Agent skill

Dormice

by BitMiracle-AI in BitMiracle-AI/Dormice

Operate Dormice self-hosted agent sandboxes — acquire a sandbox, run commands, move files, tune lifecycle policy — through the official E2B SDKs, the native HTTP API and SDK, or the dor CLI.

Apache-2.0Auto-check: notesBackend & APIs

Install Dormice

skills CLI
$ npx skills add BitMiracle-AI/Dormice --skill dormice -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BitMiracle-AI/Dormice dormice --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BitMiracle-AI/Dormice.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dormice .claude/skills/dormice && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dormice
GitHub stars
1.4k
Token cost
~2.7k tokens
SKILL.md length
1,100 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Operate Dormice self-hosted agent sandboxes — acquire a sandbox, run commands, move files, tune lifecycle policy — through the official E2B SDKs, the native HTTP API and SDK, or the dor CLI.

  • Connecting to a Dormice server
  • SKILL.md covers Connecting, Pick an entry path, Official E2B SDKs — change two… and Native API — one POST route…, plus 5 more sections
  • Calls curl, pnpm and apt; needs DORMICE_API_TOKEN
  • Running untrusted

What it does

Dormice is an agent skill from BitMiracle-AI/Dormice. Operate Dormice self-hosted agent sandboxes — acquire a sandbox, run commands, move files, tune lifecycle policy — through the official E2B SDKs, the native HTTP API and SDK, or the dor CLI. Use when connecting to a Dormice server, running untrusted or AI-generated code in a sandbox, giving an agent a persistent workspace, or migrating an application off E2B.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering REST APIs. It works with Docker. The repository describes itself as: The SQLite of agent sandboxes — self-hosted, E2B-compatible. One machine, sandboxes that live forever, idle costs nothing. The licence is Apache-2.0.

When your agent uses it

  • Connecting to a Dormice server
  • Running untrusted
  • AI-generated code in a sandbox
  • Giving an agent a persistent workspace

Example prompts

  • “/dormice”

Requirements

  • Python 3
  • A credential in DORMICE_API_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 899bf7f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • pnpm
    • apt

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DORMICE_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dormice loads about 2.7k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 1,100 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:216
    ling system packages (E2B's convention; `sudo apt install` works,

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BitMiracle-AI/Dormice at commit 899bf7f, republished under its Apache-2.0 licence (© BitMiracle-AI). 1,100 words, ~2,686 tokens.

Download SKILL.mdSave it as .claude/skills/dormice/SKILL.md (or your agent's skills folder).
name
dormice
description
Operate Dormice self-hosted agent sandboxes — acquire a sandbox, run commands, move files, tune lifecycle policy — through the official E2B SDKs, the native HTTP API and SDK, or the dor CLI. Use when connecting to a Dormice server, running untrusted or AI-generated code in a sandbox, giving an agent a persistent workspace, or migrating an application off E2B.

Dormice

Dormice is a self-hosted sandbox platform: a gateway (the front door — console, API keys, fleet settings) and one or more daemons (the nodes that run the sandboxes; a single machine runs both), and sandboxes that are permanent — idle ones cool down (active → frozen → stopped → archived) instead of being destroyed, and any acquire brings them back. Two facts drive every workflow below:

  • acquireSandbox(name) is the entire mental model. Idempotent — the name is a unique address that never errors as a duplicate: the same name always returns the same sandbox, whatever state it was in. No sandbox → create; frozen → wake (~50 ms); stopped → start; archived → restore. Only acquireSandbox creates — other verbs answer 404 for an unknown name.
  • The disk, not the container, is the sandbox's body. Files survive freezes, stops, daemon restarts, and host reboots. Only destroySandbox loses data.

Connecting

Two doors, both bound to 127.0.0.1 only: the gateway on 3677 (the console, templates, API keys, settings, and every per-sandbox verb, which it forwards to the node) and the daemon on 3676 (the sandbox verbs plus the list and observation verbs the gateway does not answer yet). On the server itself use those addresses directly; from another machine the operator has either an SSH tunnel (ssh -L 3677:127.0.0.1:3677 -L 3676:127.0.0.1:3676 root@host) or a reverse-proxy domain in front of the gateway (then use https://their-domain). Auth is one API token (created by the installer, hex): ask the user for the endpoint and token, conventionally held in DORMICE_ENDPOINT / DORMICE_API_TOKEN. API keys minted in the console (or with dor apikey create <name>) open the gateway wherever the token does — same variables, revocable per client — except the verbs that configure the fleet (keys, settings, templates, domains), which require the token (keys cannot manage keys); a daemon knows only the token.

Pick an entry path

PathWhen
Official e2b SDK (npm / PyPI, unmodified)Default for application code today, and for anything already written against E2B
Native HTTP API (curl)Shell scripts, quick checks, any language without an SDK
@dormice/sdk (TypeScript)Native semantics with types; first npm release is queued — inside the repo, pnpm build produces it
dor CLIOperator work in a terminal: list, exec, push/pull, rebuild, doctor

Official E2B SDKs — change two URLs

The daemon speaks the E2B protocol on /e2b/api (control plane) and /e2b/envd (in-sandbox). Prefix the token with e2b_:

ts
import { Sandbox } from 'e2b';

const sbx = await Sandbox.create({
  apiKey: `e2b_${process.env.DORMICE_API_TOKEN}`,
  apiUrl: 'http://127.0.0.1:3677/e2b/api',
  sandboxUrl: 'http://127.0.0.1:3677/e2b/envd',
});
await sbx.commands.run('echo hello');
python
import os
from e2b import Sandbox

sandbox = Sandbox.create(
    api_key=f"e2b_{os.environ['DORMICE_API_TOKEN']}",
    api_url="http://127.0.0.1:3677/e2b/api",
    sandbox_url="http://127.0.0.1:3677/e2b/envd",
)
sandbox.commands.run("echo hello")

Sandbox.create makes a fresh sandbox each time (faithful E2B semantics). To get Dormice's idempotent acquire through the E2B surface, pass metadata: { name: 'my-project' } — the same name then always returns the same sandbox with its files intact. E2B timeoutMs deadlines are real: at the deadline the sandbox is killed, or parked with lifecycle: { onTimeout: 'pause' } and revived by connect.

Native API — one POST route per verb

Every operation is POST /<sdkMethodName> with a JSON body and Authorization: Bearer <token>; every non-2xx body is { "message": "..." }. Core loop with the SDK:

ts
import { Dormice } from '@dormice/sdk';

const client = new Dormice({
  endpoint: 'http://127.0.0.1:3677',
  token: process.env.DORMICE_API_TOKEN!,
});

await client.acquireSandbox('my-agent', { policy: { stopAfterSeconds: null } });

const result = await client.execCommand('my-agent', 'python3 -c "print(6 * 7)"');
console.log(result.exitCode, result.stdout); // 0 42

await client.writeFiles('my-agent', [
  { path: 'notes.txt', content: 'survives freeze and stop' },
]);

await client.destroySandbox('my-agent'); // the only verb that loses data

The same loop in curl:

sh
curl -X POST http://127.0.0.1:3677/acquireSandbox \
  -H "Authorization: Bearer $DORMICE_API_TOKEN" \
  -H "content-type: application/json" \
  -d '{"name": "my-agent"}'

Verbs: acquireSandbox (optionally with metadata — string-to-string labels stored at creation for grouping/filtering), updatePolicy (patch an existing sandbox's lifecycle policy in place — no wake, no destroy), updateMetadata (replace an existing sandbox's label set wholesale, {} clears — same no-wake manners), listSandboxes, execCommand, writeFiles / writeFile, readFile / readFiles, rebuildSandbox (fresh container, /home/user kept), destroySandbox, registerTemplate / listTemplates / removeTemplate (at the gateway; nodes learn a template at their next check-in), createApiKey / listApiKeys / updateApiKey / revokeApiKey (at the gateway: revocable peers of the API token with optional expiry and a reversible disable switch; the create response shows the key once, never again; these four verbs accept only the token), getHostMetrics (one machine's reading; at the gateway name the node with nodeId, a fleet of one needs none), getSandboxMetrics / listSandboxMetrics (live resource samples; never wake anything), listSandboxImages (who still runs an old template image) — the lists at the gateway are every node's, with silent naming a node it could not include — getFleetMetrics / getFleetStateHistory (the fleet's sums and its census over time, answered by the gateway from the nodes' check-ins), getConfig / updateSettings (the fleet's settings at the gateway, secrets redacted; applied by every node at its next check-in), getIngress / setIngress (bind domains on the gateway's managed reverse proxy), listNodes (every node and what it last reported). execCommand takes { name, command, timeoutSeconds?, cwd?, env? } and returns { exitCode, stdout, stderr, ... } — a non-zero exit code is a result, not an HTTP error. When a sandbox is coming back from S3, acquireSandbox returns { status: 'restoring', progress } immediately; poll it until the status flips to ready.

Show full SKILL.md (372 more words)Show less

CLI

sh
dor sandbox ls                        # every sandbox, with lifecycle state
dor sandbox exec my-agent 'uname -r'  # exit code passes through
dor sandbox push my-agent ./data.csv  # → /home/user/data.csv
dor sandbox pull my-agent notes.txt
dor sandbox rebuild my-agent          # fresh container, /home/user kept
dor sandbox meta my-agent app=crawler # replace labels (no args = show)
dor sandbox destroy my-agent
dor apikey create ci                  # mint a revocable key (printed once)
dor doctor                            # can this machine run sandboxes?

Connects via DORMICE_ENDPOINT and DORMICE_API_TOKEN.

Files

Native file verbs move content as base64 inside JSON, capped at 16 MiB per file (batches 48 MiB) with honest refusals — never a truncated file. Paths are absolute or relative to /home/user; parent directories are created. Past the cap: download from inside the sandbox (execCommand with curl, in the stock image), or use the E2B files surface (files.read/write stream uncapped; uploadUrl() / downloadUrl() mint signed URLs).

Lifecycle policy — three knobs

Set at creation (overrides while acquiring an existing sandbox are not applied — change an existing sandbox's policy with updatePolicy, a patch that never wakes and never resets the idle clock); all count seconds since last activity, ordering freeze ≤ stop ≤ archive:

KnobDefaultnull means
freezeAfterSeconds10 minutes— (freezing is always on)
stopAfterSeconds3 daysnever stop
archiveAfterSeconds7 days when S3 is configured, else nevernever archive

The pattern Dormice was built for — one permanent sandbox per agent:

ts
await client.acquireSandbox(`agent-${userId}`, {
  policy: { stopAfterSeconds: null },
});

It parks at frozen (~5 MiB resident) and wakes in ~50 ms — never a cold start; frozen processes suspend mid-flight and resume exactly where they were. Commands and file operations reset the idle clock; observation (listSandboxes, metrics) never wakes or warms anything. A background process does not keep its sandbox warm — a resident sandbox means "ready whenever the agent returns", not an unattended 24×7 workload.

Gotchas

  • Keep the API token hexadecimal. The Python E2B SDK validates e2b_[0-9a-f]+ client-side; other characters fail before any request.
  • Bring a patient HTTP client. execCommand sends response headers only when the command finishes — legally hours later. Node's undici ships a hidden ~5-minute header timeout; disable it (the native SDK already does) or long commands die at exactly 300 s with an error that looks like the server's fault.
  • Sandboxes run untrusted code, contained. Everything runs as a non-root user (uid 1000) inside gVisor, with passwordless sudo for installing system packages (E2B's convention; sudo apt install works, but survives only until the next cold wake — persistent tooling belongs in a template or under /home/user). The stock image ships Ubuntu 24.04, Python 3.12, Node 24, git, ripgrep, and jq.

Learn more

Docs (served as /llms.txt, /llms-full.txt, and per-page .md on the project site; sources on GitHub): quickstart · lifecycle · E2B SDKs · HTTP API · files · resident agents

© BitMiracle-AI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/dormice of BitMiracle-AI/Dormice.

Open the folder on GitHubat commit 899bf7f

Compare with similar skills

Dormice next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dormice compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dormice this skillBitMiracle-AI/Dormice1.4k—~2.7kAutomated safety check: NotesApache-2.0
Cuopt Server API PythonNVIDIA/skills3.5k—~1.5kAutomated safety check: PassApache-2.0
Model Deploymentmajiayu000/claude-skill-registry6661 repos~2.1kAutomated safety check: PassMIT
RuView CLI, API and WASMruvnet/RuView97k—~1.2kAutomated safety check: NotesMIT
Dr Jskilljdubois/dr-jskill342—~4.6kAutomated safety check: NotesApache-2.0
Vss Deploy Detection Tracking 2DNVIDIA/skills3.5k1 repos~4.5kAutomated safety check: PassApache-2.0

Similar skills

  • Official

    cuOpt REST server — start server, endpoints, Python/curl client examples.

    3.5k GitHub stars~1.5k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Model Deployment

    majiayu000/claude-skill-registry

    Deploy trained machine learning models as production-ready services using REST APIs, containers, serverless functions, and orchestration platforms.

    666 GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed
  • Covers the RuView `wifi-densepose` command line binary, its Axum REST API and the WebAssembly builds for browsers and ESP32, for embedding or scripting RuView.

    97k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Dr Jskill

    jdubois/dr-jskill

    Creates Java + Spring Boot projects: Web applications, full-stack apps with Vue.js or Angular or React or vanilla JS, PostgreSQL, REST APIs, and Docker.

    342 GitHub stars~4.6k tokensUpdated 8 days ago
    Backend & APIsAuto-check: notes
  • Official

    A skill your agent uses when the user wants to deploy, run, debug, tear down, or call the REST API of the RTVI-CV 2D detection / tracking microservice.

    3.5k GitHub starsUsed in 1 repo~4.5k tokens
    Backend & APIsAuto-check passed
  • Spring Boot Skill

    piomin/sample-spring-modulith

    Build Spring Boot 4.x applications following the best practices.

    144 GitHub stars~668 tokensUpdated 13 days ago
    Backend & APIsAuto-check passed

Works with

Questions about Dormice

What does Dormice do?

Operate Dormice self-hosted agent sandboxes — acquire a sandbox, run commands, move files, tune lifecycle policy — through the official E2B SDKs, the native HTTP API and SDK, or the dor CLI. Dormice is an agent skill from BitMiracle-AI/Dormice. Operate Dormice self-hosted agent sandboxes — acquire a sandbox, run commands, move files, tune lifecycle policy — through the official E2B SDKs, the native HTTP API and SDK, or the dor CLI.

When should I use Dormice?

Dormice fits situations like: connecting to a Dormice server; running untrusted; AI-generated code in a sandbox; giving an agent a persistent workspace.

How do I install Dormice in Claude Code?

Run `npx skills add BitMiracle-AI/Dormice --skill dormice -a claude-code`. Or copy the skill folder (skills/dormice in BitMiracle-AI/Dormice) into .claude/skills/dormice in your project. Claude Code loads it when a task matches its description.

How do I install Dormice in Codex?

Run `npx skills add BitMiracle-AI/Dormice --skill dormice -a codex`. Or copy the skill folder (skills/dormice in BitMiracle-AI/Dormice) into .agents/skills/dormice in your project. Codex loads it when a task matches its description.

Can I use Dormice in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BitMiracle-AI/Dormice --skill dormice -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dormice, .gemini/skills/dormice, .github/skills/dormice and .opencode/skills/dormice in your project.

What does Dormice need to run?

Going by SKILL.md and its folder, Dormice needs the command-line tools its instructions call (curl, pnpm and apt) and credentials named DORMICE_API_TOKEN. Our summary lists: Python 3; A credential in DORMICE_API_TOKEN.

Does Dormice access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dormice safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Dormice use?

Dormice is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dormice use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dormice?

Skills that share tags, products or a category with Dormice: Cuopt Server API Python (NVIDIA/skills, 3.5k stars), Model Deployment (majiayu000/claude-skill-registry, 666 stars), RuView CLI, API and WASM (ruvnet/RuView, 97k stars) and Dr Jskill (jdubois/dr-jskill, 342 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dormice?

BitMiracle-AI (a GitHub organization) maintains it in BitMiracle-AI/Dormice, which has 1,444 GitHub stars. The repository was last updated on October 1, 2026.

Source: BitMiracle-AI/Dormice on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.