Configuring Horizon
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Operate exe.dev persistent VMs via SSH/HTTPS for safe code execution and file operations.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sandbox-exe-dev -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install disler/inkwell-agent-sandboxes-and-software-factory sandbox-exe-dev --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/disler/inkwell-agent-sandboxes-and-software-factory.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/sandbox-exe-dev .claude/skills/sandbox-exe-dev && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sandbox-exe-dev" agent skill from https://github.com/disler/inkwell-agent-sandboxes-and-software-factory/tree/main/.claude/skills/sandbox-exe-dev into .claude/skills/sandbox-exe-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-exe-dev", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/disler/inkwell-agent-sandboxes-and-software-factory/tree/main/.claude/skills/sandbox-exe-devType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sandbox-exe-dev -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install disler/inkwell-agent-sandboxes-and-software-factory sandbox-exe-dev --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/disler/inkwell-agent-sandboxes-and-software-factory.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/sandbox-exe-dev .agents/skills/sandbox-exe-dev && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sandbox-exe-dev" agent skill from https://github.com/disler/inkwell-agent-sandboxes-and-software-factory/tree/main/.claude/skills/sandbox-exe-dev into .agents/skills/sandbox-exe-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-exe-dev", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sandbox-exe-dev -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install disler/inkwell-agent-sandboxes-and-software-factory sandbox-exe-dev --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/disler/inkwell-agent-sandboxes-and-software-factory.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/sandbox-exe-dev .cursor/skills/sandbox-exe-dev && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sandbox-exe-dev" agent skill from https://github.com/disler/inkwell-agent-sandboxes-and-software-factory/tree/main/.claude/skills/sandbox-exe-dev into .cursor/skills/sandbox-exe-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-exe-dev", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/disler/inkwell-agent-sandboxes-and-software-factory.git --path .claude/skills/sandbox-exe-dev--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sandbox-exe-dev -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install disler/inkwell-agent-sandboxes-and-software-factory sandbox-exe-dev --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/disler/inkwell-agent-sandboxes-and-software-factory.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/sandbox-exe-dev .gemini/skills/sandbox-exe-dev && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sandbox-exe-dev" agent skill from https://github.com/disler/inkwell-agent-sandboxes-and-software-factory/tree/main/.claude/skills/sandbox-exe-dev into .gemini/skills/sandbox-exe-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-exe-dev", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install disler/inkwell-agent-sandboxes-and-software-factory sandbox-exe-devInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sandbox-exe-dev -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/disler/inkwell-agent-sandboxes-and-software-factory.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/sandbox-exe-dev .github/skills/sandbox-exe-dev && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sandbox-exe-dev" agent skill from https://github.com/disler/inkwell-agent-sandboxes-and-software-factory/tree/main/.claude/skills/sandbox-exe-dev into .github/skills/sandbox-exe-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-exe-dev", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sandbox-exe-dev -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install disler/inkwell-agent-sandboxes-and-software-factory sandbox-exe-dev --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/disler/inkwell-agent-sandboxes-and-software-factory.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/sandbox-exe-dev .opencode/skills/sandbox-exe-dev && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sandbox-exe-dev" agent skill from https://github.com/disler/inkwell-agent-sandboxes-and-software-factory/tree/main/.claude/skills/sandbox-exe-dev into .opencode/skills/sandbox-exe-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-exe-dev", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sandbox-exe-devOperate exe.dev persistent VMs via SSH/HTTPS for safe code execution and file operations.
Sandbox Exe Dev is an agent skill from disler/inkwell-agent-sandboxes-and-software-factory. Operate exe.dev persistent VMs via SSH/HTTPS for safe code execution and file operations. Use when the user needs persistent dev environments, SSH-accessible Linux VMs, or web-exposed sandboxes. Keywords: exe.dev, persistent VM, SSH, code execution, sandbox, exedev.
Its SKILL.md is about 5.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 26 other files, including scripts (for example `cookbook/browser.md`, `cookbook/fleet.md` and `examples/01_quickstart.md`).
It works with Linux. The repository describes itself as: Inkwell: a small app, the Super Simple Software Factory that builds it, and the rebootable sandbox system that runs both on a throwaway VM. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 92f1701. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
uvsshjustcurlpythonFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
exe.devtodo-app-20260508-7f3a.exe.xyzFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sandbox Exe Dev loads about 5.1k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 1,976 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
your SSH public key is registered: `cat ~/.ssh/id_ed25519.pub | ssh exe.dev ssh-key add`.- Wrong key picked up? Add a stanza to `~/.ssh/config`:IdentityFile ~/.ssh/id_ed25519_exe(publickey)" → register your key: `cat ~/.ssh/id_ed25519.pub | ssh exe.dev ssh-key add` (you'll need a working SSH sessd"** — the VM's host key isn't in your `~/.ssh/known_hosts` yet. Accept it once with:Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from disler/inkwell-agent-sandboxes-and-software-factory at commit 92f1701, republished under its MIT licence (© disler). 1,976 words, ~5,131 tokens.
.claude/skills/sandbox-exe-dev/SKILL.md (or your agent's skills folder). This skill also uses 20 other files; get the full folder from GitHub.This skill is the persistent-VM cousin of /agent-sandboxes (the E2B skill, installed globally at ~/.claude/skills/agent-sandboxes/). It gives an agent the same ergonomic CLI surface (exedev init, exedev exec, exedev files, exedev share, exedev browser) but backs it with exe.dev's persistent VMs over SSH instead of E2B's ephemeral sandboxes.
If you already know /agent-sandboxes, the sbx → exedev mapping below covers 90% of the muscle memory. The 10% that doesn't translate is documented honestly — pause, extend-lifetime, and template registries don't exist on exe.dev; in exchange you get persistent disks, live resize, whole-VM snapshot, and an auth-gated HTTPS proxy.
EXEDEV_CLI_PATH: .claude/skills/sandbox-exe-dev/exedev_cli/LOCAL_WORKSPACE: tmp/<workflow_id>/ — local staging for files to upload/download. Create when needed.WORKFLOW_ID: kebab-case identifier for the current task. Generate as <task>-<YYYYMMDD>-<short-uuid> if the user doesn't provide one (e.g. todo-app-20260508-7f3a). The VM name should derive from this.TIMEOUT_DURATION_IN_SECONDS: N/A on exe.dev — VMs are persistent and never auto-expire. Tear down with exedev vm kill <name> when truly done.Before using this skill, validate the environment:
Check SSH access to exe.dev:
cd EXEDEV_CLI_PATH
uv run exedev doctorExpected output ends with doctor: OK. If it doesn't:
SHA256:JJOP/lwiBGOMilfONPWZCXUrfK154cnJFXcqlsi6lPo (source: ai_docs/exedev/faq-host-key.md).cat ~/.ssh/id_ed25519.pub | ssh exe.dev ssh-key add.~/.ssh/config:Host exe.dev *.exe.xyz
IdentitiesOnly yes
IdentityFile ~/.ssh/id_ed25519_exeVerify the CLI is installed:
cd EXEDEV_CLI_PATH
uv sync --quiet
uv run exedev --helpexedev vm kill <name> it. Forgotten VMs continue billing — clean up.<name>.exe.xyz. Pick names that are unique to your workflow (<workflow_id>-<short-uuid>). Two agents using myvm will collide.exedev, home is /home/exedev. Use --root (sudo) for system-level operations.https://<name>.exe.xyz/ redirects unauthenticated users to exe.dev login. To match E2B's "anyone with the URL" behaviour, run exedev share set-public <name>. (See Step 5 of the workflow.)POST https://exe.dev/exec endpoint has a 30s timeout and 64KB body cap; this CLI deliberately avoids it. Direct SSH (ssh <vm>.exe.xyz "<cmd>") has neither.exedev files write … --stdin or exedev exec … "cat > path" --stdin. Use LOCAL_WORKSPACE only when you actually need a local artifact.The exedev CLI has six core command groups plus three top-level helpers. The shape mirrors sbx from /agent-sandboxes:
exedev init — quick VM creation (mirrors sbx init).exedev vm — lifecycle (list, info, stat, kill, restart, rename, resize, tag, comment, snapshot).exedev exec — run a command on a VM (mirrors sbx exec).exedev files — file ops (mirrors sbx files; transparent SSH/SCP/RSYNC).exedev share — port exposure & access control (unique-to-exe.dev surface, plus share get-host for ergonomic parity with sbx sandbox get-host).exedev browser — local Playwright + CDP browser automation (lifted verbatim from /agent-sandboxes; same flags, same semantics).Helpers:
exedev doctor — smoke-test the SSH-to-exe.dev pipeline.exedev whoami — show your account + registered SSH keys.Get help on any command:
cd EXEDEV_CLI_PATH
uv run exedev --help # top-level
uv run exedev <group> --help # e.g. uv run exedev vm --help
uv run exedev <group> <verb> --help # e.g. uv run exedev files write --helpsbx → exedevsbx (E2B) | exedev (exe.dev) | Status | Notes |
|---|---|---|---|
sbx init | exedev init --name <vm> | partial | exe.dev names are required and become the public URL; no auto-IDs. |
sbx exec <id> "<cmd>" | exedev exec <vm> "<cmd>" | 1:1 | All flags map (--cwd, --env, --root, --shell, --stdin, --background, --timeout). exe.dev's --stdin works as advertised, unlike E2B's. |
sbx files write/read/edit | exedev files write/read/edit | 1:1 | --stdin recommended for complex content (same footgun as E2B). |
sbx files upload/download | exedev files upload/download | 1:1 | Implemented via scp (binary-safe). |
sbx files upload-dir/download-dir | exedev files upload-dir/download-dir | partial | Same default exclude set; no --max-depth flag (rsync's filter language doesn't support it cleanly). If you need depth-bounded transfer, run find -maxdepth N over SSH first and pass the file list to scp. |
sbx files rm | exedev files rm (default file-only) / rm -r (dir) | 1:1 with policy | Default differs from E2B by design: E2B's rm removes non-empty dirs without a flag; the wrapper requires -r for dir removal as a safety policy. Pass -r to match E2B behaviour exactly. |
sbx sandbox list | exedev vm list [--json] | 1:1 | exe.dev exposes --json. |
sbx sandbox info <id> | exedev vm info <name> | partial | Composes ls --json (identity + URL) with stat (metrics). |
sbx sandbox kill <id> | exedev vm kill <name> | 1:1 | Both destructive, no confirmation prompt; on exe.dev the persistent disk is destroyed too. |
sbx sandbox get-host <id> --port | exedev share get-host <vm> --port | partial | URL is deterministic (https://<vm>.exe.xyz[:<port>]/). Reachability depends on share state — run share set-public for E2B-style anonymous access. |
sbx sandbox extend-lifetime | N/A | unique-to-E2B | exe.dev VMs don't expire. |
sbx sandbox pause / connect | N/A | unique-to-E2B | No analog on exe.dev. The closest pattern is systemctl stop inside the VM (note: doesn't reduce billing). |
sbx browser <verb> | exedev browser <verb> | 1:1 | Same code (verbatim copy). See cookbook/browser.md. |
| — | exedev vm snapshot <src> [name] | unique-to-exe.dev | Whole-VM clone (disk + config). |
| — | exedev vm resize <name> | unique-to-exe.dev | Live grow CPU/RAM/disk. |
| — | exedev vm restart/rename/tag/comment | unique-to-exe.dev | Persistent-VM affordances. |
| — | exedev share set-public/set-private | unique-to-exe.dev | Toggle anonymous access on the HTTPS proxy. |
| — | exedev share add/remove/add-link/remove-link | unique-to-exe.dev | Per-user / per-link auth grants. |
| — | exedev share port | unique-to-exe.dev | Override the primary proxy port. |
The full per-row parity table with parity-status counts is at /tmp/sandbox-parity/AGENT_SANDBOXES_FEATURE_PARITY.md (artifact of the parity exercise that produced this skill).
cd EXEDEV_CLI_PATH
uv run exedev doctorIf doctor: OK, proceed. Otherwise see the Troubleshooting section.
Pick a kebab-case workflow ID; derive the VM name from it. Both agents and humans should be able to read these.
workflow_id = "todo-app-20260508-7f3a"
vm_name = workflow_id # name == public URL: https://todo-app-20260508-7f3a.exe.xyz/cd EXEDEV_CLI_PATH
uv run exedev init --name <vm_name>
# Optional: --image ubuntu:22.04 --cpu 4 --memory 8GB --disk 20GB
# Optional: --tag <tag> --env KEY=VAL --no-shelleyBoot is ~2s. Capture the name in your context (the CLI prints it; you chose it).
# If you'll need local file staging:
mkdir -p tmp/<workflow_id>Run commands (mirrors sbx exec):
uv run exedev exec <vm_name> "uname -a"
uv run exedev exec <vm_name> "pip install requests" --root --timeout 120
uv run exedev exec <vm_name> "ls" --cwd /home/exedev/project
uv run exedev exec <vm_name> "echo \$FOO" --env FOO=bar --shellFiles:
# Write (use --stdin for complex content with brackets/quotes/globs)
echo 'print("hello")' | uv run exedev files write <vm_name> /home/exedev/hello.py --stdin
# Read
uv run exedev files read <vm_name> /home/exedev/hello.py
# Literal-string edit (matches E2B `files edit` exactly)
uv run exedev files edit <vm_name> /home/exedev/config.toml --old "debug = false" --new "debug = true"
# Binary upload/download (scp under the hood)
uv run exedev files upload <vm_name> tmp/<workflow_id>/image.png /home/exedev/image.png
uv run exedev files download <vm_name> /home/exedev/output.pdf tmp/<workflow_id>/output.pdf
# Recursive transfer (rsync; E2B-parity excludes for .git/.venv/node_modules/etc.)
uv run exedev files upload-dir <vm_name> ./local-project /home/exedev/project
uv run exedev files download-dir <vm_name> /home/exedev/project tmp/<workflow_id>/projectLong-running servers (use --background; no --timeout 0 needed because we detach with nohup):
uv run exedev exec <vm_name> "python -m http.server 5173 --bind 0.0.0.0" --background --cwd /home/exedev/project
# logs land at /tmp/exedev-bg.log on the VMThis is where exe.dev's model differs most from E2B. Every VM gets https://<vm>.exe.xyz/ for free — but it's private by default (visitors are redirected to exe.dev login).
uv run exedev exec <vm_name> "npm run dev -- --port 5173 --host 0.0.0.0" --background --cwd /home/exedev/project
# or: "python -m http.server 5173 --bind 0.0.0.0"The server must bind 0.0.0.0 (not 127.0.0.1) for the proxy to reach it.
# Tell the proxy which port to forward to (default heuristic = Dockerfile EXPOSE).
uv run exedev share port <vm_name> 5173
# Make it anonymously reachable (E2B-equivalent default):
uv run exedev share set-public <vm_name>
# OR: keep it private and grant specific people:
uv run exedev share add <vm_name> teammate@example.com
uv run exedev share add-link <vm_name> # tokenized link anyone with it can useuv run exedev share get-host <vm_name>
# https://<vm_name>.exe.xyz/
uv run exedev share get-host <vm_name> --port 8080
# https://<vm_name>.exe.xyz:8080/ (alternate ports 3000-9999 stay auth-gated)The URL is deterministic — share get-host simply composes it. (Contrast with sbx sandbox get-host which has to call out to E2B.)
curl https://<vm_name>.exe.xyz/
# Or, if you set it public, validate visually:
uv run exedev browser nav https://<vm_name>.exe.xyz/
uv run exedev browser screenshot --path tmp/<workflow_id>/validation.pnguv run exedev vm kill <vm_name>This deletes the persistent disk too. There is no undo. If you might want the state later, snapshot first:
uv run exedev vm snapshot <vm_name> <vm_name>-archive| Feature | When to read | Documentation |
|---|---|---|
| Browser Automation | When validating UIs, taking screenshots, or interacting with web pages | cookbook/browser.md |
| Fleet download-all / restore | When archiving every VM locally (the pause/resume substitute — VMs bill until killed) or recreating a killed VM byte-for-byte at the same URL | cookbook/fleet.md |
| Example | When to read | File |
|---|---|---|
| 01 — Quickstart end-to-end | First time using this skill; verify everything connects | examples/01_quickstart.md |
Built-in CLI help:
cd EXEDEV_CLI_PATH
uv run exedev --help # all groups
uv run exedev <group> --help # group-level
uv run exedev <group> <verb> --help # verb-levelFor deeper context:
EXEDEV_CLI_PATH/README.md — CLI overview and architecture.ai_docs/exedev/all.md (in the project that drove the parity exercise) — full exe.dev docs as scraped on 2026-05-08./tmp/sandbox-parity/AGENT_SANDBOXES_FEATURE_PARITY.md — full parity-status table./agent-sandboxes skill at ~/.claude/skills/agent-sandboxes/ — the E2B counterpart this skill mirrors.doctor fails on step 1 (ssh exe.dev whoami):
SHA256:JJOP/lwiBGOMilfONPWZCXUrfK154cnJFXcqlsi6lPo.cat ~/.ssh/id_ed25519.pub | ssh exe.dev ssh-key add (you'll need a working SSH session at least once for this; do it on a machine that already has access, or follow the exe.dev signup flow).exedev exec <vm> "..." hangs:
exedev vm info <vm> should show status: running.--timeout 0 (or omit --timeout) for unbounded execs. The 30s ceiling only applies to the HTTPS API, which this CLI doesn't use.~/.ssh/known_hosts yet. Accept it once with:ssh -o StrictHostKeyChecking=accept-new <vm>.exe.xyz "echo READY"exedev commands targeting that VM will work. (We don't auto-accept-new inside the wrapper because it's a security-sensitive default.)exedev exec --background "python -m http.server ..." hangs the terminal:
--background now wraps the remote command as ( nohup CMD > /tmp/exedev-bg.log 2>&1 < /dev/null & ) so SSH closes immediately. If you see this hang on an older copy, pull the latest src/modules/ssh_runner.py.exedev exec call never returns and you have to Ctrl-C. The fix (< /dev/null to close stdin + subshell to fork) ensures SSH returns the moment the remote child is detached.--background, never run python -m http.server etc. without it from inside exedev exec — the SSH session would stay alive for the lifetime of the server.https://<vm>.exe.xyz/ returns 502 / "no upstream":
0.0.0.0? Bind to 0.0.0.0, not 127.0.0.1 or localhost.exedev share show <vm> for the current proxy target; set it with exedev share port <vm> <p>.https://<vm>.exe.xyz/ redirects me to exe.dev login:
exedev share set-public <vm> for anonymous access, or share add <email> to grant a specific user.exedev files edit fails with "String not found":
--old string is matched literally. Check whitespace, line endings, quoting. Use exedev files read <vm> <path> | grep -F '...' to confirm the string is actually there.exedev browser issues:
cookbook/browser.md — same content as /agent-sandboxes/cookbook/browser.md since the implementation is identical.A VM I don't recognize shows up in exedev vm list:
vm kill. You may have created it from another agent or session. Check comment and tags. If it's truly unwanted: exedev vm kill <name>.Coming from /agent-sandboxes, you might reach for these — they're intentionally absent because the underlying platform doesn't support them, or because perfect parity isn't worth the implementation cost:
pause / extend-lifetime — exe.dev VMs are persistent. There is no expiry to extend, and pause-to-save-money is not a feature.--image accepts any container image. Build your own and reference it.POST /exec HTTPS API — capped at 30s and 64KB. We always use direct SSH, which has neither limit. If you specifically need HTTPS-API access (signed exe0 tokens etc.), read ai_docs/exedev/https-api.md and call out directly with curl.exedev vm kill <name> to stop billing. Set yourself a reminder.--shell" semantics — SSH executes remote commands via the user's login shell by default, so pipes/globs/redirection often work even when --shell isn't passed. The flag is retained for muscle-memory parity with sbx exec --shell, not for strict semantic equivalence.--max-depth on files upload-dir / files download-dir — rsync's filter language doesn't express it cleanly, and the simple translations have edge cases. If you need depth-bounded transfer, do find -maxdepth N over SSH first and pass the file list to scp. The dir-transfer parity status reflects this in the mapping table above.Conversely, the skill does expose surface that has no E2B analog: vm snapshot (whole-VM clone), vm resize (live), vm restart/rename/tag/comment, and the entire share family (auth-gated public URLs, per-user/per-link grants). These are documented inline in exedev <group> --help.
Sandbox operations split one-per-phase, so each runs alone or chained.
just/sandbox/
mod.just mount.just
lifecycle/ create.just fill.just setup.just execute.just observe.just teardown.just
manage/ list.just harvest.just reap.just
run/ orch/The root justfile loads the whole thing as one optional module:
mod? sbx 'just/sandbox/mod.just'Run one phase (just sbx lifecycle setup my-run) or the chain (just sbx mount my-run).
import flattens recipe names into the root namespace. Use mod sandbox 'just/sandbox' instead
if you want them namespaced as just sandbox create.shell — so a root that sets
shell := ["zsh", "-ic"] applies here too.© disler, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 20 other files (scripts) in .claude/skills/sandbox-exe-dev of disler/inkwell-agent-sandboxes-and-software-factory.
Open the folder on GitHubat commit 92f1701
Sandbox Exe Dev next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sandbox Exe Dev this skilldisler/inkwell-agent-sandboxes-and-software-factory | 161 | — | ~5.1k | Automated safety check: Warn | MIT | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| Engine Whats Newflutter/flutter | 179k | — | ~978 | Automated safety check: Pass | BSD-3-Clause | |
| Openclaw Live Updateropenclaw/openclaw | 392k | — | ~3.7k | Automated safety check: Pass | MIT | |
| Upgrade Browserflutter/flutter | 179k | — | ~1.1k | Automated safety check: Pass | BSD-3-Clause | |
| K8s Security PoliciesCybereason-Public/owLSM | 280 | 12 repos | ~2k | Automated safety check: Pass | GPL-2.0 |
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
flutter/flutter
Generates the "what's new" release summary and diff file for changes in the Flutter engine (//engine/src/flutter) between two releases (e.g., 3.47 vs 3.44).
openclaw/openclaw
Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.
flutter/flutter
Upgrade browser versions (Chrome or Firefox) in the Flutter Web Engine and/or Framework tests.
Cybereason-Public/owLSM
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
RustPython/RustPython
Runs RustPython tests inside a Linux container built with Apple's container CLI, so macOS users can compare Linux results with their local ones.
disler/inkwell-agent-sandboxes-and-software-factory
Drive herdr — the terminal-native agent multiplexer (herdr.dev) — from natural language.
disler/inkwell-agent-sandboxes-and-software-factory
Drive the six-phase sandbox mount system from the host — mount throwaway exe.dev VMs, run the Super Simple Software Factory inside them, watch from outside, harvest the commits, tear down.
Works with
Operate exe.dev persistent VMs via SSH/HTTPS for safe code execution and file operations. Sandbox Exe Dev is an agent skill from disler/inkwell-agent-sandboxes-and-software-factory.dev persistent VMs via SSH/HTTPS for safe code execution and file operations.
Sandbox Exe Dev fits situations like: the user needs persistent dev environments; SSH-accessible Linux VMs; web-exposed sandboxes.
Run `npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sandbox-exe-dev -a claude-code`. Or copy the skill folder (.claude/skills/sandbox-exe-dev in disler/inkwell-agent-sandboxes-and-software-factory) into .claude/skills/sandbox-exe-dev in your project. Claude Code loads it when a task matches its description.
Run `npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sandbox-exe-dev -a codex`. Or copy the skill folder (.claude/skills/sandbox-exe-dev in disler/inkwell-agent-sandboxes-and-software-factory) into .agents/skills/sandbox-exe-dev in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sandbox-exe-dev -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sandbox-exe-dev, .gemini/skills/sandbox-exe-dev, .github/skills/sandbox-exe-dev and .opencode/skills/sandbox-exe-dev in your project.
Going by SKILL.md and its folder, Sandbox Exe Dev needs Python for the scripts in its folder and the command-line tools its instructions call (uv, ssh, just, curl and python). Our summary lists: Python 3.
SKILL.md names 2 domains. In commands or code: exe.dev and todo-app-20260508-7f3a.exe.xyz; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 5 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Sandbox Exe Dev is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.1k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Sandbox Exe Dev: Configuring Horizon (coollabsio/coolify, 63k stars), Engine Whats New (flutter/flutter, 179k stars), Openclaw Live Updater (openclaw/openclaw, 392k stars) and Upgrade Browser (flutter/flutter, 179k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
disler (a GitHub user) maintains it in disler/inkwell-agent-sandboxes-and-software-factory, which has 161 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on August 9, 2026.
Source: disler/inkwell-agent-sandboxes-and-software-factory on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.