Agent skill

Sandbox Flow

by nodetool-ai in nodetool-ai/nodetool

Call NodeTool nodes as typed async functions from sandbox code, one importable module per node namespace, with streaming and plain JavaScript control flow

AGPL-3.0Auto-check passedDocuments & Office

Install Sandbox Flow

skills CLI
$ npx skills add nodetool-ai/nodetool --skill sandbox-flow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nodetool-ai/nodetool sandbox-flow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nodetool-ai/nodetool.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/sandbox-packs/sandbox-flow .claude/skills/sandbox-flow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sandbox-flow
GitHub stars
560
Token cost
~1.1k tokens
SKILL.md length
465 words
Files
78 (incl. scripts)
Skills in repo
127
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Call NodeTool nodes as typed async functions from sandbox code, one importable module per node namespace, with streaming and plain JavaScript control flow

  • Works in 2 steps: import { … } from… → import…
  • Documents & Office work in your project
  • SKILL.md covers Two imports, both required, Streaming, Errors and Fan-out, plus 2 more sections
  • Runs JavaScript scripts from its folder

What it does

Sandbox Flow is an agent skill from nodetool-ai/nodetool. Call NodeTool nodes as typed async functions from sandbox code, one importable module per node namespace, with streaming and plain JavaScript control flow

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 79 other files, including scripts (for example `package.json`, `sandbox/generated/gemini.audio.js` and `sandbox/generated/gemini.image.js`).

It sits in Documents & Office. It works with JavaScript. The repository describes itself as: Agent-first Creative Workspace. The licence is AGPL-3.0.

When your agent uses it

  • Documents & Office work in your project

Example prompts

  • “/sandbox-flow”

Requirements

  • Node.js

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. import { … } from "@nodetool-ai/sandbox-flow/"; — the nodes.
  2. import "@nodetool-ai/sandbox-nodetool/flow"; — the capability module.

What it can do on your machine

Read from SKILL.md and the folder at commit 58765d3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sandbox Flow loads about 1.1k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 465 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from nodetool-ai/nodetool at commit 58765d3, republished under its AGPL-3.0 licence (© nodetool-ai). 465 words, ~1,110 tokens.

Download SKILL.mdSave it as .claude/skills/sandbox-flow/SKILL.md (or your agent's skills folder). This skill also uses 77 other files; get the full folder from GitHub.
name
sandbox-flow
description
Call NodeTool nodes as typed async functions from sandbox code, one importable module per node namespace, with streaming and plain JavaScript control flow

Calling nodes from the sandbox

Specifier: @nodetool-ai/sandbox-flow. Each node namespace is its own module — @nodetool-ai/sandbox-flow/nodetool.text, @nodetool-ai/sandbox-flow/lib.audio, and so on for all 69. Every node type is a generated async function whose name and inputs come from the node's own metadata, so a type this pack does not export has no import to resolve.

This is not the graph DSL. Nothing is built, saved, or scheduled: the call runs the node and resolves to its outputs. await is the edge, a variable is the wire, Promise.all is the fan-out, and if/for/try are themselves.

js
import { concat } from "@nodetool-ai/sandbox-flow/nodetool.text";

const r = await concat({ a: "hello ", b: "world" });
return r.output;

Two imports, both required

  1. import { … } from "@nodetool-ai/sandbox-flow/<namespace>"; — the nodes.
  2. import "@nodetool-ai/sandbox-nodetool/flow"; — the capability module.

The second one is not decoration. The host mounts a capability module by reading the body's static imports, and this pack's guest code calls into @nodetool-ai/sandbox-nodetool/flow. Without the body-side import the facade is never mounted and the pack's own import of it is refused by name.

js
import "@nodetool-ai/sandbox-nodetool/flow";
import { concat } from "@nodetool-ai/sandbox-flow/nodetool.text";

Streaming

A node that streams its output carries a .stream member; a one-shot node does not, so the surface tells you which is which. Awaiting the plain call on a streaming node still works — it drains the node and returns the last value per slot.

js
import "@nodetool-ai/sandbox-nodetool/flow";
import { agent } from "@nodetool-ai/sandbox-flow/nodetool.agents";

let text = "";
for await (const chunk of agent.stream({ objective: "Summarize the file" })) {
  text += chunk.chunk ?? "";
  if (text.length > 2000) break; // closes the stream; the node stops
}
return text;

Breaking early releases the stream on the host. Read it to the end, or break — both are fine; abandoning the loop object without either is what leaks.

A node written against the streaming-input contract streams {slot, value} instead of partial outputs, one item per emission, and its inputs accept an array wherever a single value goes:

js
import { take } from "@nodetool-ai/sandbox-flow/nodetool.control";

const kept = [];
for await (const { slot, value } of take.stream({ input_item: [1, 2, 3], n: 2 })) {
  if (slot === "output") kept.push(value);
}

Arrays are the whole of streaming input in this version. An async iterable on an input handle is not accepted.

Show full SKILL.md (190 more words)Show less

Errors

A node that fails rejects the call with its own error. There is no verdict machinery and no per-node error stream — your try/catch is the supervisor, and retry, fallback, and timeout are yours to write:

js
import "@nodetool-ai/sandbox-nodetool/flow";
import { textToSpeech } from "@nodetool-ai/sandbox-flow/gemini.audio";

try {
  return await textToSpeech({ text: draft });
} catch (error) {
  return { error: String(error) };
}

Fan-out

Concurrency is Promise.all, and it is real: the calls run at once.

js
const summaries = await Promise.all(
  documents.map((document) => summarizer({ text: document }))
);

Nothing throttles this. A hundred items is a hundred concurrent model calls — batch them yourself when that matters.

The untyped root

import { callNode } from "@nodetool-ai/sandbox-flow" takes a node type as a string and checks nothing until the host answers. Use it when the type is decided at run time; otherwise import the namespace, where a wrong name is an import error rather than a failed call.

Gotchas

  • Inputs are values, not handles. There is nothing to wire and no .output() — the call returns the outputs record.
  • No graph comes out of this. Nothing opens in the editor, validates, or replays. When the artifact matters, build a graph with @nodetool-ai/sandbox-dsl instead.
  • A missing property is the node's default, exactly as in a graph run.
  • Names follow the node class: nodetool.text.Concat is concat, nodetool.constant.Integer is integer. Reserved words take a trailing underscore (if_).

© nodetool-ai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 77 other files (scripts) in packages/sandbox-packs/sandbox-flow of nodetool-ai/nodetool.

  • SKILL.md
  • package.json
  • sandbox/generated/gemini.audio.js
  • sandbox/generated/gemini.image.js
  • sandbox/generated/gemini.text.js
  • sandbox/generated/gemini.video.js
  • sandbox/generated/kie.dynamic_schema.js
  • sandbox/generated/lib.audio.js
  • sandbox/generated/lib.browser.js
  • sandbox/generated/lib.charts.js
  • sandbox/generated/lib.comfy.js
  • sandbox/generated/lib.grid.js
  • sandbox/generated/lib.image.channel.js
  • sandbox/generated/lib.image.color.js
  • sandbox/generated/lib.image.color_grading.js
  • sandbox/generated/lib.image.draw.js
  • sandbox/generated/lib.image.effects.js
  • sandbox/generated/lib.image.enhance.js
  • sandbox/generated/lib.image.filter.js
  • … and 59 more

Open the folder on GitHubat commit 58765d3

Compare with similar skills

Sandbox Flow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sandbox Flow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sandbox Flow this skillnodetool-ai/nodetool560—~1.1kAutomated safety check: PassAGPL-3.0
Jev SEOAgriciDaniel/jev-seo539—~2.5kAutomated safety check: NotesMIT
HTML To Bento Slidesmucsbr/ppt-agent-workflow-san643—~1.6kAutomated safety check: PassNone
Jjtheowenyoung/home115—~2.5kAutomated safety check: PassNone
Write Documentdigital-go-jp/design-system-example-components-html115—~3.1kAutomated safety check: PassMIT
Md To DOCXgithub/awesome-copilot40k1 repos~688Automated safety check: PassMIT

Similar skills

  • Jev SEO

    AgriciDaniel/jev-seo

    Full live SEO audit of any website from its homepage URL, powered by Jev (TypeSafe's System One model).

    539 GitHub stars~2.5k tokensUpdated 18 days ago
    Documents & OfficeAuto-check: notes
  • HTML To Bento Slides

    mucsbr/ppt-agent-workflow-san

    Convert an existing HTML/CSS/JavaScript slide presentation into an editable bento/slides .bento.html deck.

    643 GitHub stars~1.6k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • Jj

    theowenyoung/home

    Save the currently active browser page to the link collection at saved.owenyoung.com.

    115 GitHub stars~2.5k tokensUpdated 13 days ago
    Documents & OfficeAuto-check passed
  • Write Document

    digital-go-jp/design-system-example-components-html

    コンポーネントのMDXドキュメントを作成・更新する

    115 GitHub stars~3.1k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • Md To DOCX

    github/awesome-copilot

    Official

    Convert Markdown files to professionally formatted Word (.docx) documents with embedded PNG images — pure JavaScript, no external tools required

    40k GitHub starsUsed in 1 repo~688 tokens
    Documents & OfficeAuto-check passed
  • Analyzing Malicious PDF With Peepdf

    mukul975/Anthropic-Cybersecurity-Skills

    Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.

    34k GitHub stars~799 tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed

More from nodetool-ai/nodetool

All 127 skills in this repo
  • Beat Sync Editing

    nodetool-ai/nodetool

    Cut a NodeTool timeline to music and shape its pacing — detect the beat grid, place cuts on phrases, pick a cut type, build speed ramps with time remap, and give the piece an arc.

    560 GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Caption Titles

    nodetool-ai/nodetool

    Add and animate a consistent text layer on an existing NodeTool timeline.

    560 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Color Motion

    nodetool-ai/nodetool

    Choose and animate colour on a NodeTool timeline, including shape and text gradients, colour grades, 3D LUTs, and dither.

    560 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Commercial Beat Sheet

    nodetool-ai/nodetool

    Write a shootable, precisely timed commercial beat sheet and store it as a NodeTool storyboard, with a consistent entity roster behind every shot.

    560 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Elevenlabs Audio Prompting

    nodetool-ai/nodetool

    Direct ElevenLabs speech, dialogue, sound effects and music — the bracketed audio tags v3 acts on and why the voice decides whether a tag lands, stability as the delivery dial, punctuation instead…

    560 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Frame Composition

    nodetool-ai/nodetool

    Stage the frame on a NodeTool timeline — grids, focal placement, safe areas per aspect ratio, depth layers and parallax, camera moves, and where elements enter and leave.

    560 GitHub stars~3.5k tokensUpdated today
    Auto-check passed

Works with

Questions about Sandbox Flow

What does Sandbox Flow do?

Call NodeTool nodes as typed async functions from sandbox code, one importable module per node namespace, with streaming and plain JavaScript control flow. Sandbox Flow is an agent skill from nodetool-ai/nodetool.

When should I use Sandbox Flow?

Sandbox Flow fits situations like: documents & Office work in your project.

How do I install Sandbox Flow in Claude Code?

Run `npx skills add nodetool-ai/nodetool --skill sandbox-flow -a claude-code`. Or copy the skill folder (packages/sandbox-packs/sandbox-flow in nodetool-ai/nodetool) into .claude/skills/sandbox-flow in your project. Claude Code loads it when a task matches its description.

How do I install Sandbox Flow in Codex?

Run `npx skills add nodetool-ai/nodetool --skill sandbox-flow -a codex`. Or copy the skill folder (packages/sandbox-packs/sandbox-flow in nodetool-ai/nodetool) into .agents/skills/sandbox-flow in your project. Codex loads it when a task matches its description.

Can I use Sandbox Flow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nodetool-ai/nodetool --skill sandbox-flow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sandbox-flow, .gemini/skills/sandbox-flow, .github/skills/sandbox-flow and .opencode/skills/sandbox-flow in your project.

What does Sandbox Flow need to run?

Going by SKILL.md and its folder, Sandbox Flow needs JavaScript for the scripts in its folder. Our summary lists: Node.js.

Does Sandbox Flow access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sandbox Flow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Sandbox Flow use?

Sandbox Flow is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sandbox Flow use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sandbox Flow?

Skills that share tags, products or a category with Sandbox Flow: Jev SEO (AgriciDaniel/jev-seo, 539 stars), HTML To Bento Slides (mucsbr/ppt-agent-workflow-san, 643 stars), Jj (theowenyoung/home, 115 stars) and Write Document (digital-go-jp/design-system-example-components-html, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sandbox Flow?

nodetool-ai (a GitHub organization) maintains it in nodetool-ai/nodetool, which has 560 GitHub stars. The repository holds 127 skills in this directory. The repository was last updated on October 9, 2026.

Source: nodetool-ai/nodetool on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.