Agent skill

Sssf Sandbox Orchestrator

by disler in disler/inkwell-agent-sandboxes-and-software-factory

Drive the six-phase sandbox mount system from the host — mount throwaway exe.dev VMs, run the Super Simple Software Factory inside them, watch from outside, harvest the commits, tear down.

MITAuto-check: notes

Install Sssf Sandbox Orchestrator

skills CLI
$ npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sssf-sandbox-orchestrator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install disler/inkwell-agent-sandboxes-and-software-factory sssf-sandbox-orchestrator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/disler/inkwell-agent-sandboxes-and-software-factory.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/sssf-sandbox-orchestrator .claude/skills/sssf-sandbox-orchestrator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sssf-sandbox-orchestrator
GitHub stars
161
Token cost
~2.6k tokens
SKILL.md length
1,349 words
Files
14 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Drive the six-phase sandbox mount system from the host — mount throwaway exe.dev VMs, run the Super Simple Software Factory inside them, watch from outside, harvest the commits, tear down.

  • Works in 6 steps: Never decide teardown. Report what the… → Never run ADWs on the host. just adw… → A gate failure means STOP and diagnose,… → …
  • The user says mount a sandbox
  • SKILL.md covers The one governing principle:…, Dependencies, Two layers, one credential… and The drive surface, plus 3 more sections
  • Calls just, ssh and git; needs OPENROUTER_PROVISIONING_KEY

What it does

Sssf Sandbox Orchestrator is an agent skill from disler/inkwell-agent-sandboxes-and-software-factory. Drive the six-phase sandbox mount system from the host — mount throwaway exe.dev VMs, run the Super Simple Software Factory inside them, watch from outside, harvest the commits, tear down. Use when the user says mount a sandbox, run the factory in a sandbox, spin up N sandboxes, best-of-N, check on a run, harvest a run's commits, or tear down. Keywords - sandbox, mount, exe.dev VM, run id, fan out, best-of-N, harvest, bundle, teardown, reap.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including reference files (for example `cookbooks/access_a_running_sandbox.md`, `cookbooks/debug_a_failed_gate.md` and `cookbooks/execute_work.md`).

The repository describes itself as: Inkwell: a small app, the Super Simple Software Factory that builds it, and the rebootable sandbox system that runs both on a throwaway VM. The licence is MIT.

When your agent uses it

  • The user says mount a sandbox
  • Run the factory in a sandbox
  • Spin up N sandboxes
  • Harvest a runs commits

Example prompts

  • “/sssf-sandbox-orchestrator”

Requirements

  • A credential in OPENROUTER_PROVISIONING_KEY

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Never decide teardown. Report what the run produced, what it cost, and recommend — the human
  2. Never run ADWs on the host. just adw sdlc "..." here runs the factory on the engineer's
  3. A gate failure means STOP and diagnose, never destroy. The VM is left alive deliberately.
  4. Never touch a key. The runtime key lives at .sandbox/runs/.key (0600) and inside the
  5. Never mint outside create. The sbx- prefix is the entire safety model for reap; the
  6. Report the run id every time. It is the only handle the next phase, the next session, and

What it can do on your machine

Read from SKILL.md and the folder at commit 92f1701. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • just
    • ssh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use ssh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENROUTER_PROVISIONING_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sssf Sandbox Orchestrator loads about 2.6k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 118 tokens; SKILL.md has 1,349 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~118
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~16k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:89
    .61s, no auth), optional SHA pin, write `.env` with the runtime key |
  • NoteMentions a .env fileSKILL.md:146
    VM's `app/.env`. Never print it, never copy it, never pass it over ssh — `setup`'s gate spends it

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from disler/inkwell-agent-sandboxes-and-software-factory at commit 92f1701, republished under its MIT licence (© disler). 1,349 words, ~2,617 tokens.

Download SKILL.mdSave it as .claude/skills/sssf-sandbox-orchestrator/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
sssf-sandbox-orchestrator
description
Drive the six-phase sandbox mount system from the host — mount throwaway exe.dev VMs, run the Super Simple Software Factory inside them, watch from outside, harvest the commits, tear down. Use when the user says mount a sandbox, run the factory in a sandbox, spin up N sandboxes, best-of-N, check on a run, harvest a run's commits, or tear down. Keywords - sandbox, mount, exe.dev VM, run id, fan out, best-of-N, harvest, bundle, teardown, reap.
argument-hint
[mount|execute|agent|observe|harvest|teardown] [run-id or prompt]

SSSF Sandbox Orchestrator

Drives the out-of-sandbox half of this repo: the sbx namespace under just/sandbox/ that take a blank exe.dev VM to a health-checked, running factory in ~10s, run work inside it, expose it to a browser, and — only when a human says so — tear it down.

The one governing principle: THIN SKILL, FAT RECIPES

Every action you take should be a just command a human could type. The recipes hold the knowledge; this skill holds the judgment about which one to run and how to read the result.

  • Dropping to ssh <vm>.exe.xyz '...' or curl to inspect is fine and expected — that is what just sbx run cmd <id> '<cmd>' exists for, and reading a log or a table needs no ceremony.
  • Re-implementing what a recipe already does is not. Never hand-roll a key mint, a revoke, an ssh exe.dev new, a share port, or a detached nohup launch. Those encode measured facts (mint order, the revocation gate, the proxy retarget, the three detachment pieces) and a hand-rolled version drops one of them silently.
  • If a recipe is wrong, fix the recipe and say so. Do not route around it.

Dependencies

This skill references /sssf and /sandbox-exe-dev rather than duplicating them. /sssf owns the ADW roster, the handoff contract and the trace-db schema; /sandbox-exe-dev owns the exe.dev CLI surface. Both move without asking us, and a copy pasted here would be a second source of truth that goes wrong quietly — a stale model id, a renamed flag. Read them; do not quote them.

Preflight is one command. Run it before the first phase; any failure means report and stop, never work around a missing prerequisite by hand.

bash
just sbx manage doctor

It checks all six in one pass: ssh exe.dev reachable, OPENROUTER_PROVISIONING_KEY set (never printed), the run-record helper runs, the provisioner is executable, the models template carries full four-field rate blocks, and the adw layer resolves. Green ends with sbx doctor: OK.

Two things it does not cover, so check them yourself:

CheckCommandIf it fails
Factory skilltest -f .claude/skills/sssf/SKILL.mdthe ADWs the sandbox runs come from /sssf. Without it there is nothing to mount.
VM skilltest -f .claude/skills/sandbox-exe-dev/SKILL.mdread it for exe.dev CLI detail instead of guessing flags.

Listing a namespace is just --list sbx, not just sbx --list. The latter reads --list as a recipe name and errors with Justfile does not contain recipe `sbx --list` . A bare just sbx also works — it runs the namespace's default, which lists.

Two layers, one credential boundary

Out-sandbox (you)In-sandbox (the VM)
Lives injust/sandbox/, sandbox_mount/host/just/adws.just (mod adw), adws/, sandbox_mount/guest/
Entry pointjust sbx mount, just sbx lifecycle execute, just sbx lifecycle teardownjust adw sdlc "..."
Credentialexe.dev account + OpenRouter provisioning keyone disposable runtime key, $50 cap

The whole repo ships to the sandbox, this skill included. What a sandbox cannot do is USE the out-sandbox half — just sbx mount there fails on a missing exe.dev account, and create fails on a missing OPENROUTER_PROVISIONING_KEY. Neither credential ever leaves the host, and that, not file absence, is what stops a sandbox from mounting sandboxes. Keep the credentials on the host.

The drive surface

Four groups under sbx, plus mount at the top because it is the entry point, not a phase:

just sbx
├── mount              the chain: create → fill → setup → observe
├── lifecycle          the six phases, for when you need one on its own
├── manage             preflight, readback, fleet ops — nothing here is a phase
├── run                put work in / look inside: `run cmd`, `run agent`
└── orch               boot a host-side orchestrator: `orch cc`, `orch pi`

just sbx, just sbx lifecycle, just sbx manage, just sbx run and just sbx orch each list their own contents when run bare.

CommandWhat it does
just sbx mount RUN_ID [--limit N]create → fill → setup → observe. Never teardown. Prints the resolved run id and both URLs.
just sbx lifecycle create RUN_ID [--limit N]mint sbx-<run-id> ($50 default) + boot the VM, in record → VM → key order
just sbx lifecycle fill RUN_ID [SHA]public git clone (2.61s, no auth), optional SHA pin, write .env with the runtime key
just sbx lifecycle setup RUN_IDprovision.sh + the five-assertion gate
just sbx lifecycle execute RUN_ID "PROMPT"full SDLC detached inside the box; returns a pid, records it
just sbx run cmd RUN_ID '<cmd>'generic escape hatch, synchronous, runs in app/. Your inspection tool.
just sbx run agent RUN_ID "PROMPT"Claude Code inside the box, resumable session — hand off, then keep talking
just sbx lifecycle observe RUN_IDstart both servers, expose 4501, print URLs. Idempotent.
just sbx manage listevery run record: state, VM alive, spend
just sbx manage harvest RUN_IDpull the run's commits home as a git bundle, fetched into refs/sandbox/<run-id>. Non-destructive, idempotent, run it any time.
just sbx lifecycle teardown RUN_ID [--no-harvest]spend → artifacts → harvest → revoke → destroy → close. The only destructive recipe.
just sbx manage reap [--yes]delete orphaned sbx-* keys. Dry run by default. Run it at the start of a session.

The run id is the handle for every phase. create appends -<date>-<6 hex> if you did not, and prints what it settled on — use that string, not the one you typed.

The five gate assertions (setup): A git integrity (status --porcelain clean, HEAD matches the recorded sha) · B pi --list-models non-empty — it exits 0 while empty · C every roster model answers a ping · D pi reports non-zero cost, which proves the rate table loaded · E remaining credit. A failure reports, stops, and leaves the VM alive.

Show full SKILL.md (492 more words)Show less

Cookbooks (lazy-load the one the request calls for)

ActivityWhen to readFile
Understand the recipes before running anyfirst time, or when a recipe surprises youcookbooks/just_command_model.md
Stand up one sandbox end to end"mount a sandbox", "run this in a sandbox"cookbooks/mount_one.md
Put work into a mounted box"build X in there", "ask the agent", picking run cmd vs lifecycle execute vs run agentcookbooks/execute_work.md
Watch a run and report it back"check on the run", "is it done", "show me the URLs"cookbooks/observe_and_report.md
Give the user access to a running box"get me into the sandbox", a shell in there, talk to the in-box agentcookbooks/access_a_running_sandbox.md
A gate assertion failedsetup exited non-zero, or the box looks wrongcookbooks/debug_a_failed_gate.md
Spin up N and pick a winner"best-of-N", "three variants", "diff the runs"cookbooks/fan_out_n.md
Shut a run down, clean up keysthe human decided to tear down; orphaned sbx- keyscookbooks/teardown_and_reap.md

References (deep specs, read on demand)

ReferenceCovers
references/phases.mdwhat each of the six phases does, in order, and why the order is that order
references/kickoff_paths.mdthe two ways work enters a box: direct (lifecycle execute, a command) vs agent-mediated (run agent, a delegation)
references/run_record.md.sandbox/runs/<id>.json — the closed schema, who writes each field, who reads it
references/models.mdthe roster, per-million rates, the mandatory four-field cost block, ZDR
references/gotchas.mdevery trap that cost a debugging cycle, with the symptom it produces

Hard rules

  1. Never decide teardown. Report what the run produced, what it cost, and recommend — the human decides. mount stops at observe on purpose and nothing chains into teardown. A VM left running is a bill; a VM destroyed early is the evidence and the artifacts, gone. harvest is the exception you may run freely — it only reads the box and only writes refs/sandbox/, so run it as soon as a run commits rather than letting the commits wait on a teardown decision.
  2. Never run ADWs on the host. just adw sdlc "..." here runs the factory on the engineer's laptop — the exact collision this system exists to remove. Work goes in through just sbx lifecycle execute / just sbx run agent, always.
  3. A gate failure means STOP and diagnose, never destroy. The VM is left alive deliberately. Read the failing assertion, just sbx run cmd <id> '...' your way to the cause, fix it, re-run just sbx lifecycle setup. Re-running setup is safe.
  4. Never touch a key. The runtime key lives at .sandbox/runs/<id>.key (0600) and inside the VM's app/.env. Never print it, never copy it, never pass it over ssh — setup's gate spends it from inside the box for exactly that reason. The provisioning key never leaves the host.
  5. Never mint outside create. The sbx- prefix is the entire safety model for reap; the engineer's personal keys carry no prefix and deleting one is unrecoverable.
  6. Report the run id every time. It is the only handle the next phase, the next session, and teardown have.

© disler, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (references) in .claude/skills/sssf-sandbox-orchestrator of disler/inkwell-agent-sandboxes-and-software-factory.

  • SKILL.md
  • cookbooks/access_a_running_sandbox.md
  • cookbooks/debug_a_failed_gate.md
  • cookbooks/execute_work.md
  • cookbooks/fan_out_n.md
  • cookbooks/just_command_model.md
  • cookbooks/mount_one.md
  • cookbooks/observe_and_report.md
  • cookbooks/teardown_and_reap.md
  • references/gotchas.md
  • references/kickoff_paths.md
  • references/models.md
  • references/phases.md
  • references/run_record.md

Open the folder on GitHubat commit 92f1701

Compare with similar skills

Sssf Sandbox Orchestrator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sssf Sandbox Orchestrator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sssf Sandbox Orchestrator this skilldisler/inkwell-agent-sandboxes-and-software-factory161—~2.6kAutomated safety check: NotesMIT
Team Agent Orchestrationaffaan-m/ECC277k1 repos~1.2kAutomated safety check: PassMIT
Orca Orchestrationstablyai/orca89k—~916Automated safety check: PassMIT
Agent Orchestrator Taskruvnet/ruflo74k2 repos~1kAutomated safety check: PassMIT
Orchestratesickn33/agentic-awesome-skills47k1 repos~692Automated safety check: PassMIT
Agent Sandboxruvnet/ruflo74k2 repos~777Automated safety check: PassMIT

Similar skills

  • Run team-based orchestration for agent squads: work items with owners and scope, agent Kanban state, branch isolation, control pane visibility, and merge gates.

    277k GitHub starsUsed in 1 repo~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Orca Orchestration

    stablyai/orca

    Coordinate supervised Orca workers: threaded messages, blocking ask/reply, task dispatch, worker_done/escalation waits, task DAGs, decision gates, coordinator…

    89k GitHub stars~916 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Agent skill for orchestrator-task - invoke with $agent-orchestrator-task

    74k GitHub starsUsed in 2 repos~1k tokens
    Agent WorkflowsAuto-check passed
  • Orchestrate

    sickn33/agentic-awesome-skills

    Coordinate focused subagents on substantial work, keep their ownership non-overlapping, and integrate verified results.

    47k GitHub starsUsed in 1 repo~692 tokens
    Agent WorkflowsAuto-check passed
  • Agent Sandbox

    ruvnet/ruflo

    Agent skill for sandbox - invoke with $agent-sandbox. An agent skill from ruvnet/ruflo.

    74k GitHub starsUsed in 2 repos~777 tokens
    Auto-check passed
  • Sandbox Bench

    vercel/next.js

    Official

    Benchmark React or Next.js changes on Vercel Sandbox VMs with paired A/B statistics: react PR/commit vs base, or Next.js PR/commit vs base, measured end-to-end through the bench/render-pipeline app…

    143k GitHub stars~4.1k tokensUpdated today
    Data & AnalyticsAuto-check passed

More from disler/inkwell-agent-sandboxes-and-software-factory

  • Herdr

    disler/inkwell-agent-sandboxes-and-software-factory

    Drive herdr — the terminal-native agent multiplexer (herdr.dev) — from natural language.

    161 GitHub stars~4.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Sandbox Exe Dev

    disler/inkwell-agent-sandboxes-and-software-factory

    Operate exe.dev persistent VMs via SSH/HTTPS for safe code execution and file operations.

    161 GitHub stars~5.1k tokensUpdated 2 mo ago
    Auto-check: warnings

Questions about Sssf Sandbox Orchestrator

What does Sssf Sandbox Orchestrator do?

Drive the six-phase sandbox mount system from the host — mount throwaway exe.dev VMs, run the Super Simple Software Factory inside them, watch from outside, harvest the commits, tear down. Sssf Sandbox Orchestrator is an agent skill from disler/inkwell-agent-sandboxes-and-software-factory.dev VMs, run the Super Simple Software Factory inside them, watch from outside, harvest the commits, tear down.

When should I use Sssf Sandbox Orchestrator?

Sssf Sandbox Orchestrator fits situations like: the user says mount a sandbox; run the factory in a sandbox; spin up N sandboxes; harvest a runs commits.

How do I install Sssf Sandbox Orchestrator in Claude Code?

Run `npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sssf-sandbox-orchestrator -a claude-code`. Or copy the skill folder (.claude/skills/sssf-sandbox-orchestrator in disler/inkwell-agent-sandboxes-and-software-factory) into .claude/skills/sssf-sandbox-orchestrator in your project. Claude Code loads it when a task matches its description.

How do I install Sssf Sandbox Orchestrator in Codex?

Run `npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sssf-sandbox-orchestrator -a codex`. Or copy the skill folder (.claude/skills/sssf-sandbox-orchestrator in disler/inkwell-agent-sandboxes-and-software-factory) into .agents/skills/sssf-sandbox-orchestrator in your project. Codex loads it when a task matches its description.

Can I use Sssf Sandbox Orchestrator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add disler/inkwell-agent-sandboxes-and-software-factory --skill sssf-sandbox-orchestrator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sssf-sandbox-orchestrator, .gemini/skills/sssf-sandbox-orchestrator, .github/skills/sssf-sandbox-orchestrator and .opencode/skills/sssf-sandbox-orchestrator in your project.

What does Sssf Sandbox Orchestrator need to run?

Going by SKILL.md and its folder, Sssf Sandbox Orchestrator needs the command-line tools its instructions call (just, ssh and git) and credentials named OPENROUTER_PROVISIONING_KEY. Our summary lists: A credential in OPENROUTER_PROVISIONING_KEY.

Does Sssf Sandbox Orchestrator access the network?

SKILL.md contains no URLs. Its commands use ssh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sssf Sandbox Orchestrator safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Sssf Sandbox Orchestrator use?

Sssf Sandbox Orchestrator is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sssf Sandbox Orchestrator use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.

What are the alternatives to Sssf Sandbox Orchestrator?

Skills that share tags, products or a category with Sssf Sandbox Orchestrator: Team Agent Orchestration (affaan-m/ECC, 277k stars), Orca Orchestration (stablyai/orca, 89k stars), Agent Orchestrator Task (ruvnet/ruflo, 74k stars) and Orchestrate (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sssf Sandbox Orchestrator?

disler (a GitHub user) maintains it in disler/inkwell-agent-sandboxes-and-software-factory, which has 161 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on August 9, 2026.

Source: disler/inkwell-agent-sandboxes-and-software-factory on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.