Agent skill

Ma Sandbox Debug

by michelangelo-ai in michelangelo-ai/michelangelo

Tail logs, inspect pods, and diagnose unhealthy services in a running Michelangelo sandbox.

Apache-2.0Auto-check passedDevOps & Cloud

Install Ma Sandbox Debug

skills CLI
$ npx skills add michelangelo-ai/michelangelo --skill ma-sandbox-debug -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install michelangelo-ai/michelangelo ma-sandbox-debug --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/michelangelo-ai/michelangelo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/ma-sandbox-debug .claude/skills/ma-sandbox-debug && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ma-sandbox-debug
GitHub stars
118
Token cost
~1k tokens
SKILL.md length
347 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Tail logs, inspect pods, and diagnose unhealthy services in a running Michelangelo sandbox.

  • Works in 3 steps: Health overview → Tail logs by service → Inspect a crashing pod
  • A service is crashlooping
  • SKILL.md covers Step 1: Health overview, Step 2: Tail logs by service, Need more verbose logs? and Step 3: Inspect a crashing pod, plus 5 more sections
  • Calls kubectl, git and bash

What it does

Ma Sandbox Debug is an agent skill from michelangelo-ai/michelangelo. Tail logs, inspect pods, and diagnose unhealthy services in a running Michelangelo sandbox. Use when a service is crashlooping, returning errors, or not responding as expected. Triggers on "check logs", "why is X failing", "debug sandbox", "kubectl logs".

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes. The repository describes itself as: Michelangelo AI: Uber's end-to-end machine learning platform. The licence is Apache-2.0.

When your agent uses it

  • A service is crashlooping
  • Returning errors
  • Not responding as expected
  • Why is X failing

Example prompts

  • “check logs”
  • “why is X failing”
  • “debug sandbox”
  • “/ma-sandbox-debug”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Health overview
  2. Tail logs by service
  3. Inspect a crashing pod

What it can do on your machine

Read from SKILL.md and the folder at commit f672cca. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • git
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ma Sandbox Debug loads about 1k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 347 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from michelangelo-ai/michelangelo at commit f672cca, republished under its Apache-2.0 licence (© michelangelo-ai). 347 words, ~1,030 tokens.

Download SKILL.mdSave it as .claude/skills/ma-sandbox-debug/SKILL.md (or your agent's skills folder).
name
ma-sandbox-debug
description
Tail logs, inspect pods, and diagnose unhealthy services in a running Michelangelo sandbox. Use when a service is crashlooping, returning errors, or not responding as expected. Triggers on "check logs", "why is X failing", "debug sandbox", "kubectl logs".
user-invocable
true

Sandbox Debug

Diagnosing service failures in a running sandbox. Start with health overview, then drill into specific services.

Step 1: Health overview

bash
ma sandbox health        # high-level check: cluster, pods, API, envoy, UI
kubectl get pods -A      # full pod inventory with status

IF kubectl get pods -A output contains any pod in CrashLoopBackOff, Error, or ImagePullBackOff state (excluding expected noise listed below): proceed to Step 3 for each affected pod.

IF a pod is stuck Pending beyond 3 minutes: proceed to Step 3 for that pod.

IF all pods show Running or Completed: report the cluster as healthy and stop — do not continue to Step 2 unless the user reports a specific symptom.

Step 2: Tail logs by service

bash
# apiserver — handles all API requests (Go)
kubectl logs -f deployment/michelangelo-apiserver

# worker — handles async tasks
kubectl logs -f deployment/michelangelo-worker

# controller manager
kubectl logs -f deployment/michelangelo-controllermgr

# envoy — ingress proxy (proxy errors appear here, not in apiserver)
kubectl logs -f deployment/michelangelo-envoy

# UI — nginx serving the frontend bundle
kubectl logs -f deployment/michelangelo-ui

Useful flags: --tail=100 to limit output; --previous to see logs from the last crashed container instance.

Need more verbose logs?

Go services default to info level. Enable debug logging for deeper investigation:

bash
bash $(git rev-parse --show-toplevel)/.claude/skills/ma-sandbox-scripts/set_log_level.sh controllermgr debug

Revert when done: replace debug with info. Pair with $(git rev-parse --show-toplevel)/.claude/skills/ma-sandbox-scripts/capture_service_logs.sh to filter the resulting output down to signal.

Step 3: Inspect a crashing pod

bash
# Get the pod name
kubectl get pods -l app.kubernetes.io/component=apiserver

# Events and last exit reason
kubectl describe pod <pod-name>

# Logs from the previous crashed instance
kubectl logs <pod-name> --previous

The Events section and Last State (exit code, reason) in describe output are the most diagnostic fields.

Common failure patterns

SymptomWhere to lookLikely cause
UI loads, API returns 503envoy logsEnvoy can't reach apiserver
UI loads but shows no datakubectl get projects,pipelines,pipelineruns -ANo demo data seeded — run ma sandbox demo pipeline. If resources exist but UI is empty, check envoy logs
API returns 500apiserver logsGo panic or DB connection error
Pod in CrashLoopBackOffdescribe pod, --previous logsOOM, missing config, bad binary
Pod stuck Pendingdescribe pod EventsNo node resources or PVC mount failure
ImagePullBackOffdescribe pod EventsImage not imported — run k3d image import
Feature broken after deployapiserver logsBusiness logic bug in the deployed binary
create failed partway / "cluster already exists"—Run ma sandbox sync to finish — don't delete+recreate

Filter logs for errors

bash
kubectl logs deployment/michelangelo-apiserver | grep -i "error\|panic\|fatal"
kubectl logs deployment/michelangelo-worker --tail=200

Force-restart a stuck service

When a service isn't crashing but isn't picking up new config or code:

bash
kubectl rollout restart deployment/michelangelo-apiserver
kubectl rollout status deployment/michelangelo-apiserver --timeout=60s

Expected noise (not actual errors)

  • cadence-schema-init, ingester-schema-init, sandbox-bucket-setup — reach Completed and stay there; this is correct

Still stuck?

If the cluster state is unrecoverable, do a full reset: /ma-sandbox-reset.

© michelangelo-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/ma-sandbox-debug of michelangelo-ai/michelangelo.

Open the folder on GitHubat commit f672cca

Compare with similar skills

Ma Sandbox Debug next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ma Sandbox Debug compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ma Sandbox Debug this skillmichelangelo-ai/michelangelo118—~1kAutomated safety check: PassApache-2.0
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k—~3.1kAutomated safety check: PassCustom licence
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28013 repos~381Automated safety check: PassGPL-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0

Similar skills

  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 13 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from michelangelo-ai/michelangelo

All 9 skills in this repo
  • Ma Sandbox Deploy

    michelangelo-ai/michelangelo

    Build a Go service binary, package it into a Docker image, import into k3d, and deploy via helm sync.

    118 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Ma Sandbox Setup

    michelangelo-ai/michelangelo

    Canonical setup sequence for the Michelangelo local sandbox.

    118 GitHub stars~936 tokensUpdated today
    Auto-check passed
  • Ma Sandbox Test Plan

    michelangelo-ai/michelangelo

    Build, test, and verify a sandbox change across Go, JS, and Python.

    118 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Update Docs

    michelangelo-ai/michelangelo

    Update Michelangelo documentation. An agent skill from michelangelo-ai/michelangelo.

    118 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Ma Design Interview

    michelangelo-ai/michelangelo

    Structured interview for designing and implementing changes to the Michelangelo platform.

    118 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Ma Sandbox Reset

    michelangelo-ai/michelangelo

    Tear down the Michelangelo sandbox cluster and recreate it from scratch.

    118 GitHub stars~312 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Ma Sandbox Debug

What does Ma Sandbox Debug do?

Tail logs, inspect pods, and diagnose unhealthy services in a running Michelangelo sandbox. Ma Sandbox Debug is an agent skill from michelangelo-ai/michelangelo. Tail logs, inspect pods, and diagnose unhealthy services in a running Michelangelo sandbox.

When should I use Ma Sandbox Debug?

Ma Sandbox Debug fits situations like: A service is crashlooping; returning errors; not responding as expected; why is X failing.

How do I install Ma Sandbox Debug in Claude Code?

Run `npx skills add michelangelo-ai/michelangelo --skill ma-sandbox-debug -a claude-code`. Or copy the skill folder (.claude/skills/ma-sandbox-debug in michelangelo-ai/michelangelo) into .claude/skills/ma-sandbox-debug in your project. Claude Code loads it when a task matches its description.

How do I install Ma Sandbox Debug in Codex?

Run `npx skills add michelangelo-ai/michelangelo --skill ma-sandbox-debug -a codex`. Or copy the skill folder (.claude/skills/ma-sandbox-debug in michelangelo-ai/michelangelo) into .agents/skills/ma-sandbox-debug in your project. Codex loads it when a task matches its description.

Can I use Ma Sandbox Debug in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add michelangelo-ai/michelangelo --skill ma-sandbox-debug -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ma-sandbox-debug, .gemini/skills/ma-sandbox-debug, .github/skills/ma-sandbox-debug and .opencode/skills/ma-sandbox-debug in your project.

What does Ma Sandbox Debug need to run?

Going by SKILL.md and its folder, Ma Sandbox Debug needs the command-line tools its instructions call (kubectl, git and bash).

Does Ma Sandbox Debug access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ma Sandbox Debug safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ma Sandbox Debug use?

Ma Sandbox Debug is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ma Sandbox Debug use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ma Sandbox Debug?

Skills that share tags, products or a category with Ma Sandbox Debug: Kubeshark Installer (kubeshark/kubeshark, 12k stars), KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Sim Helm (simstudioai/sim, 30k stars) and Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ma Sandbox Debug?

michelangelo-ai (a GitHub organization) maintains it in michelangelo-ai/michelangelo, which has 118 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 9, 2026.

Source: michelangelo-ai/michelangelo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.