Agent skill

Sandbox Dsl

by nodetool-ai in nodetool-ai/nodetool

Build a NodeTool workflow graph in the sandbox from generated node wrappers, one importable module per node namespace

AGPL-3.0Auto-check passedDocuments & Office

Install Sandbox Dsl

skills CLI
$ npx skills add nodetool-ai/nodetool --skill sandbox-dsl -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nodetool-ai/nodetool sandbox-dsl --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nodetool-ai/nodetool.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/sandbox-packs/sandbox-dsl .claude/skills/sandbox-dsl && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sandbox-dsl
GitHub stars
560
Token cost
~1.4k tokens
SKILL.md length
618 words
Files
80 (incl. scripts)
Skills in repo
127
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Build a NodeTool workflow graph in the sandbox from generated node wrappers, one importable module per node namespace

  • Documents & Office work in your project
  • SKILL.md covers Build a graph, Check it, save it, run it, Wiring and Ids, plus 2 more sections
  • Runs JavaScript scripts from its folder

What it does

Sandbox Dsl is an agent skill from nodetool-ai/nodetool. Build a NodeTool workflow graph in the sandbox from generated node wrappers, one importable module per node namespace

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 81 other files, including scripts (for example `package.json`, `sandbox/authoring.js` and `sandbox/core.js`).

It sits in Documents & Office. The repository describes itself as: Agent-first Creative Workspace. The licence is AGPL-3.0.

When your agent uses it

  • Documents & Office work in your project

Example prompts

  • “/sandbox-dsl”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 339f069. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sandbox Dsl loads about 1.4k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 618 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from nodetool-ai/nodetool at commit 339f069, republished under its AGPL-3.0 licence (© nodetool-ai). 618 words, ~1,407 tokens.

Download SKILL.mdSave it as .claude/skills/sandbox-dsl/SKILL.md (or your agent's skills folder). This skill also uses 79 other files; get the full folder from GitHub.
name
sandbox-dsl
description
Build a NodeTool workflow graph in the sandbox from generated node wrappers, one importable module per node namespace

The workflow DSL in the sandbox

Specifier: @nodetool-ai/sandbox-dsl. The root exports workflow() and every namespace under a short name. Each namespace is also its own module: @nodetool-ai/sandbox-dsl/nodetool.image, @nodetool-ai/sandbox-dsl/lib.audio, and so on for all 71.

Every node type is a generated function whose name and inputs come from the node's own metadata. A type this pack does not export does not exist, and the import fails before the program runs — which is the difference from building a graph out of type strings.

Build a graph

js
import { workflow } from "@nodetool-ai/sandbox-dsl";
import { stringInput } from "@nodetool-ai/sandbox-dsl/nodetool.input";
import { resize } from "@nodetool-ai/sandbox-dsl/nodetool.image";
import { output } from "@nodetool-ai/sandbox-dsl/nodetool.output";

const prompt = stringInput({ name: "prompt", value: "a fox in snow" });
const smaller = resize({ width: 256, height: 256 });
return workflow(output({ name: "image", value: smaller.output() }));

workflow() returns { nodes, edges } in the kernel shape — nodes carry {id, type, properties}, edges carry {id, source, sourceHandle, target, targetHandle}. Hand that straight to validate_workflow or create_workflow.

Check it, save it, run it

The graph is data until something checks it. Validate first — it costs nothing and catches a missing property, a dangling edge, or a model nobody selected before a run spends money on the half of the graph that does work:

js
import { validate_workflow, create_workflow, run_workflow, debug_workflow }
  from "@nodetool-ai/sandbox-nodetool/workflows";

const graph = workflow(output({ name: "image", value: smaller.output() }));

const check = await validate_workflow({ graph });
if (!check.ok) throw new Error(check.issues.map((i) => i.message).join("; "));

validate_workflow answers {ok, counts, issues} — ok is false only when the graph has errors, and each issue carries {severity, code, message}. Warnings do not set ok false; read them off issues.

js
const saved = await create_workflow({ name: "Thumbnailer", graph });
const run = await run_workflow({
  workflow_id: saved.id,
  params: { prompt: "a fox in snow" }
});

run_workflow answers {status, outputs}. When a run fails and the graph looks right, debug_workflow({workflow_id, params}) runs it again and answers one report: {workflow_id, run, job, workflow}. run carries {status, outputs, error, verdict} — outputs is keyed by output name and each name holds an array of emitted values (run.outputs.image[0]). job carries status, cost and logs; verdict.headline and verdict.issues say which node failed and why.

Every model property must be selected before you save: assign a find_model result's ref to the node's model. A graph saved with unselected models is refused by create_workflow, because nothing stamps models in at run time.

Where the session mounts no capability modules, the same three verbs are nodetool.workflows.validate/create/run/debug. Both forms reach one implementation past one permission gate.

Wiring

A node function returns a reference. ref.output() is the default output slot; ref.output("mask") names one. Pass a handle as a property value and the edge is wired for you:

js
const wired = resize({ image: source.output(), width: 512 });

A list[...] input takes an array of handles — one edge per element, and the sources run in parallel:

js
const strip = combineImageGrid({
  tiles: [a.output(), b.output(), c.output()],
  columns: 3
});

Every element must be a handle; mixing wired outputs and literal values in one array throws. A handle buried inside an object value throws too — a connection is only made from a handle assigned directly to an input.

A node with several outputs has no default, so output() without a slot throws and names the slots it has. A slot the node does not have throws the same way.

Show full SKILL.md (192 more words)Show less

Ids

Ids are assigned from the node type: resize, resize_2, string_input. They are stable for a given program, so a later edit can name one — but the generated wrappers take inputs and nothing else, so a program cannot choose an id.

Everything in one import

js
import * as dsl from "@nodetool-ai/sandbox-dsl";

const smaller = dsl.image.resize({ width: 256, height: 256 });
return dsl.workflow(dsl.output.output({ name: "image", value: smaller.output() }));

The nodetool.* namespaces drop the prefix (dsl.image, dsl.input, dsl.text); the rest keep it in camel case (dsl.libAudio, dsl.openaiImage). Importing one namespace module is cheaper than the root, which pulls all 71.

Gotchas

  • workflow() lives only at the root. A program that imports namespace subpaths still declares @nodetool-ai/sandbox-dsl for the builder.
  • A handle is not text. `use ${node.output()}` throws rather than writing [object Object] into a property and wiring no edge.
  • Only reachable nodes ship. workflow(terminal) walks back from its terminals; a node nothing wires to is dropped. Pass every terminal you want.
  • One graph per call. workflow() clears the registry, so a handle from an earlier call is spent and using it throws.
  • This builds a graph; it does not run one. The pack is pure computation — no models are called, no assets resolve, no node executes. Run the graph through the workflow tools once it validates.

© nodetool-ai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 79 other files (scripts) in packages/sandbox-packs/sandbox-dsl of nodetool-ai/nodetool.

  • SKILL.md
  • package.json
  • sandbox/authoring.js
  • sandbox/core.js
  • sandbox/generated/gemini.audio.js
  • sandbox/generated/gemini.image.js
  • sandbox/generated/gemini.text.js
  • sandbox/generated/gemini.video.js
  • sandbox/generated/index.js
  • sandbox/generated/kie.dynamic_schema.js
  • sandbox/generated/lib.audio.js
  • sandbox/generated/lib.browser.js
  • sandbox/generated/lib.charts.js
  • sandbox/generated/lib.comfy.js
  • sandbox/generated/lib.grid.js
  • sandbox/generated/lib.image.channel.js
  • sandbox/generated/lib.image.color.js
  • sandbox/generated/lib.image.color_grading.js
  • sandbox/generated/lib.image.draw.js
  • … and 61 more

Open the folder on GitHubat commit 339f069

Compare with similar skills

Sandbox Dsl next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sandbox Dsl compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sandbox Dsl this skillnodetool-ai/nodetool560—~1.4kAutomated safety check: PassAGPL-3.0
Markdown Article FormatterJimLiu/baoyu-skills27k6 repos~3.5kAutomated safety check: PassMIT
MarkitdownImCa0/just-laws78114 repos~3.2kAutomated safety check: NotesMIT
Obsidian MarkdownAtmosphere/atmosphere3.8k20 repos~1.3kAutomated safety check: PassApache-2.0
DOCXrvdbreemen/OTGW-firmware20733 repos~4.3kAutomated safety check: PassProprietary
Word Document Reader and WriterHKUDS/DeepTutor41k—~2.5kAutomated safety check: PassApache-2.0

Similar skills

  • Markdown Article Formatter

    JimLiu/baoyu-skills

    Reformats plain text or Markdown articles with frontmatter, a title, a summary, headings, bold, lists and code blocks, and saves a separate formatted copy.

    27k GitHub starsUsed in 6 repos~3.5k tokens
    Documents & OfficeAuto-check passed
  • Markitdown

    ImCa0/just-laws

    Convert files and office documents to Markdown. An agent skill from ImCa0/just-laws.

    781 GitHub starsUsed in 14 repos~3.2k tokens
    Documents & OfficeAuto-check: notes
  • Obsidian Markdown

    Atmosphere/atmosphere

    Create and edit Obsidian Flavored Markdown with wikilinks, embeds, callouts, properties, and other Obsidian-specific syntax.

    3.8k GitHub starsUsed in 20 repos~1.3k tokens
    Documents & OfficeAuto-check passed
  • DOCX

    rvdbreemen/OTGW-firmware

    A skill your agent uses whenever the user wants to create, read, edit, or manipulate Word documents (.docx files).

    207 GitHub starsUsed in 33 repos~4.3k tokens
    Documents & OfficeAuto-check passed
  • Reads, creates and edits Word .docx files with python-docx, and drops to raw OOXML for tracked changes, comments and byte-exact edits.

    41k GitHub stars~2.5k tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed
  • Crossposting

    wasp-lang/wasp

    Crosspost Wasp blog articles (MDX) to DEV.to and Medium. An agent skill from wasp-lang/wasp.

    19k GitHub stars~1.1k tokensUpdated today
    Documents & OfficeAuto-check passed

More from nodetool-ai/nodetool

All 127 skills in this repo
  • Beat Sync Editing

    nodetool-ai/nodetool

    Cut a NodeTool timeline to music and shape its pacing — detect the beat grid, place cuts on phrases, pick a cut type, build speed ramps with time remap, and give the piece an arc.

    560 GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Caption Titles

    nodetool-ai/nodetool

    Add and animate a consistent text layer on an existing NodeTool timeline.

    560 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Color Motion

    nodetool-ai/nodetool

    Choose and animate colour on a NodeTool timeline, including shape and text gradients, colour grades, 3D LUTs, and dither.

    560 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Commercial Beat Sheet

    nodetool-ai/nodetool

    Write a shootable, precisely timed commercial beat sheet and store it as a NodeTool storyboard, with a consistent entity roster behind every shot.

    560 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Elevenlabs Audio Prompting

    nodetool-ai/nodetool

    Direct ElevenLabs speech, dialogue, sound effects and music — the bracketed audio tags v3 acts on and why the voice decides whether a tag lands, stability as the delivery dial, punctuation instead…

    560 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Frame Composition

    nodetool-ai/nodetool

    Stage the frame on a NodeTool timeline — grids, focal placement, safe areas per aspect ratio, depth layers and parallax, camera moves, and where elements enter and leave.

    560 GitHub stars~3.5k tokensUpdated today
    Auto-check passed

Questions about Sandbox Dsl

What does Sandbox Dsl do?

Build a NodeTool workflow graph in the sandbox from generated node wrappers, one importable module per node namespace. Sandbox Dsl is an agent skill from nodetool-ai/nodetool.

When should I use Sandbox Dsl?

Sandbox Dsl fits situations like: documents & Office work in your project.

How do I install Sandbox Dsl in Claude Code?

Run `npx skills add nodetool-ai/nodetool --skill sandbox-dsl -a claude-code`. Or copy the skill folder (packages/sandbox-packs/sandbox-dsl in nodetool-ai/nodetool) into .claude/skills/sandbox-dsl in your project. Claude Code loads it when a task matches its description.

How do I install Sandbox Dsl in Codex?

Run `npx skills add nodetool-ai/nodetool --skill sandbox-dsl -a codex`. Or copy the skill folder (packages/sandbox-packs/sandbox-dsl in nodetool-ai/nodetool) into .agents/skills/sandbox-dsl in your project. Codex loads it when a task matches its description.

Can I use Sandbox Dsl in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nodetool-ai/nodetool --skill sandbox-dsl -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sandbox-dsl, .gemini/skills/sandbox-dsl, .github/skills/sandbox-dsl and .opencode/skills/sandbox-dsl in your project.

What does Sandbox Dsl need to run?

Going by SKILL.md and its folder, Sandbox Dsl needs JavaScript for the scripts in its folder. Our summary lists: Node.js.

Does Sandbox Dsl access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sandbox Dsl safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Sandbox Dsl use?

Sandbox Dsl is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sandbox Dsl use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sandbox Dsl?

Skills that share tags, products or a category with Sandbox Dsl: Markdown Article Formatter (JimLiu/baoyu-skills, 27k stars), Markitdown (ImCa0/just-laws, 781 stars), Obsidian Markdown (Atmosphere/atmosphere, 3.8k stars) and DOCX (rvdbreemen/OTGW-firmware, 207 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sandbox Dsl?

nodetool-ai (a GitHub organization) maintains it in nodetool-ai/nodetool, which has 560 GitHub stars. The repository holds 127 skills in this directory. The repository was last updated on October 10, 2026.

Source: nodetool-ai/nodetool on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.