without using the real Chrome
  • Observing a sandboxed app through screenshots and logs
  • Cleaning up stale agent workspaces

Example prompts

  • “Open the app in an isolated desktop, click through the signup flow and capture screenshots.”
  • “Fill the cart on the shopping site in the workspace browser; do not touch my real Chrome.”
  • “List and remove the stale agent workspaces left from earlier runs.”

Requirements

  • The agent-workspace-linux MCP server
  • A Linux host

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Orient: call mcp_agent_context or mcp_session_brief, then use
  2. Check permissions: call mcp_permissions before mutating.
  3. Start: use workspace_start with ack_hidden_workspace=true and a clear
  4. Observe: use workspace_observe or focused screenshot/window/log/event
  5. Act: launch apps, run commands, click/type/paste/key only inside the
  6. Stop: use workspace_stop when finished; use workspace_cleanup_stale for

What it can do on your machine

Read from SKILL.md and the folder at commit 39f2473. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cursor
    • codex

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Isolated Linux Agent Workspace loads about 2.1k tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 981 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agent-sh/agent-workspace-linux at commit 39f2473, republished under its MIT licence (© agent-sh). 981 words, ~2,121 tokens.

Download SKILL.mdSave it as .claude/skills/agent-workspace-linux/SKILL.md (or your agent's skills folder).
name
agent-workspace-linux
description
Use when a task needs an isolated hidden Linux desktop or workspace-owned browser: GUI app QA, web/browser/shopping automation, sandboxed app observation, or stale workspace cleanup. Routes agent-workspace-linux MCP tools on demand. Does NOT apply to host desktop/Chrome control, generic MCP setup, or pure code/file edits.

agent-workspace-linux

Drive an isolated, agent-owned Linux desktop and workspace-owned browser through the agent-workspace-linux MCP server. The workspace runs apps, browser automation, screenshots, clipboard, and input inside its own hidden display, never the user's real desktop, focus, or host Chrome.

This skill is the lightweight entry point. The MCP exposes many tools; do not load, list, or paste them all up front. Route by phase and ask the host to load only the tool schemas needed for the next action.

Critical Boundaries

Use the dedicated Codex for Linux feature page for setup

Codex for Linux owns Agent Workspace setup through the Agent Workspaces page: binary path, page-authored permission rules, permission file mutation, Reconnect/Smoke test, profile creation, workspace start/stop, and viewer launch. Do not send users to generic MCP settings, general configuration pages, or ~/.codex/config.toml for normal Codex for Linux setup.

Skip unless: the host is Codex for Linux and the task is setup, permission changes, reconnect/restart, or the workspace tools are unavailable.

Keep tools progressive

The bundled installer is skill-first. ./install.sh installs this skill under ~/.codex/skills by default and leaves generic Codex MCP config untouched unless the user explicitly chooses --codex-configure or --permissions. For migration only, ./install.sh --clean-codex-config removes stale generic Codex MCP entries left by older installs; restart or reconnect Codex afterward.

Skip unless: the user asks how to install/register the backend or why the tool family should not be loaded at startup.

Never target the host desktop

Use this skill only for the hidden workspace. For the user's real Linux desktop, real Chrome profile, existing tabs, or host focus/mouse/keyboard, use the appropriate host-desktop or browser tool instead.

Skip unless: the requested action can run inside the isolated workspace display or workspace-owned browser.

When To Use

  • GUI app QA in a throwaway desktop.
  • Browser/web/shopping automation that must not hijack host Chrome.
  • Observation of sandboxed windows, logs, events, screenshots, or artifacts.
  • Cleanup of stale or orphaned agent workspaces.

Skip unless: the user task requires running or driving a real GUI app/browser in isolation. For pure code, shell, or file edits, do not start a workspace.

Permission Model

  • Default: no MCP ceiling is configured; the host/client owns approvals. Call mcp_permissions once before mutating to confirm configured=false.
  • Permission ceiling: --permissions PATH or AGENT_WORKSPACE_PERMISSIONS caps network, mounts, and app allowlist for the life of that MCP process. It can only be broadened by changing the config and restarting/reconnecting the backend from the owning setup surface.
  • Live control: mcp_control_state read-only/paused/active is a best-effort runtime control, not the authoritative security boundary.
  • Real-world actions: checkout, purchases, account changes, and messages require explicit user approval. Keep drafting separate from final action.

Skip unless: you are about to start a workspace, open a profile, launch/run an app, send input, or act on an external account/site.

Phase Router

Always orient before mutating.

PhaseLoad only these tools
Orientmcp_agent_context, mcp_session_brief, mcp_task_plan, mcp_permissions, mcp_action_catalog, workspace_doctor, workspace_list, workspace_status
Profilesprofile_list, profile_get, profile_template, profile_put, profile_check
Startworkspace_start, workspace_open_profile
Observeworkspace_observe, workspace_screenshot, workspace_list_windows, workspace_active_window, workspace_read_app_log, workspace_events
Actworkspace_launch_app, workspace_run_app, workspace_click, workspace_type_text, workspace_key, workspace_paste_text, workspace_focus_window, workspace_close_window
Browserworkspace_open_browser, workspace_browser_targets, workspace_browser_snapshot, workspace_browser_navigate, workspace_browser_search_results, workspace_browser_click
Viewer/controlmcp_control_state, mcp_control_update, workspace_open_viewer, workspace_list_viewers, workspace_close_viewer
Teardownworkspace_stop, workspace_kill_app, workspace_cleanup_stale

Skip unless: the current phase needs one of the listed capabilities. Do not load schemas for later phases until the plan reaches them.

Show full SKILL.md (440 more words)Show less

Safe Workflow

  1. Orient: call mcp_agent_context or mcp_session_brief, then use mcp_task_plan for app-QA, browser, observe, or cleanup intent.
  2. Check permissions: call mcp_permissions before mutating.
  3. Start: use workspace_start with ack_hidden_workspace=true and a clear purpose, or workspace_open_profile for a saved profile.
  4. Observe: use workspace_observe or focused screenshot/window/log/event tools before sending input.
  5. Act: launch apps, run commands, click/type/paste/key only inside the workspace.
  6. Stop: use workspace_stop when finished; use workspace_cleanup_stale for orphaned runtimes.

Skip unless: each step's precondition is visible in the previous tool result (workspace id, app id, target window, browser target, or explicit user approval).

Browser Tasks

Use the workspace-owned browser over its loopback DevTools endpoint. Start with workspace_open_browser, discover pages with workspace_browser_targets, read with workspace_browser_snapshot or workspace_browser_search_results, then navigate or click with browser tools.

Browser tools require a Chrome launched with --user-data-dir and loopback DevTools. Always get it from workspace_open_browser (MCP) or workspace open-browser (CLI) rather than hand-rolling a workspace_launch_app argv.

If you attach your own CDP/WebSocket client to that endpoint, omit the Origin header (e.g. websocket-client's suppress_origin=True). The DevTools port is ephemeral, so Chrome's origin allow-list cannot be pre-seeded and an Origin- bearing handshake is rejected with 403 Forbidden.

After workspace_browser_navigate or workspace_browser_click, read page.url / page.title for post-action state. target.* is refreshed to match, but if the refresh fails the response carries a warning saying it may be stale — check warnings before trusting target for verification.

Skip unless: the task is web/browser automation that can run in the isolated workspace. Do not attach to host Chrome, Playwright, or Computer Use as a shortcut.

Do NOT

  • Do not dump all MCP tools into the agent context at startup.
  • Do not send users to generic MCP/configuration pages for Codex for Linux Agent Workspace setup.
  • Do not start a workspace without ack_hidden_workspace=true and a purpose.
  • Do not send input to or screenshot the user's real desktop.
  • Do not perform purchases, checkout, account changes, or sends without explicit user approval.
  • Do not leave workspaces running after the task.

Example Trajectory

Task: "QA the settings dialog of myapp."

  1. mcp_agent_context and mcp_task_plan for app-QA.
  2. mcp_permissions to confirm the active boundary.
  3. workspace_start with ack_hidden_workspace=true and purpose "QA myapp settings".
  4. workspace_launch_app with the app command.
  5. workspace_observe to find the window.
  6. workspace_click / workspace_type_text to exercise Settings.
  7. workspace_screenshot and workspace_read_app_log for evidence.
  8. workspace_stop.

Constraints

  • Keep activation low-noise: only use this skill for isolated GUI/browser work.
  • Keep context small: frontmatter loads by default; body loads on activation; tool schemas load on demand.
  • Omit allowed-tools intentionally: different hosts namespace MCP tools differently, and the skill routes the full family progressively.
  • Validate with agnix --target generic|claude-code|cursor|codex|kiro when changing this file.

© agent-sh, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/agent-workspace-linux of agent-sh/agent-workspace-linux.

Open the folder on GitHubat commit 39f2473

Compare with similar skills

Isolated Linux Agent Workspace next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Isolated Linux Agent Workspace compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Isolated Linux Agent Workspace this skillagent-sh/agent-workspace-linux185—~2.1kAutomated safety check: PassMIT
Browser MCP Agentantibrow/anti-detect-browser-skills9141 repos~4.2kAutomated safety check: WarnMIT
Lightpandalightpanda-io/agent-skill101—~6kAutomated safety check: PassApache-2.0
Linux Desktop Controlagent-sh/computer-use-linux661—~2.7kAutomated safety check: PassMIT
Altic Studioaltic-dev/altic-mcp172—~3.3kAutomated safety check: PassApache-2.0
Computer Usexuzhougeng/wisp-science1k—~2.9kAutomated safety check: PassAGPL-3.0

Similar skills

  • Browser MCP Agent

    antibrow/anti-detect-browser-skills

    Give an AI agent its own real browser over MCP tool calls - launch, navigate, click, fill, screenshot, extract text, run JS - with a kernel-level real-device fingerprint and a persistent profile, so…

    914 GitHub starsUsed in 1 repo~4.2k tokens
    Productivity & AutomationAuto-check: warnings
  • Lightpanda

    lightpanda-io/agent-skill

    Lightpanda browser, drop-in replacement for Chrome-based browsing in any AI agent - faster and lighter for tasks without graphical rendering like data retrieval.

    101 GitHub stars~6k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Linux Desktop Control

    agent-sh/computer-use-linux

    Lets an agent observe and operate a local Linux desktop through the computer-use-linux MCP server or Pi tools: accessibility trees, screenshots, windows and input.

    661 GitHub stars~2.7k tokensUpdated 3 days ago
    Productivity & AutomationAuto-check passed
  • Altic Studio

    altic-dev/altic-mcp

    macOS automation skill for AppleScript actions and Chrome browser control via MCP CDP tools.

    172 GitHub stars~3.3k tokensUpdated 2 mo ago
    Productivity & AutomationAuto-check passed
  • Computer Use

    xuzhougeng/wisp-science

    Use Cua Driver through MCP to inspect and operate the user's native desktop apps on Windows, macOS, or Linux.

    1k GitHub stars~2.9k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • AIPex Browser Control

    AIPexStudio/AIPex

    Lets an agent drive Chrome through the AIPex extension and its MCP bridge: navigation, clicking, form filling, screenshots, tab management and downloads.

    1.3k GitHub stars~1.8k tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed

Questions about Isolated Linux Agent Workspace

What does Isolated Linux Agent Workspace do?

Drives a hidden, agent-owned Linux desktop and browser over MCP for GUI testing and web automation without touching the user's real desktop. Apps, browser automation, screenshots, clipboard and input all run inside the workspace's own hidden display, never on your real desktop, focus or Chrome profile. The skill is a light entry point to the `agent-workspace-linux` MCP server: because the server exposes many tools, the agent routes by phase and asks the host to load only the tool schemas needed next.

When should I use Isolated Linux Agent Workspace?

Isolated Linux Agent Workspace fits situations like: testing a GUI application in a disposable desktop; automating a web or shopping task without using the real Chrome; observing a sandboxed app through screenshots and logs; cleaning up stale agent workspaces.

How do I install Isolated Linux Agent Workspace in Claude Code?

Run `npx skills add agent-sh/agent-workspace-linux --skill agent-workspace-linux -a claude-code`. Or copy the skill folder (skills/agent-workspace-linux in agent-sh/agent-workspace-linux) into .claude/skills/agent-workspace-linux in your project. Claude Code loads it when a task matches its description.

How do I install Isolated Linux Agent Workspace in Codex?

Run `npx skills add agent-sh/agent-workspace-linux --skill agent-workspace-linux -a codex`. Or copy the skill folder (skills/agent-workspace-linux in agent-sh/agent-workspace-linux) into .agents/skills/agent-workspace-linux in your project. Codex loads it when a task matches its description.

Can I use Isolated Linux Agent Workspace in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agent-sh/agent-workspace-linux --skill agent-workspace-linux -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-workspace-linux, .gemini/skills/agent-workspace-linux, .github/skills/agent-workspace-linux and .opencode/skills/agent-workspace-linux in your project.

What does Isolated Linux Agent Workspace need to run?

Going by SKILL.md and its folder, Isolated Linux Agent Workspace needs the command-line tools its instructions call (cursor and codex). Our summary lists: The agent-workspace-linux MCP server; A Linux host.

Does Isolated Linux Agent Workspace access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Isolated Linux Agent Workspace safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Isolated Linux Agent Workspace use?

Isolated Linux Agent Workspace is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Isolated Linux Agent Workspace use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Isolated Linux Agent Workspace?

Skills that share tags, products or a category with Isolated Linux Agent Workspace: Browser MCP Agent (antibrow/anti-detect-browser-skills, 914 stars), Lightpanda (lightpanda-io/agent-skill, 101 stars), Linux Desktop Control (agent-sh/computer-use-linux, 661 stars) and Altic Studio (altic-dev/altic-mcp, 172 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Isolated Linux Agent Workspace?

agent-sh (a GitHub organization) maintains it in agent-sh/agent-workspace-linux, which has 185 GitHub stars. The repository was last updated on October 3, 2026.

Source: agent-sh/agent-workspace-linux on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.