Agent skill

Sandbox Claude Inside

by arbiterForge in arbiterForge/codeArbiter

Run Claude Code INSIDE a ca-sandbox box (--with-claude). An agent skill from arbiterForge/codeArbiter.

AGPL-3.0Auto-check passedBackend & APIs

Install Sandbox Claude Inside

skills CLI
$ npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install arbiterForge/codeArbiter sandbox-claude-inside --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/arbiterForge/codeArbiter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ca-sandbox/skills/sandbox-claude-inside .claude/skills/sandbox-claude-inside && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sandbox-claude-inside
GitHub stars
147
Token cost
~2.4k tokens
SKILL.md length
1,206 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Run Claude Code INSIDE a ca-sandbox box (--with-claude). An agent skill from arbiterForge/codeArbiter.

  • Works in 5 steps: Posture · gate: BLOCK → Image · gate: BLOCK → Token · gate: BLOCK → …
  • Wants an agent loop running against an isolated
  • SKILL.md covers Pre-flight, Phase 1 — Posture · gate: BLOCK, Phase 2 — Image · gate: BLOCK and Phase 3 — Token · gate: BLOCK, plus 3 more sections
  • Calls docker, claude and node; needs CLAUDE_CODE_OAUTH_TOKEN

What it does

Sandbox Claude Inside is an agent skill from arbiterForge/codeArbiter. Run Claude Code INSIDE a ca-sandbox box (--with-claude). Routed to when the user wants an agent loop running against an isolated, ephemeral sandbox rather than the host. Authenticates via an env-injected CLAUDECODEOAUTHTOKEN with no host bind of ~/.claude; the image pins the CLI and disables the autoupdater; HOME is backed by a named volume so the .claude state persists across restart. Five gated phases — posture, image, token, run, teardown. The hard default is offline or Anthropic-domains-only egress, and the…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Autonomous loops and OAuth and OpenID Connect. The repository describes itself as: Open-source governance and hard gates for AI coding agents across Claude Code, Codex CLI, and Pi. The licence is AGPL-3.0.

When your agent uses it

  • Wants an agent loop running against an isolated
  • Ephemeral sandbox rather than the host

Example prompts

  • “/sandbox-claude-inside”

Requirements

  • Docker
  • A credential in CLAUDE_CODE_OAUTH_TOKEN

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Posture · gate: BLOCK
  2. Image · gate: BLOCK
  3. Token · gate: BLOCK
  4. Run · gate: BLOCK
  5. Teardown · gate: BLOCK

What it can do on your machine

Read from SKILL.md and the folder at commit 9496cff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • claude
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CLAUDE_CODE_OAUTH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sandbox Claude Inside loads about 2.4k tokens when it runs. Until then it costs about 159 tokens; SKILL.md has 1,206 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~159
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from arbiterForge/codeArbiter at commit 9496cff, republished under its AGPL-3.0 licence (© arbiterForge). 1,206 words, ~2,396 tokens.

Download SKILL.mdSave it as .claude/skills/sandbox-claude-inside/SKILL.md (or your agent's skills folder).
name
sandbox-claude-inside
description
Run Claude Code INSIDE a ca-sandbox box (`--with-claude`). Routed to when the user wants an agent loop running against an isolated, ephemeral sandbox rather than the host. Authenticates via an env-injected CLAUDE_CODE_OAUTH_TOKEN with no host bind of ~/.claude; the image pins the CLI and disables the autoupdater; HOME is backed by a named volume so the .claude state persists across restart. Five gated phases — posture, image, token, run, teardown. The hard default is offline or Anthropic-domains-only egress, and the token volume is NEVER co-mounted with an untrusted-code run; both are enforced, not advised.

sandbox-claude-inside

Put Claude Code in the box, not the box on your machine. --with-claude runs the CLI inside a host-FS-isolated ca-sandbox container, authenticating from an env-injected token with no host bind of ~/.claude — the mechanism proven by Spike B (.codearbiter/spikes/ca-sandbox-claude-auth.md, CONFIRM-07). It is the deliberately-hardened lane: a token in a box is stealable, so the posture is locked down by construction (offline or Anthropic-only egress, token volume never shared with untrusted code), never left to operator discipline.

Pre-flight

Read these, or STOP and surface the gap — never guess the token source, the egress posture, or the persistence mechanism:

  • ${CLAUDE_PROJECT_DIR}/.codearbiter/spikes/ca-sandbox-claude-auth.md — the proven auth path (env token → real 401 on a dummy), the named-volume HOME persistence mechanism, and the load-bearing caveat that fixes the hard default.
  • ${CLAUDE_PROJECT_DIR}/.codearbiter/spikes/ca-sandbox-egress.md — why the egress allowlist is EXPERIMENTAL (CDN drift + DNS-exfil hole), so offline is the only GUARANTEED posture for a token-bearing box.
  • ${CLAUDE_PROJECT_DIR}/.codearbiter/decisions/0007-second-plugin-ca-sandbox.md — the governing decision; ca-sandbox is infrastructure, sibling to ca.

The shipped driver is plugins/ca-sandbox/tools/claude-inside.js, its OWN binary rather than a sandbox subcommand (#377):

node <plugin>/tools/claude-inside.js --image <tag> --home-volume <name> [--net offline|anthropic-only]

That separation IS the gate. A sandbox with-claude subcommand would let anyone start a token-bearing box with one ungated command, which would turn the five BLOCK phases below from enforcement into advice. This routine is the only sanctioned caller.

The token MUST come from the approved store as CLAUDE_CODE_OAUTH_TOKEN, in the ENVIRONMENT. The entry point refuses a --token flag outright: an argument list is world-readable, so passing a credential there publishes it to every process on the host. In tests use a DUMMY token only.

Sources: plugins/ca-sandbox/tools/claude-inside.ts (buildClaudeImageDockerfile, buildClaudeRunArgs, runClaudeInside, TokenCoMountRejectedError) and claude-inside-cli.ts (the entry).

Phase 1 — Posture · gate: BLOCK

Fix the egress posture and the trust boundary BEFORE anything is built or started. A token-bearing box is the one place ca-sandbox's FS-isolation invariant and a live credential are in direct tension — resolve it here, explicitly.

  • Egress — choose exactly one: offline (default, GUARANTEED — no interface at all) or anthropic-only (the EXPERIMENTAL Anthropic-domains allowlist, for interactive inference). No third option exists; a wide-open policy is rejected.
  • Trust boundary — the box runs Claude, NOT the untrusted source repo. Confirm the run mounts only the token/home volume, never the source volume at /work/repo. If the user wants Claude to read an untrusted repo, that is a SEPARATE, source-only box without the token — say so.

Gate: a named egress posture (offline or anthropic-only) AND an explicit statement that this box carries the token and NOT untrusted source. If the user asks for both at once, STOP and split them — the co-mount is forbidden (Phase 4).

Phase 2 — Image · gate: BLOCK

Build (or reuse) the pinned --with-claude image via buildClaudeImageDockerfile.

  • The image installs @anthropic-ai/claude-code@<pinned> — a PINNED semver, never @latest — and bakes DISABLE_AUTOUPDATER=1 so the box never silently pulls an unreviewed CLI into a token-bearing environment.
  • The base is node:22-slim (Spike B installed the CLI cleanly there), bound to a reviewed content DIGEST — node:22-slim@sha256:…, the CLAUDE_BASE_IMAGE constant. The tag is kept only as human-readable provenance; docker resolves the digest. This is the driver's highest-stakes pin: the base image's code runs in the SAME container as CLAUDE_CODE_OAUTH_TOKEN, so a retag or registry compromise would otherwise execute unreviewed code alongside a live credential. Pinning the CLI version alone is not enough. HOME is baked to the in-container claude home so the named volume has a writable mount point.

Gate: the image carries the exact pinned version (claude --version reports it), DISABLE_AUTOUPDATER=1, and a digest-pinned base. A floating or unpinned CLI — or an unpinned base image — fails the gate; image reproducibility is non-negotiable for a token box. Changing the digest is a reviewed dependency change: re-resolve it with docker buildx imagetools inspect, then re-run the credential-boundary and isolation suites.

Phase 3 — Token · gate: BLOCK

Source the OAuth token and confirm it is injected as ENV, never bound from the host.

  • The token comes from the approved secret store as CLAUDE_CODE_OAUTH_TOKEN (auth-precedence #5, from claude setup-token). It is env-injected (-e CLAUDE_CODE_OAUTH_TOKEN=…) — this IS the auth path; no host bind of ~/.claude is required or permitted.
  • The token MUST NOT be echoed to logs, written to a file the source volume can read, or passed into any LLM prompt. Prefer a scoped/short-lived setup-token.
  • Persistence: HOME is backed by a docker NAMED VOLUME, so the credential store $HOME/.claude/.credentials.json survives a restart on the volume — not on the host. A fresh container on the same volume resumes the session.

Gate: the token is from the approved store, env-injected (not bound), and never logged/persisted to a host-readable location. The home volume is a NAMED VOLUME, not a bind.

Show full SKILL.md (452 more words)Show less

Phase 4 — Run · gate: BLOCK

Start the box via buildClaudeRunArgs / runClaudeInside. The builder enforces the guarantees by construction — do not hand-roll a docker run.

  • Mounts go through the one chokepoint (mounts.ts): the home named volume at HOME and a tmpfs /tmp. NO bind mount, NO /var/run/docker.sock, NEVER --privileged. Read-only root, non-root, no-new-privileges, resource caps — the same structural lockdown as any sandbox.
  • The egress posture from Phase 1 is applied: offline → --network none; anthropic-only → the experimental Anthropic-domains allowlist (custom bridge + NET_ADMIN/NET_RAW + the init-firewall script applied inside the box).
  • The CO-MOUNT GUARD: supplying a sourceVolume throws TokenCoMountRejectedError. The token volume is NEVER co-mounted with an untrusted-code run. This is the load-bearing Spike B caveat made structural — it is not optional.

Gate: the run argv was produced by the builder (not hand-rolled), the co-mount guard was not bypassed, the posture matches Phase 1, and a dummy token reaches AUTH (a real 401 Invalid bearer token) — proving the env token is the auth path before any real credential is used.

Phase 5 — Teardown · gate: BLOCK

Tear down per the lifecycle rules, deciding the fate of the credential volume.

  • Remove the container (docker rm -f). By default REMOVE the home/token volume too — a persisted credential store is a standing exfil target; keep it only on an explicit, recorded --keep-volume decision.
  • Every object created carries the ca.sandbox=1 label (plus a build marker in tests); the lifecycle/registry surfaces (destroy, prune) reclaim them.
  • Confirm zero leaked labeled containers/volumes after teardown (cached images excepted).

Gate: container removed; the credential volume removed unless --keep-volume was explicitly chosen and recorded; no leaked ca.sandbox=1 objects remain.

Hard rules

  • MUST authenticate via an env-injected CLAUDE_CODE_OAUTH_TOKEN — NEVER a host bind of ~/.claude.
  • MUST install a PINNED @anthropic-ai/claude-code@<semver> with DISABLE_AUTOUPDATER=1; MUST NOT use @latest or an unpinned CLI.
  • MUST default --with-claude egress to offline or anthropic-only; MUST NOT give a token-bearing box wide-open egress.
  • MUST NEVER co-mount the token/credential volume with an untrusted-code run (a run that mounts the source volume at /work/repo) — buildClaudeRunArgs throws TokenCoMountRejectedError and that throw MUST NOT be bypassed.
  • MUST back HOME with a docker NAMED VOLUME (never a bind) so the .claude credential store persists across restart on the volume, not on the host.
  • MUST NOT give the box a host bind mount, the docker socket, or --privileged; read-only root, non-root, and cap-drop hold as for any sandbox.
  • MUST source the token from the approved store; MUST NOT log it, write it to a host-readable file, or pass it into any LLM prompt. Use a DUMMY token in tests.
  • MUST remove the credential volume on teardown unless --keep-volume is an explicit, recorded decision.
  • MUST treat the egress allowlist as EXPERIMENTAL (Spike C): for a token-bearing box, offline is the only GUARANTEED posture.

© arbiterForge, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/ca-sandbox/skills/sandbox-claude-inside of arbiterForge/codeArbiter.

Open the folder on GitHubat commit 9496cff

Compare with similar skills

Sandbox Claude Inside next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sandbox Claude Inside compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sandbox Claude Inside this skillarbiterForge/codeArbiter147—~2.4kAutomated safety check: PassAGPL-3.0
Uipath FunctionsUiPath/skills167—~3.6kAutomated safety check: NotesMIT
Xquik MCPXquik-dev/x-twitter-scraper2091 repos~997Automated safety check: PassMIT
MCP Dart Streamable HTTPleehack/mcp_dart116—~2kAutomated safety check: PassMIT
Unifapiunifapi-agent/agents587—~741Automated safety check: PassMIT
Durable Objectsbutterbase-ai/butterbase-skills534—~2.8kAutomated safety check: PassMIT

Similar skills

  • Uipath Functions

    UiPath/skills

    UiPath Coded Functions — deterministic Python or TypeScript/JavaScript units built with the uip function CLI (new -l py|ts|js, init, serve, run, pack, publish); the functions map in uipath.json…

    167 GitHub stars~3.6k tokensUpdated today
    AI & LLM EngineeringAuto-check: notes
  • Xquik MCP

    Xquik-dev/x-twitter-scraper

    Connect, verify, and troubleshoot Xquik's remote MCP server.

    209 GitHub starsUsed in 1 repo~997 tokens
    Backend & APIsAuto-check passed
  • MCP Dart Streamable HTTP

    leehack/mcp_dart

    A skill your agent uses when serving an MCP server over HTTP with mcpdart or connecting to a remote one: StreamableMcpServer setup, Host and Origin allowlists (DNS rebinding protection), CORS for…

    116 GitHub stars~2k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Unifapi

    unifapi-agent/agents

    A skill your agent uses when working with UnifAPI public-data APIs or the UnifAPI MCP server: connecting OAuth MCP clients, discovering operations, calling social/search/scrape/news APIs…

    587 GitHub stars~741 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Durable Objects

    butterbase-ai/butterbase-skills

    A skill your agent uses when building stateful per-key actors — chat rooms, multiplayer rooms, rate limiters, long-running agents, leaderboards — that need persistent in-memory + storage state…

    534 GitHub stars~2.8k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • E2a Setup

    tokencanopy/e2a

    A skill your agent uses when a user wants to connect or authorize the e2a MCP server, select or create an agent inbox, verify first-run readiness, or set up a custom email domain.

    192 GitHub stars~820 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from arbiterForge/codeArbiter

All 12 skills in this repo
  • Ca Adr

    arbiterForge/codeArbiter

    Record user-decided ADRs or inspect their health read-only. An agent skill from arbiterForge/codeArbiter.

    147 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Ca Conflict

    arbiterForge/codeArbiter

    Stop everything and surface a rule conflict — persona vs. An agent skill from arbiterForge/codeArbiter.

    147 GitHub stars~574 tokensUpdated today
    Auto-check passed
  • Ca Feature

    arbiterForge/codeArbiter

    Start a feature: brainstorm a spec, get it approved, then drive it test-first through the pipeline.

    147 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Ca Init

    arbiterForge/codeArbiter

    Opt this repo into codeArbiter — scaffold the root-level .codearbiter/ state store.

    147 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Ca Metrics

    arbiterForge/codeArbiter

    Read-only 3-metric governance glance — override rate, small-lane rate, sprint low-confidence ratio — each with a trend arrow vs.

    147 GitHub stars~966 tokensUpdated today
    Auto-check passed
  • Ca Override

    arbiterForge/codeArbiter

    Sanctioned, logged bypass of a gate or hard rule — one audit line, then proceed.

    147 GitHub stars~1.5k tokensUpdated today
    Auto-check passed

Questions about Sandbox Claude Inside

What does Sandbox Claude Inside do?

Run Claude Code INSIDE a ca-sandbox box (--with-claude). An agent skill from arbiterForge/codeArbiter. Sandbox Claude Inside is an agent skill from arbiterForge/codeArbiter. Run Claude Code INSIDE a ca-sandbox box (--with-claude).

When should I use Sandbox Claude Inside?

Sandbox Claude Inside fits situations like: wants an agent loop running against an isolated; ephemeral sandbox rather than the host.

How do I install Sandbox Claude Inside in Claude Code?

Run `npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a claude-code`. Or copy the skill folder (plugins/ca-sandbox/skills/sandbox-claude-inside in arbiterForge/codeArbiter) into .claude/skills/sandbox-claude-inside in your project. Claude Code loads it when a task matches its description.

How do I install Sandbox Claude Inside in Codex?

Run `npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a codex`. Or copy the skill folder (plugins/ca-sandbox/skills/sandbox-claude-inside in arbiterForge/codeArbiter) into .agents/skills/sandbox-claude-inside in your project. Codex loads it when a task matches its description.

Can I use Sandbox Claude Inside in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add arbiterForge/codeArbiter --skill sandbox-claude-inside -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sandbox-claude-inside, .gemini/skills/sandbox-claude-inside, .github/skills/sandbox-claude-inside and .opencode/skills/sandbox-claude-inside in your project.

What does Sandbox Claude Inside need to run?

Going by SKILL.md and its folder, Sandbox Claude Inside needs the command-line tools its instructions call (docker, claude and node) and credentials named CLAUDE_CODE_OAUTH_TOKEN. Our summary lists: Docker; A credential in CLAUDE_CODE_OAUTH_TOKEN.

Does Sandbox Claude Inside access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sandbox Claude Inside safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sandbox Claude Inside use?

Sandbox Claude Inside is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sandbox Claude Inside use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sandbox Claude Inside?

Skills that share tags, products or a category with Sandbox Claude Inside: Uipath Functions (UiPath/skills, 167 stars), Xquik MCP (Xquik-dev/x-twitter-scraper, 209 stars), MCP Dart Streamable HTTP (leehack/mcp_dart, 116 stars) and Unifapi (unifapi-agent/agents, 587 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sandbox Claude Inside?

arbiterForge (a GitHub organization) maintains it in arbiterForge/codeArbiter, which has 147 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 8, 2026.

Source: arbiterForge/codeArbiter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.