Agent skill

Operating In Agent Sandbox

by mattolson in mattolson/agent-sandbox

Read this when you are an AI coding agent running inside an Agent Sandbox container.

MITAuto-check passedDevelopment

Install Operating In Agent Sandbox

skills CLI
$ npx skills add mattolson/agent-sandbox --skill operating-in-agent-sandbox -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mattolson/agent-sandbox operating-in-agent-sandbox --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mattolson/agent-sandbox.git skills-src && mkdir -p .claude/skills && cp -r skills-src/images/base/skills/operating-in-agent-sandbox .claude/skills/operating-in-agent-sandbox && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
operating-in-agent-sandbox
GitHub stars
208
Token cost
~2k tokens
SKILL.md length
958 words
Files
2
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Read this when you are an AI coding agent running inside an Agent Sandbox container.

  • Works in 2 steps: Firewall (in your container). All direct… → Proxy (the proxy sidecar). All…
  • Tasks that involve Pull requests
  • SKILL.md covers Am I in a sandbox?, The network model (two…, Discover your actual limits and Quick checks you can run, plus 5 more sections
  • Calls gh and curl; reaches api.github.com; needs GH_TOKEN

What it does

Operating In Agent Sandbox is an agent skill from mattolson/agent-sandbox. Read this when you are an AI coding agent running inside an Agent Sandbox container. Explains the network proxy, allowlist policy, filesystem/git constraints, how to discover your own limits from the read-only .agent-sandbox directory, how to use GitHub (issues, pull requests, CI) through gh api, and what to do when a request fails with "Blocked by proxy policy" (HTTP 403) or a direct connection is refused. Use it before fighting a network/permission error or concluding a tool is broken.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `github-api.md`).

It sits in Development, covering Pull requests and Git workflow. It works with Git and GitHub. The repository describes itself as: Secure local dev environment for collaboration with AI coding agents. The licence is MIT.

When your agent uses it

  • Tasks that involve Pull requests
  • Tasks that involve Git workflow

Example prompts

  • “Blocked by proxy policy”
  • “/operating-in-agent-sandbox”

Requirements

  • Docker

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Firewall (in your container). All direct outbound traffic is dropped. Only the
  2. Proxy (the proxy sidecar). All HTTP/HTTPS must go through http://proxy:8080.

What it can do on your machine

Read from SKILL.md and the folder at commit c5b65e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Operating In Agent Sandbox loads about 2k tokens when it runs. Until then it costs about 130 tokens; SKILL.md has 958 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~130
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mattolson/agent-sandbox at commit c5b65e7, republished under its MIT licence (© mattolson). 958 words, ~1,986 tokens.

Download SKILL.mdSave it as .claude/skills/operating-in-agent-sandbox/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
operating-in-agent-sandbox
description
Read this when you are an AI coding agent running inside an Agent Sandbox container. Explains the network proxy, allowlist policy, filesystem/git constraints, how to discover your own limits from the read-only .agent-sandbox directory, how to use GitHub (issues, pull requests, CI) through `gh api`, and what to do when a request fails with "Blocked by proxy policy" (HTTP 403) or a direct connection is refused. Use it before fighting a network/permission error or concluding a tool is broken.

Operating Inside an Agent Sandbox

Agent Sandbox runs AI coding agents inside a locked-down local container. If you are reading this from inside one, your network is restricted and your filesystem is partly read-only by design. This is not a bug. Knowing the rules lets you work with the sandbox instead of wasting turns fighting it.

This skill is generic. The authoritative, current constraints for your specific sandbox always live in the read-only .agent-sandbox/ directory in your project root. Read those files; do not rely on memory or assumptions.

Am I in a sandbox?

You are almost certainly inside an Agent Sandbox if any of these hold:

  • HTTP_PROXY / HTTPS_PROXY are set to http://proxy:8080.
  • A read-only .agent-sandbox/ directory exists at the workspace root.
  • You are the non-root user dev (uid 501) and lack general sudo.
  • A proxy CA certificate is mounted at /etc/mitmproxy.

The network model (two enforcement layers)

  1. Firewall (in your container). All direct outbound traffic is dropped. Only the Docker host network — which includes the proxy sidecar — is reachable. A direct connection that bypasses the proxy is rejected immediately (ICMP admin-prohibited), so it fails fast rather than hanging. SSH outbound is disabled.

  2. Proxy (the proxy sidecar). All HTTP/HTTPS must go through http://proxy:8080. The standard proxy env vars are already set, so most tools (curl, git, package managers, language toolchains) use it automatically. The proxy enforces a domain/service allowlist. Anything not on the allowlist is blocked.

    • A blocked request returns HTTP 403 with body Blocked by proxy policy: <host>.
    • For HTTPS, the blocking CONNECT is refused before the tunnel opens.

The proxy is a TLS-terminating man-in-the-middle. Its CA cert is installed in the container's system trust store. Tools that use the system store just work. A tool that ships its own CA bundle (some Node, Python, Go setups) may report a certificate error — point it at the proxy CA file /etc/mitmproxy/ca.crt (e.g. NODE_EXTRA_CA_CERTS, REQUESTS_CA_BUNDLE, SSL_CERT_FILE) rather than disabling verification.

Discover your actual limits

The single most useful file is the effective allowlist, written by the proxy:

  • /run/agentbox/policy.yaml — the complete, sanitized list of hosts reachable through the proxy, with their allowed schemes/methods/paths. This is the merged result of every policy layer (agent baseline + user policy), rewritten on proxy startup and on each successful policy reload (SIGHUP). If a host is not in this file, requests to it return HTTP 403. Credentials and request-rewriting rules are intentionally omitted. (Older sandboxes may not export this file yet; if it is missing, fall back to the .agent-sandbox/ files below and to probing.)

For the editable inputs and your runtime config, read these under the read-only .agent-sandbox/ mount:

  • active-target.env — which agent is active and the project name.
  • policy/user.policy.yaml — shared user-owned allowlist (applies to every agent).
  • policy/user.agent.<agent>.policy.yaml — extra allowlist for the active agent only.
  • compose/base.yml and compose/agent.<agent>.yml — mounts, volumes, and env you run with.

Note: the .agent-sandbox/policy/*.yaml files show only the user-editable layer. Each agent also has a baseline allowlist (its own API, auth, and CDN endpoints) that is merged in but is not authored in these files. The baseline is reflected in /run/agentbox/policy.yaml. When unsure whether a host is allowed, check that file, or just try the request and read the result.

Allowlist entries take two forms:

yaml
services:          # symbolic bundles, e.g. github, claude — expand to known host sets
  - github
domains:           # explicit hosts; wildcards like "*.example.com" are allowed
  - raw.githubusercontent.com

Quick checks you can run

bash
# Should succeed only if the GitHub API is allowed for this repository (the
# allowlist is scoped to repository paths, so the API root itself returns 403):
curl -sS -o /dev/null -w '%{http_code}\n' https://api.github.com/repos/OWNER/REPO

# A 403 body of "Blocked by proxy policy: <host>" means the host is not allowed.
# A direct (non-proxy) attempt is refused by the firewall, not the proxy:
curl --noproxy '*' --connect-timeout 3 https://example.com   # expected to fail
Show full SKILL.md (419 more words)Show less

What you cannot do (stop and don't retry)

  • You cannot change network policy from inside the container. .agent-sandbox/ is mounted read-only, and policy only takes effect after a proxy reload or restart, which is a host-side action. Editing those files from inside will fail or have no effect.
  • The agentbox CLI is not yours to run — it runs on the host, not in this container.
  • You cannot bypass the firewall or proxy. No SSH, no direct sockets, no alternate egress. Retrying a blocked request, disabling TLS verification, or hunting for another route wastes turns and won't work.

What to do when something is blocked

  1. Confirm the cause. Blocked by proxy policy: <host> = host not on the allowlist. A connection refused/admin-prohibited on a direct attempt = firewall; route it through the proxy instead (usually automatic via the env vars).

  2. Check whether the host is already allowed in /run/agentbox/policy.yaml (or, failing that, .agent-sandbox/policy/*.yaml).

  3. Prefer an allowlisted alternative if one exists (e.g. a mirror or registry that is already permitted).

  4. If you genuinely need a blocked host, ask the human rather than working around it. Give them the exact host(s) and a ready-to-paste snippet, e.g.:

    I need outbound access to pypi.org and files.pythonhosted.org. Add to .agent-sandbox/policy/user.policy.yaml:

    yaml
    domains:
      - pypi.org
      - files.pythonhosted.org

    Then on the host run agentbox proxy reload to apply it (or agentbox compose restart proxy). (agentbox policy config shows the effective allowlist.)

Filesystem and git

  • /workspace is your project and is writable. .agent-sandbox/ is read-only.
  • Git remotes are rewritten from SSH to HTTPS, and outbound git goes through the proxy. Push/pull works only for repos the policy allows.
  • Credentials are injected at the proxy via credential shims; you will not see raw tokens as env vars, and you do not need them — authenticated requests to allowed services are handled for you. Env vars such as GH_TOKEN=agentbox-proxy-managed are placeholders the proxy replaces in flight. Leave them alone.

GitHub issues, pull requests, and CI

If api.github.com appears in /run/agentbox/policy.yaml, you can read and write issues and pull requests for the allowed repository with gh api repos/{owner}/{repo}/.... The high-level gh pr and gh issue commands use GraphQL and are blocked; do not retry them. Read github-api.md next to this file for the validated commands, paging, and what stays blocked.

Bottom line

Treat blocks as guardrails carrying information, not obstacles to defeat. Read .agent-sandbox/ to learn the rules, prefer what's already allowed, and when you truly need more access, hand the human a precise, minimal request they can apply on the host.

© mattolson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in images/base/skills/operating-in-agent-sandbox of mattolson/agent-sandbox.

  • SKILL.md
  • github-api.md

Open the folder on GitHubat commit c5b65e7

Compare with similar skills

Operating In Agent Sandbox next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Operating In Agent Sandbox compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Operating In Agent Sandbox this skillmattolson/agent-sandbox208—~2kAutomated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Creating Description For Gh PRredis/jedis12k—~838Automated safety check: PassMIT
Create Pull Request with Work Item IDmakeplane/plane61k—~824Automated safety check: PassAGPL-3.0
React Router Pull Request Creatorremix-run/react-router57k—~2.5kAutomated safety check: PassMIT

Similar skills

  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Official

    Generate a clear, concise GitHub PR title and description from the diff between two local git branches, and save it to prDescription.md in the repo root.

    12k GitHub stars~838 tokensUpdated today
    DevelopmentAuto-check passed
  • Opens a pull request for the current branch using the repo's template, a work item ID in the title and a description filled in from the actual diff.

    61k GitHub stars~824 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • React Router Pull Request Creator

    remix-run/react-router

    Packages finished React Router work into a draft pull request: branch, commit, push, a written PR body and the right GitHub labels.

    57k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Pascal Editor PR Opener

    pascalorg/editor

    Opens or refreshes a pull request on pascalorg/editor from the current branch, describing only what the branch's commits and diff actually contain.

    25k GitHub stars~619 tokensUpdated today
    DevelopmentAuto-check passed

More from mattolson/agent-sandbox

  • Plan

    mattolson/agent-sandbox

    Entry point for the three-tier planning system. An agent skill from mattolson/agent-sandbox.

    208 GitHub stars~1.1k tokensUpdated 8 days ago
    Auto-check passed
  • Plan Milestone

    mattolson/agent-sandbox

    Break a milestone into discrete tasks. An agent skill from mattolson/agent-sandbox.

    208 GitHub stars~1.1k tokensUpdated 8 days ago
    Auto-check passed
  • Plan Project

    mattolson/agent-sandbox

    Create a project plan for a new initiative. An agent skill from mattolson/agent-sandbox.

    208 GitHub stars~1.1k tokensUpdated 8 days ago
    Auto-check passed
  • Plan Task

    mattolson/agent-sandbox

    Plan and track execution of a task. An agent skill from mattolson/agent-sandbox.

    208 GitHub stars~1.4k tokensUpdated 8 days ago
    Auto-check passed
  • Add Agent

    mattolson/agent-sandbox

    Add a new AI coding agent to Agent Sandbox. An agent skill from mattolson/agent-sandbox.

    208 GitHub stars~3.2k tokensUpdated 8 days ago
    Auto-check passed

Works with

Categories

Questions about Operating In Agent Sandbox

What does Operating In Agent Sandbox do?

Read this when you are an AI coding agent running inside an Agent Sandbox container. Operating In Agent Sandbox is an agent skill from mattolson/agent-sandbox. Read this when you are an AI coding agent running inside an Agent Sandbox container.

When should I use Operating In Agent Sandbox?

Operating In Agent Sandbox fits situations like: tasks that involve Pull requests; tasks that involve Git workflow.

How do I install Operating In Agent Sandbox in Claude Code?

Run `npx skills add mattolson/agent-sandbox --skill operating-in-agent-sandbox -a claude-code`. Or copy the skill folder (images/base/skills/operating-in-agent-sandbox in mattolson/agent-sandbox) into .claude/skills/operating-in-agent-sandbox in your project. Claude Code loads it when a task matches its description.

How do I install Operating In Agent Sandbox in Codex?

Run `npx skills add mattolson/agent-sandbox --skill operating-in-agent-sandbox -a codex`. Or copy the skill folder (images/base/skills/operating-in-agent-sandbox in mattolson/agent-sandbox) into .agents/skills/operating-in-agent-sandbox in your project. Codex loads it when a task matches its description.

Can I use Operating In Agent Sandbox in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mattolson/agent-sandbox --skill operating-in-agent-sandbox -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/operating-in-agent-sandbox, .gemini/skills/operating-in-agent-sandbox, .github/skills/operating-in-agent-sandbox and .opencode/skills/operating-in-agent-sandbox in your project.

What does Operating In Agent Sandbox need to run?

Going by SKILL.md and its folder, Operating In Agent Sandbox needs the command-line tools its instructions call (gh and curl) and credentials named GH_TOKEN. Our summary lists: Docker.

Does Operating In Agent Sandbox access the network?

SKILL.md names 1 domain. In commands or code: api.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Operating In Agent Sandbox safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Operating In Agent Sandbox use?

Operating In Agent Sandbox is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Operating In Agent Sandbox use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Operating In Agent Sandbox?

Skills that share tags, products or a category with Operating In Agent Sandbox: Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), Create Pull Request (cline/cline, 70k stars), Creating Description For Gh PR (redis/jedis, 12k stars) and Create Pull Request with Work Item ID (makeplane/plane, 61k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Operating In Agent Sandbox?

mattolson (a GitHub user) maintains it in mattolson/agent-sandbox, which has 208 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 1, 2026.

Source: mattolson/agent-sandbox on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.