Official agent skill

Sandbox Migrate To Next

by cloudflare in cloudflare/skills

Migrate Cloudflare Sandbox apps from stable @cloudflare/sandbox to @cloudflare/sandbox@next (SDK 1.0 preview).

OfficialApache-2.0Auto-check passed

Install Sandbox Migrate To Next

skills CLI
$ npx skills add cloudflare/skills --skill sandbox-migrate-to-next -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cloudflare/skills sandbox-migrate-to-next --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cloudflare/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sandbox-migrate-to-next .claude/skills/sandbox-migrate-to-next && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sandbox-migrate-to-next
GitHub stars
3k
Used in
3 other repos
Token cost
~2k tokens
SKILL.md length
622 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

Migrate Cloudflare Sandbox apps from stable @cloudflare/sandbox to @cloudflare/sandbox@next (SDK 1.0 preview).

  • Works in 5 steps: Review hard rules and the replacement map → Audit the codebase; list hits and target… → Clarify with the user (cutover, bridge,… → …
  • SKILL.md covers Workflow, Hard rules, Replacement map and Audit, plus 4 more sections
  • Calls rg, npm and npx

What it does

Sandbox Migrate To Next is an agent skill from cloudflare/skills, published by the product's own GitHub organization. Migrate Cloudflare Sandbox apps from stable @cloudflare/sandbox to @cloudflare/sandbox@next (SDK 1.0 preview). Use sandbox-next for apps already on the preview.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Cloudflare. The repository describes itself as: Skills for teaching agents how to build on Cloudflare. The licence is Apache-2.0.

Example prompts

  • “/sandbox-migrate-to-next”

Requirements

  • Python 3
  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Review hard rules and the replacement map
  2. Audit the codebase; list hits and target shapes
  3. Clarify with the user (cutover, bridge, Python image, unclear sites)
  4. Upgrade package, image, and code
  5. Validate

What it can do on your machine

Read from SKILL.md and the folder at commit a18ffe2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sandbox Migrate To Next loads about 2k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 622 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cloudflare/skills at commit a18ffe2, republished under its Apache-2.0 licence (© cloudflare). 622 words, ~1,967 tokens.

Download SKILL.mdSave it as .claude/skills/sandbox-migrate-to-next/SKILL.md (or your agent's skills folder).
name
sandbox-migrate-to-next
description
Migrate Cloudflare Sandbox apps from stable @cloudflare/sandbox to @cloudflare/sandbox@next (SDK 1.0 preview). Use sandbox-next for apps already on the preview.

Migrate stable → Sandbox SDK 1.0 preview (@next)

Perform the port. Follow the steps in order. Depth lives in docs—fetch the linked page when a step needs detail.

Human guide: Migrate · 1.0 preview

New projects should start on @next (sandbox-next), not this skill. Day-to-day stable work → sandbox-stable. Deprecated-API cleanup without moving to @next → 2026 deprecation guide first if needed.

Existing apps should migrate when you can, so you are ready when 1.0 becomes the stable release. Do not force production cutover without the user agreeing.

Prefer installed @next types and the migrate doc over memory.

Workflow

  1. Review hard rules and the replacement map
  2. Audit the codebase; list hits and target shapes
  3. Clarify with the user (cutover, bridge, Python image, unclear sites)
  4. Upgrade package, image, and code
  5. Validate

Stop after any step that needs a user decision.

Hard rules

  • Worker package and container image must be the same @next line.
  • Production cutover uses immediate container rollout. Stable and @next control protocols are incompatible both ways; gradual rollout leaves a broken mixed window. In-flight container work can stop.
  • After cutover, await sandbox.exec(...) means process started, not command finished.
  • Argv is as-is (no implicit shell). Shell syntax needs an explicit shell binary.
  • Process handles have no stdin → terminals for interactive input.
  • Observation timeout / AbortSignal cancel the wait only, not the process.
  • No single retry loop for every error.
  • Do not invent APIs (gitCheckout on core, process stdin, string-exec completion helper).
  • Self-deployed bridge stays on stable (not part of the preview line yet).

Replacement map

Stable@next
SANDBOX_TRANSPORT / transport / setTransportRemove — RPC only
await sandbox.exec("cmd") → buffered resultawait sandbox.exec(argv) → handle, then output / waits
execStream / startProcessSame handle: logs, waitFor*, kill
Default / named sessionsGone — cwd/env per launch, or one shell script
sandbox.terminal(request) / session terminalcreateTerminal + terminal.connect(request)
xterm sessionIdterminalId
Interpreter methods on SandboxwithInterpreter → sandbox.interpreter.*
gitCheckoutargv git via exec
String kill signalsNumeric only
Files, mounts, backups, ports, tunnels, proxyToSandboxMostly unchanged (ignore session/transport bits on stable pages)

Depth: Migrate · after port, day-to-day → sandbox-next

Audit

sh
rg 'SANDBOX_TRANSPORT|transport:|setTransport|enableDefaultSession|createSession|getSession|deleteSession|execStream\(|startProcess\(|killProcess\(|sandbox\.terminal\(|sessionId|gitCheckout\(|SandboxTransport|ExecutionSession'

Also: string exec(, cd then a later exec, bare createCodeContext / runCode on Sandbox.

Clarify (ask when needed)

  • OK to cut production with --containers-rollout=immediate (live processes/terminals/streams may stop)?
  • Self-deployed bridge? Leave on stable.
  • Python interpreter → -python image variant?
  • Call sites not covered by the map?
Show full SKILL.md (242 more words)Show less

Upgrade

Package and image
sh
npm install @cloudflare/sandbox@next
dockerfile
FROM cloudflare/sandbox:next
# Python: cloudflare/sandbox:next-python

Same prerelease tag on Worker and image when not on floating next.

Code by area

Apply replacements from the map. For each area, implement from the doc—not from stable habits:

AreaDoc
Commands / handles / waitsProcesses · Processes API
cwd / env / secretsEnvironment · Outbound traffic
Drop sessionsMigrate · Lifecycle
TerminalsTerminals
InterpreterInterpreter
ErrorsErrors
Durable job across requestsProcess execution — lifetime / durability

Commands (shape):

ts
// Before (stable)
const result = await sandbox.exec("npm test");

// After (@next)
const process = await sandbox.exec(["/bin/bash", "-lc", "npm test"]);
const result = await process.output({ encoding: "utf8" });
ts
const server = await sandbox.exec(["/bin/bash", "-lc", "npm run dev"], {
  cwd: "/workspace/app",
});
await server.waitForPort(3000, { timeout: 60_000 });
await server.kill(); // numeric; default 15

Terminals (shape):

ts
const terminal = await sandbox.createTerminal({ command: ["bash"], cwd: "/workspace" });
const t = await sandbox.getTerminal(terminal.id);
if (!t) return new Response("terminal gone", { status: 410 });
return t.connect(request, { cursor, cols, rows });

Interpreter (shape):

ts
import { Sandbox as BaseSandbox } from "@cloudflare/sandbox";
import { withInterpreter } from "@cloudflare/sandbox/interpreter";

export class Sandbox extends BaseSandbox<Env> {
  interpreter = withInterpreter(this);
}

Git (shape):

ts
const clone = await sandbox.exec(
  ["git", "clone", "--depth", "1", "--", repoUrl, "/workspace/repo"],
  { cwd: "/workspace" },
);
const result = await clone.output({ encoding: "utf8" });

Delete transport settings entirely. Remove session APIs. Isolate users with separate sandbox IDs.

Deploy cutover

Staging/branch first. Production is one deploy of matching Worker + image:

sh
npx wrangler deploy --containers-rollout=immediate

Leave rollout_active_grace_period at default 0 (or set 0 if raised). After cutover, pre-deploy process/terminal IDs are invalid. Details: Migrate · Container rollouts

Validate

  1. Lockfile + Dockerfile on the same @next line
  2. Typecheck against @next
  3. Smoke argv exec + output({ encoding: "utf8" })
  4. Smoke long process / terminal / interpreter if used
  5. Errors distinguished: unavailable / interrupted-RPC / stale / local wait
  6. No live secrets in sandbox env
  7. Grep again for removed APIs
  8. Production used --containers-rollout=immediate

Then day-to-day work uses sandbox-next.

Red flags — stop and fix

  • Mixing @next Worker with stable image (or reverse)
  • Gradual container rollout for this cutover
  • Treating await exec as command completion
  • Assuming cd / exports persist across exec calls
  • One retry wrapper for every error
  • Inventing gitCheckout, process stdin, or undocumented APIs
  • Keeping pre-cutover process/terminal IDs after deploy
  • Forcing production cutover without user agreement
  • Putting live secrets in setEnvVars / launch env

© cloudflare, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sandbox-migrate-to-next of cloudflare/skills.

Open the folder on GitHubat commit a18ffe2

Used in 3 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in cloudflare/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Sandbox Migrate To Next next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sandbox Migrate To Next compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sandbox Migrate To Next this skillcloudflare/skills3k3 repos~2kAutomated safety check: PassApache-2.0
Cloudflare Browser Renderingcloudflare/moltworker10k—~742Automated safety check: PassApache-2.0
Star Office UI Setupringhyacinth/Star-Office-UI7.5k—~1.3kAutomated safety check: PassMIT
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Golivemikehasa/golive-skill1.2k—~13kAutomated safety check: NotesMIT

Similar skills

  • Cloudflare Browser Rendering

    cloudflare/moltworker

    Official

    Drives headless Chrome through Cloudflare Browser Rendering over a CDP WebSocket to take screenshots, navigate and scrape pages, and record multi-page videos.

    10k GitHub stars~742 tokensUpdated 5 mo ago
    Productivity & AutomationAuto-check passed
  • Star Office UI Setup

    ringhyacinth/Star-Office-UI

    Sets up Star Office UI, a pixel-art office dashboard that shows AI agent states, lets other agents join and can be opened from a phone or a public link.

    7.5k GitHub stars~1.3k tokensUpdated 7 mo ago
    Agent WorkflowsAuto-check passed
  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Golive

    mikehasa/golive-skill

    Take an agent-written app from repo to live production on the user's OWN accounts, with providers they choose (hosting, database, auth, payments, email, domain/DNS).

    1.2k GitHub stars~13k tokensUpdated 5 days ago
    Backend & APIsAuto-check: notes
  • Build, review, debug, reverse-engineer data sources for, and package FongMi/WebHome custom homepage single-file HTML.

    1.7k GitHub stars~3.8k tokensUpdated yesterday
    Frontend & DesignAuto-check passed

More from cloudflare/skills

All 16 skills in this repo
  • Turnstile Spin

    cloudflare/skills

    Official

    Set up, repair, or migrate to Cloudflare Turnstile bot verification in an existing frontend and backend, including server-side Siteverify.

    3k GitHub starsUsed in 4 repos~7.2k tokens
    Auto-check: notes
  • Nextjs On Cloudflare

    cloudflare/skills

    Official

    Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext.

    3k GitHub starsUsed in 2 repos~678 tokens
    Auto-check passed
  • Agents SDK

    cloudflare/skills

    Official

    Build, debug, or review Cloudflare Agents SDK applications using the agents package.

    3k GitHub starsUsed in 2 repos~3k tokens
    Auto-check passed
  • Durable Objects

    cloudflare/skills

    Official

    Build, debug, or review Cloudflare Durable Objects code for persistent state and coordination.

    3k GitHub starsUsed in 2 repos~1.5k tokens
    Auto-check passed
  • Sandbox Next

    cloudflare/skills

    Official

    Build or maintain Cloudflare Sandbox apps on @cloudflare/sandbox@next (SDK 1.0 preview).

    3k GitHub starsUsed in 2 repos~1.7k tokens
    Auto-check passed
  • Cloudflare One Migrations

    cloudflare/skills

    Official

    Assess and plan migrations from existing VPN, SWG, or SASE platforms to Cloudflare One, including policy mapping, parity gaps, and rollout.

    3k GitHub starsUsed in 6 repos~3.1k tokens
    Auto-check passed

Works with

Questions about Sandbox Migrate To Next

What does Sandbox Migrate To Next do?

Migrate Cloudflare Sandbox apps from stable @cloudflare/sandbox to @cloudflare/sandbox@next (SDK 1.0 preview). Sandbox Migrate To Next is an agent skill from cloudflare/skills, published by the product's own GitHub organization.0 preview).

How do I install Sandbox Migrate To Next in Claude Code?

Run `npx skills add cloudflare/skills --skill sandbox-migrate-to-next -a claude-code`. Or copy the skill folder (skills/sandbox-migrate-to-next in cloudflare/skills) into .claude/skills/sandbox-migrate-to-next in your project. Claude Code loads it when a task matches its description.

How do I install Sandbox Migrate To Next in Codex?

Run `npx skills add cloudflare/skills --skill sandbox-migrate-to-next -a codex`. Or copy the skill folder (skills/sandbox-migrate-to-next in cloudflare/skills) into .agents/skills/sandbox-migrate-to-next in your project. Codex loads it when a task matches its description.

Can I use Sandbox Migrate To Next in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudflare/skills --skill sandbox-migrate-to-next -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sandbox-migrate-to-next, .gemini/skills/sandbox-migrate-to-next, .github/skills/sandbox-migrate-to-next and .opencode/skills/sandbox-migrate-to-next in your project.

What does Sandbox Migrate To Next need to run?

Going by SKILL.md and its folder, Sandbox Migrate To Next needs the command-line tools its instructions call (rg, npm and npx). Our summary lists: Python 3; Node.js.

Does Sandbox Migrate To Next access the network?

SKILL.md names 1 domain. As links in the text: developers.cloudflare.com. This is read from the text; nothing was executed.

Is Sandbox Migrate To Next safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sandbox Migrate To Next use?

Sandbox Migrate To Next is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sandbox Migrate To Next use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sandbox Migrate To Next?

Skills that share tags, products or a category with Sandbox Migrate To Next: Cloudflare Browser Rendering (cloudflare/moltworker, 10k stars), Star Office UI Setup (ringhyacinth/Star-Office-UI, 7.5k stars), Cloudflare (hodgef/apiker, 127 stars) and Webhome Extension Builder (webhtv/webhtv, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sandbox Migrate To Next?

cloudflare (a GitHub organization, an official publisher) maintains it in cloudflare/skills, which has 3,016 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 9, 2026.

Source: cloudflare/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.