Uipath Functions
UiPath/skills
UiPath Coded Functions — deterministic Python or TypeScript/JavaScript units built with the uip function CLI (new -l py|ts|js, init, serve, run, pack, publish); the functions map in uipath.json…
Run Claude Code INSIDE a ca-sandbox box (--with-claude). An agent skill from arbiterForge/codeArbiter.
$ npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install arbiterForge/codeArbiter sandbox-claude-inside --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/arbiterForge/codeArbiter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ca-sandbox/skills/sandbox-claude-inside .claude/skills/sandbox-claude-inside && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sandbox-claude-inside" agent skill from https://github.com/arbiterForge/codeArbiter/tree/main/plugins/ca-sandbox/skills/sandbox-claude-inside into .claude/skills/sandbox-claude-inside/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-claude-inside", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/arbiterForge/codeArbiter/tree/main/plugins/ca-sandbox/skills/sandbox-claude-insideType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install arbiterForge/codeArbiter sandbox-claude-inside --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/arbiterForge/codeArbiter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/ca-sandbox/skills/sandbox-claude-inside .agents/skills/sandbox-claude-inside && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sandbox-claude-inside" agent skill from https://github.com/arbiterForge/codeArbiter/tree/main/plugins/ca-sandbox/skills/sandbox-claude-inside into .agents/skills/sandbox-claude-inside/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-claude-inside", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install arbiterForge/codeArbiter sandbox-claude-inside --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/arbiterForge/codeArbiter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/ca-sandbox/skills/sandbox-claude-inside .cursor/skills/sandbox-claude-inside && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sandbox-claude-inside" agent skill from https://github.com/arbiterForge/codeArbiter/tree/main/plugins/ca-sandbox/skills/sandbox-claude-inside into .cursor/skills/sandbox-claude-inside/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-claude-inside", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/arbiterForge/codeArbiter.git --path plugins/ca-sandbox/skills/sandbox-claude-inside--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install arbiterForge/codeArbiter sandbox-claude-inside --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/arbiterForge/codeArbiter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/ca-sandbox/skills/sandbox-claude-inside .gemini/skills/sandbox-claude-inside && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sandbox-claude-inside" agent skill from https://github.com/arbiterForge/codeArbiter/tree/main/plugins/ca-sandbox/skills/sandbox-claude-inside into .gemini/skills/sandbox-claude-inside/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-claude-inside", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install arbiterForge/codeArbiter sandbox-claude-insideInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/arbiterForge/codeArbiter.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/ca-sandbox/skills/sandbox-claude-inside .github/skills/sandbox-claude-inside && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sandbox-claude-inside" agent skill from https://github.com/arbiterForge/codeArbiter/tree/main/plugins/ca-sandbox/skills/sandbox-claude-inside into .github/skills/sandbox-claude-inside/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-claude-inside", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install arbiterForge/codeArbiter sandbox-claude-inside --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/arbiterForge/codeArbiter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/ca-sandbox/skills/sandbox-claude-inside .opencode/skills/sandbox-claude-inside && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sandbox-claude-inside" agent skill from https://github.com/arbiterForge/codeArbiter/tree/main/plugins/ca-sandbox/skills/sandbox-claude-inside into .opencode/skills/sandbox-claude-inside/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-claude-inside", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sandbox-claude-insideRun Claude Code INSIDE a ca-sandbox box (--with-claude). An agent skill from arbiterForge/codeArbiter.
Sandbox Claude Inside is an agent skill from arbiterForge/codeArbiter. Run Claude Code INSIDE a ca-sandbox box (--with-claude). Routed to when the user wants an agent loop running against an isolated, ephemeral sandbox rather than the host. Authenticates via an env-injected CLAUDECODEOAUTHTOKEN with no host bind of ~/.claude; the image pins the CLI and disables the autoupdater; HOME is backed by a named volume so the .claude state persists across restart. Five gated phases — posture, image, token, run, teardown. The hard default is offline or Anthropic-domains-only egress, and the…
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Autonomous loops and OAuth and OpenID Connect. The repository describes itself as: Open-source governance and hard gates for AI coding agents across Claude Code, Codex CLI, and Pi. The licence is AGPL-3.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9496cff. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dockerclaudenodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CLAUDE_CODE_OAUTH_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sandbox Claude Inside loads about 2.4k tokens when it runs. Until then it costs about 159 tokens; SKILL.md has 1,206 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from arbiterForge/codeArbiter at commit 9496cff, republished under its AGPL-3.0 licence (© arbiterForge). 1,206 words, ~2,396 tokens.
.claude/skills/sandbox-claude-inside/SKILL.md (or your agent's skills folder).Put Claude Code in the box, not the box on your machine. --with-claude runs the
CLI inside a host-FS-isolated ca-sandbox container, authenticating from an
env-injected token with no host bind of ~/.claude — the mechanism proven by
Spike B (.codearbiter/spikes/ca-sandbox-claude-auth.md, CONFIRM-07). It is the
deliberately-hardened lane: a token in a box is stealable, so the posture is locked
down by construction (offline or Anthropic-only egress, token volume never shared
with untrusted code), never left to operator discipline.
Read these, or STOP and surface the gap — never guess the token source, the egress posture, or the persistence mechanism:
${CLAUDE_PROJECT_DIR}/.codearbiter/spikes/ca-sandbox-claude-auth.md — the
proven auth path (env token → real 401 on a dummy), the named-volume HOME
persistence mechanism, and the load-bearing caveat that fixes the hard default.${CLAUDE_PROJECT_DIR}/.codearbiter/spikes/ca-sandbox-egress.md — why the
egress allowlist is EXPERIMENTAL (CDN drift + DNS-exfil hole), so offline is
the only GUARANTEED posture for a token-bearing box.${CLAUDE_PROJECT_DIR}/.codearbiter/decisions/0007-second-plugin-ca-sandbox.md
— the governing decision; ca-sandbox is infrastructure, sibling to ca.The shipped driver is plugins/ca-sandbox/tools/claude-inside.js, its OWN
binary rather than a sandbox subcommand (#377):
node <plugin>/tools/claude-inside.js --image <tag> --home-volume <name> [--net offline|anthropic-only]That separation IS the gate. A sandbox with-claude subcommand would let anyone
start a token-bearing box with one ungated command, which would turn the five
BLOCK phases below from enforcement into advice. This routine is the only
sanctioned caller.
The token MUST come from the approved store as CLAUDE_CODE_OAUTH_TOKEN, in the
ENVIRONMENT. The entry point refuses a --token flag outright: an argument list
is world-readable, so passing a credential there publishes it to every process
on the host. In tests use a DUMMY token only.
Sources: plugins/ca-sandbox/tools/claude-inside.ts
(buildClaudeImageDockerfile, buildClaudeRunArgs, runClaudeInside,
TokenCoMountRejectedError) and claude-inside-cli.ts (the entry).
Fix the egress posture and the trust boundary BEFORE anything is built or started. A token-bearing box is the one place ca-sandbox's FS-isolation invariant and a live credential are in direct tension — resolve it here, explicitly.
offline (default, GUARANTEED — no interface at
all) or anthropic-only (the EXPERIMENTAL Anthropic-domains allowlist, for
interactive inference). No third option exists; a wide-open policy is rejected./work/repo. If the user wants Claude to read an untrusted repo, that is a
SEPARATE, source-only box without the token — say so.Gate: a named egress posture (offline or anthropic-only) AND an explicit
statement that this box carries the token and NOT untrusted source. If the user
asks for both at once, STOP and split them — the co-mount is forbidden (Phase 4).
Build (or reuse) the pinned --with-claude image via buildClaudeImageDockerfile.
@anthropic-ai/claude-code@<pinned> — a PINNED semver,
never @latest — and bakes DISABLE_AUTOUPDATER=1 so the box never silently
pulls an unreviewed CLI into a token-bearing environment.node:22-slim (Spike B installed the CLI cleanly there), bound to a
reviewed content DIGEST — node:22-slim@sha256:…, the CLAUDE_BASE_IMAGE
constant. The tag is kept only as human-readable provenance; docker resolves the
digest. This is the driver's highest-stakes pin: the base image's code runs in
the SAME container as CLAUDE_CODE_OAUTH_TOKEN, so a retag or registry
compromise would otherwise execute unreviewed code alongside a live credential.
Pinning the CLI version alone is not enough. HOME is baked to the in-container
claude home so the named volume has a writable mount point.Gate: the image carries the exact pinned version (claude --version reports it),
DISABLE_AUTOUPDATER=1, and a digest-pinned base. A floating or unpinned CLI —
or an unpinned base image — fails the gate; image reproducibility is
non-negotiable for a token box. Changing the digest is a reviewed dependency
change: re-resolve it with docker buildx imagetools inspect, then re-run the
credential-boundary and isolation suites.
Source the OAuth token and confirm it is injected as ENV, never bound from the host.
CLAUDE_CODE_OAUTH_TOKEN
(auth-precedence #5, from claude setup-token). It is env-injected
(-e CLAUDE_CODE_OAUTH_TOKEN=…) — this IS the auth path; no host bind of
~/.claude is required or permitted.$HOME/.claude/.credentials.json survives a restart on the volume — not on the
host. A fresh container on the same volume resumes the session.Gate: the token is from the approved store, env-injected (not bound), and never logged/persisted to a host-readable location. The home volume is a NAMED VOLUME, not a bind.
Start the box via buildClaudeRunArgs / runClaudeInside. The builder enforces the
guarantees by construction — do not hand-roll a docker run.
mounts.ts): the home named volume at HOME
and a tmpfs /tmp. NO bind mount, NO /var/run/docker.sock, NEVER
--privileged. Read-only root, non-root, no-new-privileges, resource caps —
the same structural lockdown as any sandbox.offline → --network none;
anthropic-only → the experimental Anthropic-domains allowlist (custom bridge +
NET_ADMIN/NET_RAW + the init-firewall script applied inside the box).sourceVolume throws TokenCoMountRejectedError.
The token volume is NEVER co-mounted with an untrusted-code run. This is the
load-bearing Spike B caveat made structural — it is not optional.Gate: the run argv was produced by the builder (not hand-rolled), the co-mount
guard was not bypassed, the posture matches Phase 1, and a dummy token reaches AUTH
(a real 401 Invalid bearer token) — proving the env token is the auth path before
any real credential is used.
Tear down per the lifecycle rules, deciding the fate of the credential volume.
docker rm -f). By default REMOVE the home/token volume
too — a persisted credential store is a standing exfil target; keep it only on an
explicit, recorded --keep-volume decision.ca.sandbox=1 label (plus a build marker in
tests); the lifecycle/registry surfaces (destroy, prune) reclaim them.Gate: container removed; the credential volume removed unless --keep-volume was
explicitly chosen and recorded; no leaked ca.sandbox=1 objects remain.
CLAUDE_CODE_OAUTH_TOKEN — NEVER a host
bind of ~/.claude.@anthropic-ai/claude-code@<semver> with
DISABLE_AUTOUPDATER=1; MUST NOT use @latest or an unpinned CLI.--with-claude egress to offline or anthropic-only; MUST NOT
give a token-bearing box wide-open egress./work/repo) — buildClaudeRunArgs throws
TokenCoMountRejectedError and that throw MUST NOT be bypassed..claude
credential store persists across restart on the volume, not on the host.--privileged;
read-only root, non-root, and cap-drop hold as for any sandbox.--keep-volume is an
explicit, recorded decision.offline is the only GUARANTEED posture.© arbiterForge, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/ca-sandbox/skills/sandbox-claude-inside of arbiterForge/codeArbiter.
Open the folder on GitHubat commit 9496cff
Sandbox Claude Inside next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sandbox Claude Inside this skillarbiterForge/codeArbiter | 147 | — | ~2.4k | Automated safety check: Pass | AGPL-3.0 | |
| Uipath FunctionsUiPath/skills | 167 | — | ~3.6k | Automated safety check: Notes | MIT | |
| Xquik MCPXquik-dev/x-twitter-scraper | 209 | 1 repos | ~997 | Automated safety check: Pass | MIT | |
| MCP Dart Streamable HTTPleehack/mcp_dart | 116 | — | ~2k | Automated safety check: Pass | MIT | |
| Unifapiunifapi-agent/agents | 587 | — | ~741 | Automated safety check: Pass | MIT | |
| Durable Objectsbutterbase-ai/butterbase-skills | 534 | — | ~2.8k | Automated safety check: Pass | MIT |
UiPath/skills
UiPath Coded Functions — deterministic Python or TypeScript/JavaScript units built with the uip function CLI (new -l py|ts|js, init, serve, run, pack, publish); the functions map in uipath.json…
Xquik-dev/x-twitter-scraper
Connect, verify, and troubleshoot Xquik's remote MCP server.
leehack/mcp_dart
A skill your agent uses when serving an MCP server over HTTP with mcpdart or connecting to a remote one: StreamableMcpServer setup, Host and Origin allowlists (DNS rebinding protection), CORS for…
unifapi-agent/agents
A skill your agent uses when working with UnifAPI public-data APIs or the UnifAPI MCP server: connecting OAuth MCP clients, discovering operations, calling social/search/scrape/news APIs…
butterbase-ai/butterbase-skills
A skill your agent uses when building stateful per-key actors — chat rooms, multiplayer rooms, rate limiters, long-running agents, leaderboards — that need persistent in-memory + storage state…
tokencanopy/e2a
A skill your agent uses when a user wants to connect or authorize the e2a MCP server, select or create an agent inbox, verify first-run readiness, or set up a custom email domain.
arbiterForge/codeArbiter
Record user-decided ADRs or inspect their health read-only. An agent skill from arbiterForge/codeArbiter.
arbiterForge/codeArbiter
Stop everything and surface a rule conflict — persona vs. An agent skill from arbiterForge/codeArbiter.
arbiterForge/codeArbiter
Start a feature: brainstorm a spec, get it approved, then drive it test-first through the pipeline.
arbiterForge/codeArbiter
Opt this repo into codeArbiter — scaffold the root-level .codearbiter/ state store.
arbiterForge/codeArbiter
Read-only 3-metric governance glance — override rate, small-lane rate, sprint low-confidence ratio — each with a trend arrow vs.
arbiterForge/codeArbiter
Sanctioned, logged bypass of a gate or hard rule — one audit line, then proceed.
Categories
Run Claude Code INSIDE a ca-sandbox box (--with-claude). An agent skill from arbiterForge/codeArbiter. Sandbox Claude Inside is an agent skill from arbiterForge/codeArbiter. Run Claude Code INSIDE a ca-sandbox box (--with-claude).
Sandbox Claude Inside fits situations like: wants an agent loop running against an isolated; ephemeral sandbox rather than the host.
Run `npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a claude-code`. Or copy the skill folder (plugins/ca-sandbox/skills/sandbox-claude-inside in arbiterForge/codeArbiter) into .claude/skills/sandbox-claude-inside in your project. Claude Code loads it when a task matches its description.
Run `npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a codex`. Or copy the skill folder (plugins/ca-sandbox/skills/sandbox-claude-inside in arbiterForge/codeArbiter) into .agents/skills/sandbox-claude-inside in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sandbox-claude-inside, .gemini/skills/sandbox-claude-inside, .github/skills/sandbox-claude-inside and .opencode/skills/sandbox-claude-inside in your project.
Going by SKILL.md and its folder, Sandbox Claude Inside needs the command-line tools its instructions call (docker, claude and node) and credentials named CLAUDE_CODE_OAUTH_TOKEN. Our summary lists: Docker; A credential in CLAUDE_CODE_OAUTH_TOKEN.
SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sandbox Claude Inside is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Sandbox Claude Inside: Uipath Functions (UiPath/skills, 167 stars), Xquik MCP (Xquik-dev/x-twitter-scraper, 209 stars), MCP Dart Streamable HTTP (leehack/mcp_dart, 116 stars) and Unifapi (unifapi-agent/agents, 587 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
arbiterForge (a GitHub organization) maintains it in arbiterForge/codeArbiter, which has 147 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 8, 2026.
Source: arbiterForge/codeArbiter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.