Agent skill

Agentbox Setup

by madarco in madarco/agentbox

Generate an agentbox.yaml for the current AgentBox workspace.

MITAuto-check: notesDevelopment

Install Agentbox Setup

skills CLI
$ npx skills add madarco/agentbox --skill agentbox-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install madarco/agentbox agentbox-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/madarco/agentbox.git skills-src && mkdir -p .claude/skills && cp -r skills-src/apps/cli/share/agentbox-setup .claude/skills/agentbox-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agentbox-setup
GitHub stars
523
Token cost
~5.9k tokens
SKILL.md length
2,788 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Generate an agentbox.yaml for the current AgentBox workspace.

  • Works in 11 steps: Discover the project → Pick services and tasks → Wire readiness probes (services only) → …
  • Opens a sandbox without an agentbox.yaml
  • SKILL.md covers Box layout (what you're…, Goal, 1. Discover the project and 2. Pick services and tasks, plus 10 more sections
  • Calls docker, git and bash; reaches agent-box.sh; needs AGENTBOX_AUTO_SECRET and BETTER_AUTH_SECRET

What it does

Agentbox Setup is an agent skill from madarco/agentbox. Generate an agentbox.yaml for the current AgentBox workspace. Invoke when the user opens a sandbox without an agentbox.yaml or asks to (re)configure one.

Its SKILL.md is about 5.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with Git, Docker and Visual Studio Code. The repository describes itself as: Run multiple agents in parallel sandboxed VMs, with a single command, on your PC or in the cloud. The licence is MIT.

When your agent uses it

  • Opens a sandbox without an agentbox.yaml
  • Asks to (re)configure one

Example prompts

  • “/agentbox-setup”

Requirements

  • Docker

Workflow steps

11 steps, taken from the step headings in SKILL.md.

  1. Discover the project
  2. Pick services and tasks
  3. Wire readiness probes (services only)
  4. Restart + backoff
  5. (Optional) defaults: block
  6. Worked example
  7. Validate before handing off
  8. Hand-off
  9. Checkpoint the warm state - DON't SKIP THIS STEP
  10. Known issues
  11. Pin URLs / render config files (env, secrets)

What it can do on your machine

Read from SKILL.md and the folder at commit 605ee75. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • git
    • bash
    • pnpm
    • cursor
    • playwright
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • agent-box.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AGENTBOX_AUTO_SECRET
    • BETTER_AUTH_SECRET
    • POSTGRES_PASSWORD
    • TELEGRAM_BOT_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agentbox Setup loads about 5.9k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 2,788 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~5.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:188
    sudo apt-get update && sudo apt-get install -y postgresql-client
  • NoteMentions a .env fileSKILL.md:295
    optima.localhost`) or read a gitignored `.env`. Instead of long `sed` commands in a task, use the built-ins:
  • NoteMentions a .env fileSKILL.md:299
    Render a gitignored `.env` from a committed `env.example` on every boot, pinning the URLs to this box:
  • NoteMentions a .env fileSKILL.md:310
    x that carries a different box's host in .env.
  • NoteMentions a .env fileSKILL.md:311
    er apps/saas/env.example --out apps/saas/.env --env --rules box-host
  • NoteMentions a .env fileSKILL.md:316
    er (stable when you render the template→`.env` once). `{{AGENTBOX_AUTO_SECRET:better-auth}}` → generated once, persisted
  • NoteMentions a .env fileSKILL.md:340
    `** — for a host-only file (e.g. a real `.env` with secrets that never lives in the repo), carry it in and render it hos
  • NoteMentions a .env fileSKILL.md:345
    dest: /workspace/apps/saas/.env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from madarco/agentbox at commit 605ee75, republished under its MIT licence (© madarco). 2,788 words, ~5,939 tokens.

Download SKILL.mdSave it as .claude/skills/agentbox-setup/SKILL.md (or your agent's skills folder).
name
agentbox-setup
description
Generate an agentbox.yaml for the current AgentBox workspace. Invoke when the user opens a sandbox without an agentbox.yaml or asks to (re)configure one.

/agentbox-setup

Box layout (what you're configuring against)

Your user i vscode and you can use sudo to run commands as root.

/workspace is where the user code lives, a per-box git worktree on a fresh agentbox/<box-name> branch (or a tar-piped copy of the host workspace for non-git projects). Run agentbox checkpoint --set-default (similar to docker commit) to save any changes make to the system and workspace so that new boxes will start from a warm state. Everything is wiped on agentbox destroy.

Some special folders:

  • Host main repo's .git/ — If the box bind-mounted RW at its identical absolute host path. In-box commits land on the host's branch refs (visible to git log on the host immediately); the box itself carries no SSH/git creds, so git push goes through the host relay (agentbox-ctl git push). The host's working tree is never written to — only refs/objects under .git/. GitHub PR ops (agentbox-ctl git pr create|view|list|comment|review|merge|close|reopen|checkout) flow the same way through host gh; write ops require host confirmation (deny → exit 10), merge and checkout have additional opt-in guards.
  • ~/.claude — and similar home folders for coding agents are seeded from the host's ~/.claude on each create so auth, skills, and plugins persist without leaking the host's home dir.
  • agentbox.yaml — read by agentbox-ctl from /workspace. Tasks and services declared here are what the supervisor will run.

Exposed ports and services:

  • portless - every port with expose: setting in agentbox.yaml, will be exposed not only as a local port but also as a special domain name https://<name>.localhost (so on https) using portless cli and proxy. This will be also mapped to the host where also portless proxy is running so users can access the same service on the same looking url.
  • vnc - the webVNC server exposed on 6080 will be proxies to the host on a random port.
  • vscode - the vscode server is proxied to the host on a random port.

Goal

Produce a /workspace/agentbox.yaml that captures this project's services, tasks, and box defaults so the in-box supervisor (agentbox-ctl) can boot the workspace deterministically.

agentbox.yaml is declarative. The supervisor reads it on box start, but you don't have to restart the box: after you write the file, agentbox-ctl reload (run from inside the box) makes the already-running supervisor re-read it and immediately run the declared tasks and autostart the services. See step 8.

1. Discover the project

Look at /workspace:

  • Top-level manifests: package.json, pyproject.toml / requirements.txt, Cargo.toml, go.mod, Gemfile, composer.json, mix.exs, etc. — these tell you the runtime.
  • docker-compose.yaml / docker-compose.yml — often lists the real services the project expects.
  • package.json → scripts: look for dev, start, build, test, migrate, seed.
  • Makefile / justfile / Taskfile.yaml — alternative task runners.
  • Listening ports: grep for listen(, PORT=, framework defaults (3000 for Next.js / Nuxt, 5173 for Vite, 8000 for Django, 8080 for Spring, etc.).
  • Database / cache deps to spin up locally (Postgres, Redis, …) — declare them as services if the project doesn't expect them to be external.

2. Pick services and tasks

  • Services = long-running. Web servers, watchers, queue workers, databases. restart: on-failure by default.
  • Tasks = one-shot. pnpm install, DB migrations, codegen, fixture loaders, install apt packages. Wire dependent services with needs: so they wait for the task to finish successfully.
  • Names: must match [A-Za-z0-9_-]+. Task names and service names share a namespace — no collisions.
  • No cycles in needs:.
  • Always generate a dependency-install task and make it the root of the needs: graph (every service that needs deps gets needs: [install, …]). Future boxes start from a snapshot of the final filesystem so they won't need this, but updates or moving to a cloud provider might need to rebuild the container from scratch. The filesystem can be then later captured by agentbox-ctl checkpoint --set-default. The task must be idempotent: agentbox-ctl re-runs pending tasks on every box stop/start (the daemon dies with the container and is relaunched), so an unguarded install would reinstall on every start. The clean way is the run_once: true field — the supervisor stores a marker keyed by a hash of the command and skips warm boots automatically (the marker lives at /var/lib/agentbox/tasks/<name>, on the box rootfs, captured by checkpoints, never polluting /workspace). Editing the command re-runs it. Detect the package manager from the lockfile — never hardcode pnpm. See the worked example below.
  • Add a comment to the beginning of the file to explain what you did and what issues you encountered, so that future run might use this information in case the project evolves and you need to update the agentbox.yaml file.
Stateful services: data persistence & re-seeding (read this for databases)

Declare a containerized dependency with the image: service form — AgentBox generates the docker start-or-run shell (no hand-written docker run … || docker start …). The container runs in the box's dockerd; a published port is reachable from other in-box services at 127.0.0.1:<host port>:

yaml
services:
  postgres:
    image:                            # bare string (image: postgres:17-alpine) or a mapping:
      name: postgres:17-alpine
      ports: ["5432:5432"]
      env:
        POSTGRES_PASSWORD: postgres
        POSTGRES_DB: app
      args: "-c max_connections=200"  # string or ["-c","max_connections=200"]
      container_name: app_db          # optional; default = service name
    ready_when: { port: 5432 }
    restart: always

The container is reused by name across box stop/start. (Changing image/env reuses the existing container as-is; docker rm <container_name> + agentbox-ctl reload to apply.) Install the DB client the migrate/seed tasks need (e.g. postgresql-client) in the install task and reach the DB over TCP — don't docker exec the container (nested exec fails with a setns error in a box).

A checkpoint does NOT capture docker-in-docker data. agentbox checkpoint is a docker commit of the box's writable filesystem (the system + /workspace). The in-box dockerd keeps its storage in a separate per-box volume (/var/lib/docker), which is not part of that image — it's fresh on every new box and wiped on agentbox destroy. So a database or cache you run as a docker container (e.g. docker run … postgres) starts empty on every new box created from a checkpoint (every agentbox claude / agentbox create), even though /workspace and any marker files you wrote were restored. (A DB run as a native process with its data dir on the box filesystem — e.g. postgres -D /var/lib/postgresql/data — is captured by the checkpoint, since it lives in the writable layer.)

Consequence for migrate/seed tasks of a containerized DB: do NOT use run_once: true (the marker form). A command-hash marker is correct for deps (they live in /workspace, which the checkpoint captures), but wrong for DB data living in a docker volume: the marker is restored from the checkpoint while the DB is empty, so a marker-guarded seed wrongly skips and the app boots against an empty database. Instead use the run_once: { check: <cmd> } form — the probe runs first and the seed runs unless the probe exits 0, and no marker is written (the DB is the source of truth). Gate on the actual data:

yaml
  seed:
    # Re-seed when the DB is empty. The postgres data lives in the in-box docker
    # volume, which is NOT captured by `agentbox checkpoint` — so a box started
    # from a checkpoint has the workspace warm but an empty DB. The marker form
    # would be restored while the DB is blank and wrongly skip; the `check` probe
    # gates on the data itself. Exit 0 = already seeded, skip. Fast no-op once
    # the data is present.
    command: pnpm db:seed
    needs: [install, migrate]
    run_once:
      check: |
        export PGPASSWORD=postgres
        psql -h 127.0.0.1 -p 5432 -U postgres -d app -tAc \
          "SELECT EXISTS (SELECT 1 FROM users LIMIT 1)" 2>/dev/null | grep -q t

Lifecycle nuance (this is why the data check, not a marker, is right):

  • Box stop → start (agentbox stop/start): the supervisor daemon dies with the container and is relaunched, so it re-runs all tasks from pending. The per-box docker volume does survive stop/start, so the DB still has data — the data check makes the seed a fast no-op.
  • New box from a checkpoint (agentbox claude/create): tasks run and the DB volume is empty → the check fails → the seed runs. Correct.
  • Resume after pause (agentbox pause/unpause): the daemon is frozen and thawed, not restarted, so tasks do not re-run at all — nothing to seed, the running DB is untouched.

(Migrations are usually safe to re-run as-is: migration tools track applied migrations in their own table, which on a fresh box is empty, so they simply re-apply. Only the data seed needs the existence check.) Install the DB client the seed/migrate tasks need (e.g. postgresql-client) in the install task — don't docker exec the DB container for these checks (nested docker exec fails inside a box with a setns error); reach it over TCP with the client tools instead.

3. Wire readiness probes (services only)

ready_when: lets the supervisor decide when a service is "ready" (vs. just "running"). Exactly one of these must be present:

  • port: 3000 — TCP connect (default host 127.0.0.1; override with host:).
  • log_match: "Listening on" — regex matched against stdout/stderr. First match flips the service to ready.
  • http: "http://127.0.0.1:3000/health" — GET probe. Optional expect_status: 200 (default: any 2xx).

Tunables: interval_ms (default 500), initial_delay_ms (default 0), timeout_ms (default 60000), on_timeout: kill | mark_unhealthy (default kill — re-enters the restart policy).

Mark the web service with expose:

The box's primary web app (the dev server / Next.js / API the user opens in a browser) should declare:

yaml
    expose:
      port: 3000   # the port this service listens on inside the box
      as: 80        # must be 80 — the container port AgentBox publishes

At most one service may set expose:. AgentBox forwards container :80 to 127.0.0.1:<port> and publishes it on the host with portless proxy to a <boxname>.localhost url, so agentbox list/status show it as the box's main URL on every engine (no OrbStack dependency). Set this on the same service whose ready_when: you just wrote (a DB or worker should not get expose:).

If the box hosts a SERVICE AGENT (openclaw), the units are already there

A service agent — agentbox openclaw today — is a daemon AgentBox itself runs. Its supervisor units (an openclaw-onboard one-shot, an openclaw-render, and the openclaw gateway service with ready_when: { http: /healthz } and expose: { port: 18789, as: 80 }) are synthesized from the agent's own catalog row and folded in at boot. Do not write them into agentbox.yaml — a unit of the same name in the workspace file WINS and would replace the one the agent ships.

Two things you may still need to write:

  • A different web app on :80. Only ONE service may expose:. If the project has its own web service that must be the box URL, the agent's expose: is dropped with a warning — decide which one the user wants and keep exactly one.
  • The openclaw: overlay block (see §11a below), for gateway config the user wants under version control.

4. Restart + backoff

Per service:

  • restart: always | on-failure | never (default on-failure).
  • backoff: — initial_ms (default 500), max_ms (default 30000; must be >= initial_ms), factor (default 2).

5. (Optional) defaults: block

Sets per-project defaults for agentbox create/claude/code/shell — same shape as ~/.agentbox/config.yaml. CLI flags still override. Common keys:

  • box.hostSnapshot (bool) — APFS-clone the host workspace into a per-box scratch dir before seeding /workspace (stabilizes the tar-pipe source).
  • box.defaultCheckpoint (string) — checkpoint new boxes start from (normally you set this via agentbox-ctl checkpoint --set-default at the end of setup — see section 9, not by hand).
  • box.withPlaywright (bool) — install @playwright/cli globally inside the box.
  • box.vnc (bool) — run Xvnc + noVNC on container port 6080.
  • box.isolateClaudeConfig (bool) — per-box ~/.claude volume instead of the shared one.
  • code.ide — vscode | cursor | auto.
  • code.autoTerminals (bool) — auto-generate .vscode/tasks.json with per-service tails.
  • browser.default — agent-browser | playwright | both.

Full key list (run on the host): agentbox config list --keys.

Show full SKILL.md (1,140 more words)Show less

6. Worked example

yaml
# yaml-language-server: $schema=https://agent-box.sh/schema/agentbox.schema.json
# This agentbox.yaml setup this Next.js project, and includes:
# - a postgres database because it's used in the project
# - an inngest server for queues
# - a fix to move .turbo/cache folder to the workspace to avoid a permission error during setup
# - ...
defaults:
  box:
    withPlaywright: true
  code:
    ide: cursor

tasks:
  # Idempotent install. /workspace is the container's writable filesystem, so
  # node_modules persists across pause/stop/start and is captured by
  # `agentbox checkpoint`. The host's node_modules is macOS-native and is
  # never copied in, so the first Linux install runs; `run_once: true` then
  # skips it on every subsequent box start (the supervisor stores a marker
  # keyed by a hash of the command). Adjust the lockfile detection to the
  # project's package manager.
  install:
    command: |
      set -e
      sudo apt-get update && sudo apt-get install -y postgresql-client
      if [ -f pnpm-lock.yaml ]; then
        corepack enable >/dev/null 2>&1 || true
        pnpm install --frozen-lockfile || pnpm install
      fi
    run_once: true

  migrate:
    command: pnpm db:migrate
    needs: [install]

services:
  postgres:
    command: postgres -D /var/lib/postgresql/data
    ready_when:
      port: 5432
    restart: always

  dev:
    command: pnpm dev
    needs: [install, migrate, postgres]
    ready_when:
      port: 3000
      timeout_ms: 120000
    expose:
      port: 3000
      as: 80
    restart: on-failure
    backoff:
      initial_ms: 500
      max_ms: 5000
      factor: 2

6b. Bringing extra host files/folders into the box

Two ways to copy host files in (both COPY — never a live mount, so the box can't write back to the host):

  • carry: block (declarative, in agentbox.yaml) — for files/dirs every box should get at create time. Each entry is { src, dest } with optional mode, user, optional, and exclude: (a list of tar globs / bare dir names to drop when copying a directory). Heavy regenerable dirs (.git, node_modules, bin, obj, packages, dist, .next, target) are dropped by default; exclude: is additive. Each carry entry is capped at box.cpMaxBytes (default 100 MiB after excludes) — the same limit agentbox cp enforces.
  • agentbox-ctl cp fromHost <hostPath...> <boxPath> (ad-hoc, from inside the box) — for a one-off copy. Takes several sources in one call (last path is the dest, which must be a directory). Prompts the user on the host to approve.

The per-copy size limit (important for large/legacy folders). A single copy is blocked above box.cpMaxBytes (default 100 MB) after default excludes, so it fails loud instead of silently hanging. When blocked you get a du-style tree of the biggest remaining folders/subfolders. To get under the limit, EITHER:

  • drop what the box can regenerate (the default excludes already remove node_modules/.git/build output; add more with --exclude=<glob-or-name>), OR
  • copy the heavy folders one at a time so each copy is under the limit, OR
  • pass --yes to copy the whole thing anyway (only when you really need it all).

Example: a 2.4 GB legacy folder is mostly packages/ (NuGet) + .git; those are excluded by default, and what's left can be copied in one call by listing the sub-folders into a destination directory: agentbox-ctl cp fromHost ../legacy/src ../legacy/Database /workspace/legacy/.

7. Validate before handing off

  • check with agentbox-ctl reload and then agentbox-ctl status that everything is running as expected.
  • Every name in needs: must reference an existing task or service.
  • A service with restart: never and an autostart dependency will block the dependent forever after one failed run — usually a mistake.
  • command: is either a shell string (run via bash -c) or an argv array. Use the argv form if you need to avoid shell quoting.

8. Hand-off

Tell the user (verbatim):

 █████╗  ██████╗ ███████╗███╗   ██╗████████╗██████╗  ██████╗ ██╗  ██╗
██╔══██╗██╔════╝ ██╔════╝████╗  ██║╚══██╔══╝██╔══██╗██╔═══██╗╚██╗██╔╝
███████║██║  ███╗█████╗  ██╔██╗ ██║   ██║   ██████╔╝██║   ██║ ╚███╔╝
██╔══██║██║   ██║██╔══╝  ██║╚██╗██║   ██║   ██╔══██╗██║   ██║ ██╔██╗
██║  ██║╚██████╔╝███████╗██║ ╚████║   ██║   ██████╔╝╚██████╔╝██╔╝ ██╗
╚═╝  ╚═╝ ╚═════╝ ╚══════╝╚═╝  ╚═══╝   ╚═╝   ╚═════╝  ╚═════╝ ╚═╝  ╚═╝

your box is ready, you can start more sessions with agentbox claude you can access the web app at https://<boxname>.localhost

9. Checkpoint the warm state - DON't SKIP THIS STEP

Checkpoint (snapshot) this box writable layer: once the box is warmed up (deps installed, services ready), checkpoint it with agentbox-ctl checkpoint --name setup --replace --set-default so future boxes start ready. Remember the checkpoint captures the writable layer (/workspace + system), not docker-in-docker volumes — so a containerized DB's data does not carry into new boxes. That's expected; the data-existence-gated seed task from section 2 re-seeds those automatically. (If you need the data itself to persist into new boxes, run the DB as a native process with its data dir on the box filesystem, or bind a /workspace path as the container's data volume so it lands in the checkpoint.) Run this command exactly once. The --name setup --replace makes it idempotent — if it ever needs to run again it overwrites the existing setup checkpoint instead of stacking duplicates. On all providers except Vercel, this doesn't need to be confirmed by the user. It will pause the container for several seconds so warn the user about it and write Done when it's done. On Vercel: this actually STOPS the sandbox, so warn the user about it. Also the system will ask confirmation.

10. Known issues

  • For Nextjs/Vite/Tasnstack projects, makes sure to forward also websocket for hot reload.

  • Service like flask, nextjs, BETTER_AUTH_URL, NEXT_PUBLIC_APP_URL should use the env-init {{AGENTBOX_BOX_HOST}} in agentbox.yaml so it will be automatically replaced.

  • The install task above uses run_once: true, so it is a no-op on warm boots. Do not wrap it in a manual marker check too. To force a one-off rebuild, run agentbox-ctl run-task install --force (which bypasses the run_once marker), or edit the command (a changed command invalidates the hash and re-runs).

11. Pin URLs / render config files (env, secrets)

Many apps hard-code a hostname (e.g. optima.localhost) or read a gitignored .env. Instead of long sed commands in a task, use the built-ins:

  • agentbox-ctl render <src> — a declarative sed for files already in the workspace. --env substitutes {{AGENTBOX_*}} placeholders; --rules <name> applies a named rule-set from the top-level replacements: block; --rule 'from=>to' / --rule-regex 'pat=>repl' are inline. Write to --out <path> (or --in-place). The whitelist placeholders are {{AGENTBOX_BOX_NAME}}, {{AGENTBOX_BOX_HOST}} (= <boxname>.localhost), {{AGENTBOX_BOX_ID}}, {{AGENTBOX_BOX_KIND}}, {{AGENTBOX_HOST_WORKSPACE}}, {{AGENTBOX_PROJECT_ROOT}}.

    Render a gitignored .env from a committed env.example on every boot, pinning the URLs to this box:

    yaml
    replacements:
      box-host:
        - { from: 'optima\.localhost', to: '{{AGENTBOX_BOX_HOST}}', regex: true }  # {{AGENTBOX_BOX_HOST}} = <box>.localhost
    
    tasks:
      env:
        # The render is idempotent (the rules re-pin the same lines every boot), so
        # no `run_once:` guard is needed — it self-corrects on a checkpoint-started
        # box that carries a different box's host in .env.
        command: agentbox-ctl render apps/saas/env.example --out apps/saas/.env --env --rules box-host

    Note: an run_once: { check: <cmd> } probe runs verbatim via bash -c with the box env — use shell vars like $AGENTBOX_BOX_NAME, NOT {{…}} placeholders (those are only expanded by render/carry, never by the supervisor).

    Generated secrets: put {{AGENTBOX_AUTO_SECRET}} in the template for a value like BETTER_AUTH_SECRET instead of shelling out to openssl rand. Unnamed → a fresh 32-byte base64url secret each render (stable when you render the template→.env once). {{AGENTBOX_AUTO_SECRET:better-auth}} → generated once, persisted at /var/lib/agentbox/secrets/<name>, reused on every render (stable even if you render every boot). Example env.example line: BETTER_AUTH_SECRET="{{AGENTBOX_AUTO_SECRET:better-auth}}".

11a. openclaw: — layered config for a service agent

A box created with agentbox openclaw accepts a top-level openclaw: block. It is an OVERLAY on the gateway's own ~/.openclaw/openclaw.json, applied through openclaw's own validated config patch --stdin merge by the openclaw-render task:

yaml
openclaw:
  logging:
    level: debug
  channels:
    telegram:
      enabled: true
      # NEVER a literal token here — agentbox.yaml is committed. See below.
      tokenEnv: TELEGRAM_BOT_TOKEN

Three rules:

  • Only the keys you CHANGE are sent. The render diffs the block against the overlay it applied last time, so a key you edit in the box by hand survives every later render — and re-appears under AgentBox's control the moment you name it here again.

  • Never put a secret in the block. agentbox.yaml is committed. Real values ride a carry: entry into a 0600 env file and the overlay references them by name; the render warns when a value looks like a literal secret.

  • Re-apply with agentbox-ctl run-task openclaw-render --force after editing the block on a live box. reload alone applies the unit diff, and the task itself has not changed.

  • Do not set gateway.bind or gateway.auth. The gateway binds loopback and generates its own token; AgentBox forwards :80 to it inside the container, which is both sufficient and safer. agentbox openclaw url prints the URL and that token.

  • carry: + replaceEnvs/replace/rules — for a host-only file (e.g. a real .env with secrets that never lives in the repo), carry it in and render it host-side in one step (file entries only):

    yaml
    carry:
      - src: ~/secrets/optima.env
        dest: /workspace/apps/saas/.env
        replaceEnvs: true
        rules: [box-host]

© madarco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in apps/cli/share/agentbox-setup of madarco/agentbox.

Open the folder on GitHubat commit 605ee75

Compare with similar skills

Agentbox Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agentbox Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agentbox Setup this skillmadarco/agentbox523—~5.9kAutomated safety check: NotesMIT
Build Px4 macOSPX4/PX4-Autopilot13k—~1.1kAutomated safety check: PassBSD-3-Clause
Workthreadsspecstoryai/getspecstory1.3k—~1.3kAutomated safety check: NotesApache-2.0
Git Conventionswerf/werf4.7k—~1.3kAutomated safety check: PassApache-2.0
Git Worktree Managermicrosoft/WindowsAppSDK4.7k—~2kAutomated safety check: PassMIT
Roo Conflict Resolutionzgsm-ai/costrict4.4k—~2.3kAutomated safety check: PassApache-2.0

Similar skills

  • Build Px4 macOS

    PX4/PX4-Autopilot

    Build PX4 board firmware on macOS in the px4-dev Docker container, including git worktrees, and stage commit-labeled artifacts without flashing hardware.

    13k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Workthreads

    specstoryai/getspecstory

    SpecStory Workthreads - a weekly work-thread rollup across a team's repos from SpecStory coding histories (any agent - Claude Code, Codex, Cursor, Gemini, and more).

    1.3k GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • werf conventions for branch names and commit messages. An agent skill from werf/werf.

    4.7k GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Git Worktree Manager

    microsoft/WindowsAppSDK

    Official

    Creates and manages Git worktrees with PowerShell scripts so separate issues and Copilot sessions each get an isolated branch, build and test environment.

    4.7k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Roo Conflict Resolution

    zgsm-ai/costrict

    Provides comprehensive guidelines for resolving merge conflicts intelligently using git history and commit context.

    4.4k GitHub stars~2.3k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Release

    PowerShell/vscode-powershell

    Guide for preparing a release of the PowerShell VS Code extension.

    1.9k GitHub stars~1.1k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

More from madarco/agentbox

  • Agentbox Info

    madarco/agentbox

    Spin up isolated sandboxes ("boxes") for coding agents, run them in parallel, queue background runs with -i, and push commits safely through the host relay.

    523 GitHub starsUsed in 1 repo~6.6k tokens
    Auto-check: warnings
  • Agentbox Identity

    madarco/agentbox

    Write this bot's identity replacement rules into agentbox.yaml, so a copy of it spawned with agentbox clone gets its own name instead of yours.

    523 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Agentbox

    madarco/agentbox

    Fork the current agent session into a new VM or local Docker container with all the project files, agent settings and session teleported into.

    523 GitHub stars~811 tokensUpdated today
    Auto-check: warnings

Categories

Questions about Agentbox Setup

What does Agentbox Setup do?

Generate an agentbox.yaml for the current AgentBox workspace. Agentbox Setup is an agent skill from madarco/agentbox.yaml for the current AgentBox workspace.

When should I use Agentbox Setup?

Agentbox Setup fits situations like: opens a sandbox without an agentbox.yaml; asks to (re)configure one.

How do I install Agentbox Setup in Claude Code?

Run `npx skills add madarco/agentbox --skill agentbox-setup -a claude-code`. Or copy the skill folder (apps/cli/share/agentbox-setup in madarco/agentbox) into .claude/skills/agentbox-setup in your project. Claude Code loads it when a task matches its description.

How do I install Agentbox Setup in Codex?

Run `npx skills add madarco/agentbox --skill agentbox-setup -a codex`. Or copy the skill folder (apps/cli/share/agentbox-setup in madarco/agentbox) into .agents/skills/agentbox-setup in your project. Codex loads it when a task matches its description.

Can I use Agentbox Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add madarco/agentbox --skill agentbox-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agentbox-setup, .gemini/skills/agentbox-setup, .github/skills/agentbox-setup and .opencode/skills/agentbox-setup in your project.

What does Agentbox Setup need to run?

Going by SKILL.md and its folder, Agentbox Setup needs the command-line tools its instructions call (docker, git, bash, pnpm, cursor and playwright) and credentials named AGENTBOX_AUTO_SECRET, BETTER_AUTH_SECRET, POSTGRES_PASSWORD and TELEGRAM_BOT_TOKEN. Our summary lists: Docker.

Does Agentbox Setup access the network?

SKILL.md names 1 domain. In commands or code: agent-box.sh; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Agentbox Setup safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo; mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Agentbox Setup use?

Agentbox Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agentbox Setup use?

About 5.9k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agentbox Setup?

Skills that share tags, products or a category with Agentbox Setup: Build Px4 macOS (PX4/PX4-Autopilot, 13k stars), Workthreads (specstoryai/getspecstory, 1.3k stars), Git Conventions (werf/werf, 4.7k stars) and Git Worktree Manager (microsoft/WindowsAppSDK, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agentbox Setup?

madarco (a GitHub user) maintains it in madarco/agentbox, which has 523 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.

Source: madarco/agentbox on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.