Agent skill

Sandbox XML

by nodetool-ai in nodetool-ai/nodetool

Parse XML feeds and sitemaps in a Code node or CodeAct action, with fast-xml-parser running on the host

AGPL-3.0Auto-check passedMarketing & SEO

Install Sandbox XML

skills CLI
$ npx skills add nodetool-ai/nodetool --skill sandbox-xml -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nodetool-ai/nodetool sandbox-xml --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nodetool-ai/nodetool.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/sandbox-packs/sandbox-xml .claude/skills/sandbox-xml && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sandbox-xml
GitHub stars
560
Token cost
~293 tokens
SKILL.md length
128 words
Files
2
Skills in repo
127
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Parse XML feeds and sitemaps in a Code node or CodeAct action, with fast-xml-parser running on the host

  • Tasks that involve Technical SEO
  • SKILL.md covers parse — XML to a plain object and Gotchas
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Sandbox XML is an agent skill from nodetool-ai/nodetool. Parse XML feeds and sitemaps in a Code node or CodeAct action, with fast-xml-parser running on the host

Its SKILL.md is about 290 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `package.json`).

It sits in Marketing & SEO, covering Technical SEO. The repository describes itself as: Agent-first Creative Workspace. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve Technical SEO

Example prompts

  • “/sandbox-xml”

What it can do on your machine

Read from SKILL.md and the folder at commit 58765d3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sandbox XML loads about 293 tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 128 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~293

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nodetool-ai/nodetool at commit 58765d3, republished under its AGPL-3.0 licence (© nodetool-ai). 128 words, ~293 tokens.

Download SKILL.mdSave it as .claude/skills/sandbox-xml/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
sandbox-xml
description
Parse XML feeds and sitemaps in a Code node or CodeAct action, with fast-xml-parser running on the host

XML in the sandbox

Specifier: @nodetool-ai/sandbox-xml. Import it at the top of the body.

fast-xml-parser reads a bare window, which the guest does not have, so it cannot be compiled in. This pack is a host module: the import resolves to a generated facade over NodeTool's own implementation.

parse — XML to a plain object

js
import { parse } from "@nodetool-ai/sandbox-xml";

const feed = await parse(inputs.xml);
const items = feed?.rss?.channel?.item ?? [];
return { titles: items.map((i) => i.title) };

Attributes ride along prefixed @_ so they never collide with child-element keys; pass { attributes: false } to drop them. Text values stay text — a numeric-looking id must not change shape between runs.

Invalid XML throws with the parser's own reason rather than returning a partial tree.

Gotchas

  • parse is async.
  • 5 MB of text per call.
  • A single child is not an array. channel.item is one object when the feed has one item; normalize with [].concat(x ?? []).

© nodetool-ai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in packages/sandbox-packs/sandbox-xml of nodetool-ai/nodetool.

  • SKILL.md
  • package.json

Open the folder on GitHubat commit 58765d3

Compare with similar skills

Sandbox XML next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sandbox XML compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sandbox XML this skillnodetool-ai/nodetool560—~293Automated safety check: PassAGPL-3.0
Hreflang and International SEOAgriciDaniel/claude-seo19k5 repos~3.4kAutomated safety check: PassMIT
Google SEO APIsAgriciDaniel/claude-seo19k1 repos~4.2kAutomated safety check: PassMIT
GEO-First SEO Audit Toolzubair-trabzada/geo-seo-claude11k—~2.8kAutomated safety check: NotesMIT
SEO Optimizerailabs-393/ai-labs-claude-skills4541 repos~3.2kAutomated safety check: PassMIT
SEO Drift MonitorAgriciDaniel/claude-seo19k1 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Hreflang and International SEO

    AgriciDaniel/claude-seo

    Audits, validates and generates hreflang tags for multi-language and multi-region sites in HTML, HTTP headers or XML sitemaps, flagging common code and return-tag mistakes.

    19k GitHub starsUsed in 5 repos~3.4k tokens
    Marketing & SEOAuto-check passed
  • Google SEO APIs

    AgriciDaniel/claude-seo

    Pulls real Google data for SEO work: Search Console, PageSpeed Insights, CrUX field data, the Indexing API and GA4 organic traffic, through /seo google commands.

    19k GitHub starsUsed in 1 repo~4.2k tokens
    Marketing & SEOAuto-check passed
  • GEO-First SEO Audit Tool

    zubair-trabzada/geo-seo-claude

    Audits a website for AI search visibility across ChatGPT, Claude, Perplexity and Google AI Overviews while checking traditional SEO, schema and E-E-A-T content quality.

    11k GitHub stars~2.8k tokensUpdated today
    Marketing & SEOAuto-check: notes
  • SEO Optimizer

    ailabs-393/ai-labs-claude-skills

    This skill should be used when analyzing HTML/CSS websites for SEO optimization, fixing SEO issues, generating SEO reports, or implementing SEO best practices.

    454 GitHub starsUsed in 1 repo~3.2k tokens
    Marketing & SEOAuto-check passed
  • SEO Drift Monitor

    AgriciDaniel/claude-seo

    Captures baselines of a page's SEO-critical elements, compares later snapshots against them and flags regressions by severity, like version control for on-page SEO.

    19k GitHub starsUsed in 1 repo~1.9k tokens
    Marketing & SEOAuto-check passed
  • llms.txt Analyzer and Generator

    zubair-trabzada/geo-seo-claude

    Validates an existing llms.txt file or crawls a site to generate a new one, following the format rules for a root-level Markdown file aimed at AI systems.

    11k GitHub starsUsed in 2 repos~3.9k tokens
    Marketing & SEOAuto-check: notes

More from nodetool-ai/nodetool

All 127 skills in this repo
  • Beat Sync Editing

    nodetool-ai/nodetool

    Cut a NodeTool timeline to music and shape its pacing — detect the beat grid, place cuts on phrases, pick a cut type, build speed ramps with time remap, and give the piece an arc.

    560 GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Caption Titles

    nodetool-ai/nodetool

    Add and animate a consistent text layer on an existing NodeTool timeline.

    560 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Color Motion

    nodetool-ai/nodetool

    Choose and animate colour on a NodeTool timeline, including shape and text gradients, colour grades, 3D LUTs, and dither.

    560 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Commercial Beat Sheet

    nodetool-ai/nodetool

    Write a shootable, precisely timed commercial beat sheet and store it as a NodeTool storyboard, with a consistent entity roster behind every shot.

    560 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Elevenlabs Audio Prompting

    nodetool-ai/nodetool

    Direct ElevenLabs speech, dialogue, sound effects and music — the bracketed audio tags v3 acts on and why the voice decides whether a tag lands, stability as the delivery dial, punctuation instead…

    560 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Frame Composition

    nodetool-ai/nodetool

    Stage the frame on a NodeTool timeline — grids, focal placement, safe areas per aspect ratio, depth layers and parallax, camera moves, and where elements enter and leave.

    560 GitHub stars~3.5k tokensUpdated today
    Auto-check passed

Categories

Questions about Sandbox XML

What does Sandbox XML do?

Parse XML feeds and sitemaps in a Code node or CodeAct action, with fast-xml-parser running on the host. Sandbox XML is an agent skill from nodetool-ai/nodetool.

When should I use Sandbox XML?

Sandbox XML fits situations like: tasks that involve Technical SEO.

How do I install Sandbox XML in Claude Code?

Run `npx skills add nodetool-ai/nodetool --skill sandbox-xml -a claude-code`. Or copy the skill folder (packages/sandbox-packs/sandbox-xml in nodetool-ai/nodetool) into .claude/skills/sandbox-xml in your project. Claude Code loads it when a task matches its description.

How do I install Sandbox XML in Codex?

Run `npx skills add nodetool-ai/nodetool --skill sandbox-xml -a codex`. Or copy the skill folder (packages/sandbox-packs/sandbox-xml in nodetool-ai/nodetool) into .agents/skills/sandbox-xml in your project. Codex loads it when a task matches its description.

Can I use Sandbox XML in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nodetool-ai/nodetool --skill sandbox-xml -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sandbox-xml, .gemini/skills/sandbox-xml, .github/skills/sandbox-xml and .opencode/skills/sandbox-xml in your project.

What does Sandbox XML need to run?

SKILL.md names no scripts, command-line tools or credentials: Sandbox XML is instructions for the agent only.

Does Sandbox XML access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sandbox XML safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sandbox XML use?

Sandbox XML is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sandbox XML use?

About 293 tokens (SKILL.md is roughly 1.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sandbox XML?

Skills that share tags, products or a category with Sandbox XML: Hreflang and International SEO (AgriciDaniel/claude-seo, 19k stars), Google SEO APIs (AgriciDaniel/claude-seo, 19k stars), GEO-First SEO Audit Tool (zubair-trabzada/geo-seo-claude, 11k stars) and SEO Optimizer (ailabs-393/ai-labs-claude-skills, 454 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sandbox XML?

nodetool-ai (a GitHub organization) maintains it in nodetool-ai/nodetool, which has 560 GitHub stars. The repository holds 127 skills in this directory. The repository was last updated on October 9, 2026.

Source: nodetool-ai/nodetool on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.