Official agent skill

Sandbox npm Install

by github in github/awesome-copilot

Install npm packages in a Docker sandbox environment. An agent skill from github/awesome-copilot.

OfficialMITAuto-check: warningsDevOps & Cloud

Install Sandbox npm Install

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add github/awesome-copilot --skill sandbox-npm-install -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/awesome-copilot sandbox-npm-install --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sandbox-npm-install .claude/skills/sandbox-npm-install && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sandbox-npm-install
GitHub stars
40k
Used in
1 other repo
Token cost
~951 tokens
SKILL.md length
443 words
Files
2 (incl. scripts)
Skills in repo
417
Repo updated
First seen
Licence
MIT

At a glance

Install npm packages in a Docker sandbox environment. An agent skill from github/awesome-copilot.

  • Works in 5 steps: Copies package.json, package-lock.json,… → Runs npm ci (or npm install if no… → Symlinks node_modules back into the… → …
  • You need to install
  • SKILL.md covers When to Use This Skill, Prerequisites, Background and Step-by-Step Installation, plus 4 more sections
  • Runs Shell scripts from its folder; calls npm and bash

What it does

Sandbox npm Install is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Install npm packages in a Docker sandbox environment. Use this skill whenever you need to install, reinstall, or update nodemodules inside a container where the workspace is mounted via virtiofs. Native binaries (esbuild, lightningcss, rollup) crash on virtiofs, so packages must be installed on the local ext4 filesystem and symlinked back.

Its SKILL.md is about 950 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/install.sh`).

It sits in DevOps & Cloud, covering Containers. It works with npm, Docker and Playwright. The repository describes itself as: Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot. The licence is MIT.

When your agent uses it

  • You need to install
  • Update nodemodules inside a container where the workspace is mounted via virtiofs

Example prompts

  • “/sandbox-npm-install”

Requirements

  • Node.js
  • A Bash shell
  • Docker

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Copies package.json, package-lock.json, and .npmrc (if present) to a local ext4 directory
  2. Runs npm ci (or npm install if no lockfile) on the local filesystem
  3. Symlinks node_modules back into the workspace
  4. Verifies known native binaries (esbuild, rollup, lightningcss, vite) if present
  5. Optionally installs Playwright browsers and system dependencies (uses sudo when available)

What it can do on your machine

Read from SKILL.md and the folder at commit 727ff2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sandbox npm Install loads about 951 tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 443 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~951

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:43
    ackage.json`, `package-lock.json`, and `.npmrc` (if present) to a local ext4 directory

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from github/awesome-copilot at commit 727ff2e, republished under its MIT licence (© github). 443 words, ~951 tokens.

Download SKILL.mdSave it as .claude/skills/sandbox-npm-install/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
sandbox-npm-install
description
Install npm packages in a Docker sandbox environment. Use this skill whenever you need to install, reinstall, or update node_modules inside a container where the workspace is mounted via virtiofs. Native binaries (esbuild, lightningcss, rollup) crash on virtiofs, so packages must be installed on the local ext4 filesystem and symlinked back.

Sandbox npm Install

When to Use This Skill

Use this skill whenever:

  • You need to install npm packages for the first time in a new sandbox session
  • package.json or package-lock.json has changed and you need to reinstall
  • You encounter native binary crashes with errors like SIGILL, SIGSEGV, mmap, or unaligned sysNoHugePageOS
  • The node_modules directory is missing or corrupted

Prerequisites

  • A Docker sandbox environment with a virtiofs-mounted workspace
  • Node.js and npm available in the container
  • A package.json file in the target workspace

Background

Docker sandbox workspaces are typically mounted via virtiofs (file sync between the host and Linux VM). Native Go and Rust binaries (esbuild, lightningcss, rollup, etc.) crash with mmap alignment failures when executed from virtiofs on aarch64. The fix is to install on the container's local ext4 filesystem and symlink back into the workspace.

Step-by-Step Installation

Run the bundled install script from the workspace root:

bash
bash scripts/install.sh
Common Options
OptionDescription
--workspace <path>Path to directory containing package.json (auto-detected if omitted)
--playwrightAlso install Playwright Chromium browser for E2E testing
What the Script Does
  1. Copies package.json, package-lock.json, and .npmrc (if present) to a local ext4 directory
  2. Runs npm ci (or npm install if no lockfile) on the local filesystem
  3. Symlinks node_modules back into the workspace
  4. Verifies known native binaries (esbuild, rollup, lightningcss, vite) if present
  5. Optionally installs Playwright browsers and system dependencies (uses sudo when available)

If verification fails, run the script again — crashes can be intermittent during initial setup.

Post-Install Verification

After the script completes, verify your toolchain works. For example:

bash
npm test             # Run project tests
npm run build        # Build the project
npm run dev          # Start dev server
Show full SKILL.md (187 more words)Show less

Important Notes

  • The local install directory (e.g., /home/agent/project-deps) is container-local and is NOT synced back to the host
  • The node_modules symlink appears as a broken link on the host — this is harmless since node_modules is typically gitignored
  • Running npm ci or npm install on the host naturally replaces the symlink with a real directory
  • After any package.json or package-lock.json change, re-run the install script
  • Do NOT run npm ci or npm install directly in the mounted workspace — native binaries will crash

Troubleshooting

ProblemSolution
SIGILL or SIGSEGV when running dev serverRe-run the install script; ensure you're not running npm install directly in the workspace
node_modules not found after installCheck that the symlink exists: ls -la node_modules
Permission errors during installEnsure the local deps directory is writable by the current user
Verification fails intermittentlyRun the script again — native binary crashes can be non-deterministic on first load

Vite Compatibility

If your project uses Vite, you may need to allow the symlinked path in server.fs.allow. Add the symlink target's parent directory (e.g., /home/agent/project-deps/) to your Vite config so that Vite can serve files through the symlink.

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in skills/sandbox-npm-install of github/awesome-copilot.

  • SKILL.md
  • scripts/install.sh

Open the folder on GitHubat commit 727ff2e

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in github/awesome-copilot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Sandbox npm Install next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sandbox npm Install compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sandbox npm Install this skillgithub/awesome-copilot40k1 repos~951Automated safety check: WarnMIT
Acarshub Tool Additionssdr-enthusiasts/docker-acarshub117—~707Automated safety check: PassGPL-3.0
Project Releaseswimmwatch/cloakbrowser-mcp161—~1.9kAutomated safety check: PassMIT
Project Docs Maintainerswimmwatch/cloakbrowser-mcp161—~569Automated safety check: PassMIT
Redis Insight Pluginredis/RedisInsight8.9k—~3.5kAutomated safety check: PassMIT
Reflexo ReleaseMyriad-Dreamin/typst.ts1.2k—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Acarshub Tool Additions

    sdr-enthusiasts/docker-acarshub

    Use ONLY when working in the docker-acarshub repository AND a task may require adding a system tool, npm package, or other dependency.

    117 GitHub stars~707 tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Project Release

    swimmwatch/cloakbrowser-mcp

    Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work.

    161 GitHub stars~1.9k tokensUpdated 5 days ago
    Agent WorkflowsAuto-check passed
  • Project Docs Maintainer

    swimmwatch/cloakbrowser-mcp

    Maintain, organize, consolidate, or audit the cloakbrowser-mcp documentation set only when the user explicitly requests project documentation maintenance or an authorized public change requires it.

    161 GitHub stars~569 tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Redis Insight Plugin

    redis/RedisInsight

    Official

    A skill your agent uses when creating, modifying, debugging, deploying, or testing Redis Insight Workbench visualization plugins, plugin manifests, package.json visualizations, activationMethod…

    8.9k GitHub stars~3.5k tokensUpdated 2 days ago
    DatabasesAuto-check passed
  • Reflexo Release

    Myriad-Dreamin/typst.ts

    Guide Reflexo/typst.ts release preparation and operator handoffs.

    1.2k GitHub stars~1.5k tokensUpdated 13 days ago
    DevOps & CloudAuto-check passed
  • Web Ng Docker Loop

    carverauto/serviceradar

    Run ServiceRadar elixir/web-ng locally against the Docker Compose CNPG database with copied mTLS certs and Docker secrets, then verify dashboard UI changes with Playwright.

    921 GitHub stars~737 tokensUpdated today
    DevOps & CloudAuto-check passed

More from github/awesome-copilot

All 417 skills in this repo
  • Acquire Codebase Knowledge

    github/awesome-copilot

    Official

    Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Draw.io Diagram Generator

    github/awesome-copilot

    Official

    Generates, edits and validates draw.io files with correct mxGraph XML, covering flowcharts, architecture, sequence, ER and UML class diagrams.

    40k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Credit Risk Data Cleaning

    github/awesome-copilot

    Official

    Cleans raw credit data and screens variables before loan modeling, dropping unstable, noisy or redundant features and writing an Excel report of every step.

    40k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Daily Focus Board

    github/awesome-copilot

    Official

    Builds a warm, browser-based daily focus board the user updates by talking to their agent, with Eisenhower priorities, a brain-dump box and kind not-today carryover.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Python Pypi Package Builder

    github/awesome-copilot

    Official

    End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.

    40k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Sandbox npm Install

What does Sandbox npm Install do?

Install npm packages in a Docker sandbox environment. An agent skill from github/awesome-copilot. Sandbox npm Install is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Install npm packages in a Docker sandbox environment.

When should I use Sandbox npm Install?

Sandbox npm Install fits situations like: you need to install; update nodemodules inside a container where the workspace is mounted via virtiofs.

How do I install Sandbox npm Install in Claude Code?

Run `npx skills add github/awesome-copilot --skill sandbox-npm-install -a claude-code`. Or copy the skill folder (skills/sandbox-npm-install in github/awesome-copilot) into .claude/skills/sandbox-npm-install in your project. Claude Code loads it when a task matches its description.

How do I install Sandbox npm Install in Codex?

Run `npx skills add github/awesome-copilot --skill sandbox-npm-install -a codex`. Or copy the skill folder (skills/sandbox-npm-install in github/awesome-copilot) into .agents/skills/sandbox-npm-install in your project. Codex loads it when a task matches its description.

Can I use Sandbox npm Install in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/awesome-copilot --skill sandbox-npm-install -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sandbox-npm-install, .gemini/skills/sandbox-npm-install, .github/skills/sandbox-npm-install and .opencode/skills/sandbox-npm-install in your project.

What does Sandbox npm Install need to run?

Going by SKILL.md and its folder, Sandbox npm Install needs a shell for the scripts in its folder and the command-line tools its instructions call (npm and bash). Our summary lists: Node.js; A Bash shell; Docker.

Does Sandbox npm Install access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sandbox npm Install safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Sandbox npm Install use?

Sandbox npm Install is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sandbox npm Install use?

About 951 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sandbox npm Install?

Skills that share tags, products or a category with Sandbox npm Install: Acarshub Tool Additions (sdr-enthusiasts/docker-acarshub, 117 stars), Project Release (swimmwatch/cloakbrowser-mcp, 161 stars), Project Docs Maintainer (swimmwatch/cloakbrowser-mcp, 161 stars) and Redis Insight Plugin (redis/RedisInsight, 8.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sandbox npm Install?

github (a GitHub organization, an official publisher) maintains it in github/awesome-copilot, which has 39,748 GitHub stars. The repository holds 417 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/awesome-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.