Agent skill

GitHub Outside Sandbox

by davidondrej in davidondrej/skills

Run Git and GitHub CLI commands on the host when sandboxing blocks Keychain auth, network access, or .git writes.

MITAuto-check passedDevelopment

Install GitHub Outside Sandbox

skills CLI
$ npx skills add davidondrej/skills --skill github-outside-sandbox -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davidondrej/skills github-outside-sandbox --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davidondrej/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ops-and-setup/github-outside-sandbox .claude/skills/github-outside-sandbox && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-outside-sandbox
GitHub stars
4.1k
Token cost
~331 tokens
SKILL.md length
157 words
Files
2
Skills in repo
51
Repo updated
First seen
Licence
MIT

At a glance

Run Git and GitHub CLI commands on the host when sandboxing blocks Keychain auth, network access, or .git writes.

  • Works in 7 steps: Start normally. Escalate only the… → If sandboxed gh auth status fails, rerun… → Run GitHub CLI network operations… → …
  • Repo/PR operations
  • Calls git and gh
  • Permission errors

What it does

GitHub Outside Sandbox is an agent skill from davidondrej/skills. Run Git and GitHub CLI commands on the host when sandboxing blocks Keychain auth, network access, or .git writes. Use for gh auth, repo/PR operations, index.lock, or permission errors; covers execution context only.

Its SKILL.md is about 330 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Git workflow. It works with GitHub and Git. The repository describes itself as: access to david ondrej's personal agent skills. The licence is MIT.

When your agent uses it

  • Repo/PR operations
  • Permission errors
  • Covers execution context only

Example prompts

  • “/github-outside-sandbox”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Start normally. Escalate only the blocked command and only within the user's authorization.
  2. If sandboxed gh auth status fails, rerun it outside the sandbox before claiming authentication is broken. Never expose or copy tokens.
  3. Run GitHub CLI network operations outside the sandbox when required: gh repo ..., gh pr ..., and related gh commands.
  4. Run Git writes outside the sandbox when .git is outside writable roots or errors mention index.lock or Operation not permitted: git add…
  5. Use the harness's official host-execution mechanism. In Codex, set sandbox_permissions: "require_escalated", give a concrete…
  6. Never use shell wrappers, credential copying, or broad approval prefixes to bypass the sandbox.
  7. Verify from the host context with git status -sb, git remote -v, and the relevant gh ... view command. Ask the user to authenticate only…

What it can do on your machine

Read from SKILL.md and the folder at commit ea32e5f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub Outside Sandbox loads about 331 tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 157 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~331

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davidondrej/skills at commit ea32e5f, republished under its MIT licence (© davidondrej). 157 words, ~331 tokens.

Download SKILL.mdSave it as .claude/skills/github-outside-sandbox/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
github-outside-sandbox
description
Run Git and GitHub CLI commands on the host when sandboxing blocks Keychain auth, network access, or .git writes. Use for gh auth, repo/PR operations, index.lock, or permission errors; covers execution context only.

GitHub Outside Sandbox

  1. Start normally. Escalate only the blocked command and only within the user's authorization.
  2. If sandboxed gh auth status fails, rerun it outside the sandbox before claiming authentication is broken. Never expose or copy tokens.
  3. Run GitHub CLI network operations outside the sandbox when required: gh repo ..., gh pr ..., and related gh commands.
  4. Run Git writes outside the sandbox when .git is outside writable roots or errors mention index.lock or Operation not permitted: git add, git commit, and git push.
  5. Use the harness's official host-execution mechanism. In Codex, set sandbox_permissions: "require_escalated", give a concrete justification, and use only a narrow safe prefix_rule when appropriate.
  6. Never use shell wrappers, credential copying, or broad approval prefixes to bypass the sandbox.
  7. Verify from the host context with git status -sb, git remote -v, and the relevant gh ... view command. Ask the user to authenticate only if the host-context check also fails.

© davidondrej, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/ops-and-setup/github-outside-sandbox of davidondrej/skills.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit ea32e5f

Compare with similar skills

GitHub Outside Sandbox next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Outside Sandbox compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Outside Sandbox this skilldavidondrej/skills4.1k—~331Automated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Release Bumpjamiepine/voicebox57k—~1.1kAutomated safety check: PassMIT
Creating Description For Gh PRredis/jedis12k—~838Automated safety check: PassMIT
Create Pull Request with Work Item IDmakeplane/plane60k—~824Automated safety check: PassAGPL-3.0

Similar skills

  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Release Bump

    jamiepine/voicebox

    Ends a release cycle by moving the Unreleased changelog notes under a dated version heading, bumping version files with bumpversion and tagging the commit.

    57k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Generate a clear, concise GitHub PR title and description from the diff between two local git branches, and save it to prDescription.md in the repo root.

    12k GitHub stars~838 tokensUpdated today
    DevelopmentAuto-check passed
  • Opens a pull request for the current branch using the repo's template, a work item ID in the title and a description filled in from the actual diff.

    60k GitHub stars~824 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • React Router Pull Request Creator

    remix-run/react-router

    Packages finished React Router work into a draft pull request: branch, commit, push, a written PR body and the right GitHub labels.

    57k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed

More from davidondrej/skills

All 51 skills in this repo
  • Nagent

    davidondrej/skills

    Launch a new bb worker thread with the right project, model, worktree, and task brief.

    4.1k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check: notes
  • Browser Harness

    davidondrej/skills

    Direct browser control via CDP. An agent skill from davidondrej/skills.

    4.1k GitHub starsUsed in 2 repos~3k tokens
    Auto-check passed
  • Persistent Localhost

    davidondrej/skills

    Manage persistent dev servers, APIs, and other local processes on a port using macOS LaunchAgents.

    4.1k GitHub stars~618 tokensUpdated yesterday
    Auto-check passed
  • Reset Cursor Acp

    davidondrej/skills

    Reset a stuck Cursor ACP thread in <chat-system and reload its configuration.

    4.1k GitHub stars~728 tokensUpdated yesterday
    Auto-check passed
  • Anti Sleep

    davidondrej/skills

    Keep a Mac awake for a set duration or while a process runs.

    4.1k GitHub stars~640 tokensUpdated yesterday
    Auto-check: warnings
  • Bb CLI

    davidondrej/skills

    Use this when controlling bb. An agent skill from davidondrej/skills.

    4.1k GitHub stars~823 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about GitHub Outside Sandbox

What does GitHub Outside Sandbox do?

Run Git and GitHub CLI commands on the host when sandboxing blocks Keychain auth, network access, or .git writes. GitHub Outside Sandbox is an agent skill from davidondrej/skills.git writes.

When should I use GitHub Outside Sandbox?

GitHub Outside Sandbox fits situations like: repo/PR operations; permission errors; covers execution context only.

How do I install GitHub Outside Sandbox in Claude Code?

Run `npx skills add davidondrej/skills --skill github-outside-sandbox -a claude-code`. Or copy the skill folder (skills/ops-and-setup/github-outside-sandbox in davidondrej/skills) into .claude/skills/github-outside-sandbox in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Outside Sandbox in Codex?

Run `npx skills add davidondrej/skills --skill github-outside-sandbox -a codex`. Or copy the skill folder (skills/ops-and-setup/github-outside-sandbox in davidondrej/skills) into .agents/skills/github-outside-sandbox in your project. Codex loads it when a task matches its description.

Can I use GitHub Outside Sandbox in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davidondrej/skills --skill github-outside-sandbox -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-outside-sandbox, .gemini/skills/github-outside-sandbox, .github/skills/github-outside-sandbox and .opencode/skills/github-outside-sandbox in your project.

What does GitHub Outside Sandbox need to run?

Going by SKILL.md and its folder, GitHub Outside Sandbox needs the command-line tools its instructions call (git and gh).

Does GitHub Outside Sandbox access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is GitHub Outside Sandbox safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitHub Outside Sandbox use?

GitHub Outside Sandbox is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Outside Sandbox use?

About 331 tokens (SKILL.md is roughly 1.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitHub Outside Sandbox?

Skills that share tags, products or a category with GitHub Outside Sandbox: Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), Create Pull Request (cline/cline, 70k stars), Release Bump (jamiepine/voicebox, 57k stars) and Creating Description For Gh PR (redis/jedis, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Outside Sandbox?

davidondrej (a GitHub user) maintains it in davidondrej/skills, which has 4,105 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 6, 2026.

Source: davidondrej/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.