AWS Cdk Development
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
Manage warm sandbox pools on OpenHands Enterprise by driving the runtime-api admin endpoints (list, save, delete warm runtime configurations) from a Python CLI.
$ npx skills add OpenHands/extensions --skill runtime-api-configs -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OpenHands/extensions runtime-api-configs --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OpenHands/extensions.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/runtime-api-configs .claude/skills/runtime-api-configs && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "runtime-api-configs" agent skill from https://github.com/OpenHands/extensions/tree/main/plugins/runtime-api-configs into .claude/skills/runtime-api-configs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-api-configs", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OpenHands/extensions/tree/main/plugins/runtime-api-configsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OpenHands/extensions --skill runtime-api-configs -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OpenHands/extensions runtime-api-configs --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OpenHands/extensions.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/runtime-api-configs .agents/skills/runtime-api-configs && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "runtime-api-configs" agent skill from https://github.com/OpenHands/extensions/tree/main/plugins/runtime-api-configs into .agents/skills/runtime-api-configs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-api-configs", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OpenHands/extensions --skill runtime-api-configs -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OpenHands/extensions runtime-api-configs --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OpenHands/extensions.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/runtime-api-configs .cursor/skills/runtime-api-configs && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "runtime-api-configs" agent skill from https://github.com/OpenHands/extensions/tree/main/plugins/runtime-api-configs into .cursor/skills/runtime-api-configs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-api-configs", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OpenHands/extensions.git --path plugins/runtime-api-configs--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OpenHands/extensions --skill runtime-api-configs -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OpenHands/extensions runtime-api-configs --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OpenHands/extensions.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/runtime-api-configs .gemini/skills/runtime-api-configs && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "runtime-api-configs" agent skill from https://github.com/OpenHands/extensions/tree/main/plugins/runtime-api-configs into .gemini/skills/runtime-api-configs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-api-configs", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OpenHands/extensions runtime-api-configsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OpenHands/extensions --skill runtime-api-configs -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OpenHands/extensions.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/runtime-api-configs .github/skills/runtime-api-configs && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "runtime-api-configs" agent skill from https://github.com/OpenHands/extensions/tree/main/plugins/runtime-api-configs into .github/skills/runtime-api-configs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-api-configs", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OpenHands/extensions --skill runtime-api-configs -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OpenHands/extensions runtime-api-configs --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OpenHands/extensions.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/runtime-api-configs .opencode/skills/runtime-api-configs && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "runtime-api-configs" agent skill from https://github.com/OpenHands/extensions/tree/main/plugins/runtime-api-configs into .opencode/skills/runtime-api-configs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-api-configs", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
runtime-api-configsManage warm sandbox pools on OpenHands Enterprise by driving the runtime-api admin endpoints (list, save, delete warm runtime configurations) from a Python CLI.
Runtime API Configs is an agent skill from OpenHands/extensions. Manage warm sandbox pools on OpenHands Enterprise by driving the runtime-api admin endpoints (list, save, delete warm runtime configurations) from a Python CLI. Use when an OpenHands Enterprise administrator asks to add, update, delete, or inspect custom sandbox images, warm pools, or warm-runtime-configs, or when the docs point to enterprise/custom-sandbox-images/multiple-images-warm-pools.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts (for example `.plugin/plugin.json`, `README.md` and `scripts/warm_runtime_configs.py`).
It sits in DevOps & Cloud. It works with Python. The repository describes itself as: Public registry for OpenHands extensions. The licence is MIT.
Read from SKILL.md and the folder at commit d008b81. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3kubectlFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.openhands.devFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
API_KEYADMIN_PASSWORDADMIN_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Runtime API Configs loads about 2.5k tokens when it runs. Until then it costs about 105 tokens; SKILL.md has 973 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
eval "$(sudo -E python3 scripts/warm_runtime_configs.py bootstrap --namespace openhands)"Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from OpenHands/extensions at commit d008b81, republished under its MIT licence (© OpenHands). 973 words, ~2,468 tokens.
.claude/skills/runtime-api-configs/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.This plugin manages the warm sandbox pools used by OpenHands Enterprise. It
replaces the ad-hoc warm-runtime-configs.sh shell script embedded in the
docs and gives administrators a single, testable Python CLI for the same
workflow.
The CLI talks HTTP to the runtime-api service. It never modifies the cluster
directly, and it uses only the Python standard library, so it runs anywhere
python3 is available.
Reach for this skill whenever the user wants to:
openhands-php:8.4-v1) so
users can select it from the Settings → Application → Default Sandbox
dropdown.RUNTIME_API_URL, API_KEY, ADMIN_PASSWORD)
from Kubernetes secrets so subsequent runs need no cluster access.If the user is instead asking how to build a custom sandbox image (Dockerfile, versioning), point them at Building a Custom Image
OpenHands Enterprise 0.64.0 or later.
Python 3.9+ on the machine running the CLI. No third-party packages.
The Runtime API Admin Password:
admin-password Kubernetes
secret in the runtime-api namespace. Helm has no Admin Console.Helm installs only: the runtime-api chart must be running in overlay
mode and have warm pools enabled, so v1_current shows up in list and
can be used as a template source. Set both in your umbrella values:
runtime-api:
warmRuntimes:
enabled: true
env:
WARM_RUNTIME_CONFIG_OVERLAY: "1"Overlay mode is on by default on Replicated VM installs. Without it on
Helm, list returns [] on a fresh install and template v1_current
fails.
On any machine with HTTPS reachability to the runtime-api, export two env vars:
export RUNTIME_API_URL=https://runtime-api.<your-base-domain>
export ADMIN_PASSWORD=<runtime-api-admin-password> # see Prerequisites aboveThat is the full setup on any install where the runtime-api ingress is
reachable from the machine running the CLI. No kubectl, no SSH, no
cluster access. If the runtime-api is cluster-internal (Helm default), see
the Helm entry in the Advanced section below to port-forward first.
Under the hood, the CLI uses the admin password directly for save and
delete (via the PBKDF2 handshake), and for list and template it logs
in as admin and fetches the default read-only API key over HTTPS from
/api/admin/api-keys.
If you already know the read-only API key (for example, from an operator runbook), export it too and the CLI will skip the extra admin-login round trip on reads:
export API_KEY=<default api key>If you have kubectl access to the cluster and prefer to pull all three
env vars from Kubernetes secrets in one step, see
Advanced: bootstrap from Kubernetes
at the bottom of this file.
Run with python3 scripts/warm_runtime_configs.py <subcommand>. Each
subcommand exits non-zero on error and prints the runtime-api's HTTP body
on failure.
| Subcommand | Auth | Purpose |
|---|---|---|
list | API_KEY if set, else admin login | Print the effective set of configurations. |
template <source> | API_KEY if set, else admin login | Fetch a config, strip identity fields, override image/count, print JSON ready to save. |
save <name> [--file F] | Admin password | Upsert a configuration. Reads JSON from --file or stdin. |
delete <name> | Admin password | Delete a database-managed configuration. |
bootstrap | kubectl | Print export lines for RUNTIME_API_URL, API_KEY, ADMIN_PASSWORD. Optional; see Advanced below. |
Full help: python3 scripts/warm_runtime_configs.py --help and
python3 scripts/warm_runtime_configs.py <subcommand> --help.
Register a new PHP sandbox image once credentials are in the environment:
# 1. Derive a config JSON from the current default, changing only the image
python3 scripts/warm_runtime_configs.py template v1_current \
--image ghcr.io/your-org/openhands-php:8.4-v1 --count 1 \
--output php-web.json
# 2. Save it
python3 scripts/warm_runtime_configs.py save php-web --file php-web.json
# 3. Confirm
python3 scripts/warm_runtime_configs.py listWithin about a minute the pool is ready and php-web appears in
Settings → Application → Default Sandbox.
Deleting an API-managed configuration removes it from the effective set:
python3 scripts/warm_runtime_configs.py delete php-webdelete operates on database rows only, so it 404s for names that have
never been saved through this CLI (installer-managed entries like
v1_current on a fresh install fall in that bucket). In overlay mode, if
you had previously saved a database row that shadowed a same-named
ConfigMap entry, deleting the row reverts to the ConfigMap entry on the
next reconciler cycle.
Frozen API-managed configurations do not follow release bumps. After every OHE upgrade, re-derive each API-managed configuration from the refreshed default template, keeping each configuration's current image tag and pool size unless you deliberately change them:
# One "name image count" tuple per API-managed config; edit for your fleet.
# Preserving the existing pool count matters: hardcoding it would silently
# shrink pools on every refresh.
while read -r name image count; do
[ -z "$name" ] && continue
python3 scripts/warm_runtime_configs.py template v1_current \
--image "$image" --count "$count" \
| python3 scripts/warm_runtime_configs.py save "$name" --file -
done <<'EOF'
php-web ghcr.io/your-org/openhands-php:8.4-v2 3
ruby-app ghcr.io/your-org/openhands-ruby:3.3-v2 2
node-monorepo ghcr.io/your-org/openhands-node:24-v2 1
EOFTwo caveats worth spelling out:
template refreshes the command and environment to match the new
v1_current, but it keeps whatever image tag you pass. To actually
pick up a new agent-server version, the image itself must be rebuilt
against the matching agent-server base. This loop alone does not do
that.| Variable | Used by | Notes |
|---|---|---|
RUNTIME_API_URL | all HTTP subcommands | e.g. https://runtime-api.example.com or http://localhost:5000. |
ADMIN_PASSWORD | save, delete; also list/template when API_KEY is unset | Runs the PBKDF2 challenge-response handshake. |
ADMIN_TOKEN | Anywhere ADMIN_PASSWORD is used | Pre-obtained admin JWT. When set, it wins over ADMIN_PASSWORD and skips the handshake. |
API_KEY | list, template (optional) | Sent as X-API-Key. Optional: when unset, the CLI fetches the default key over HTTPS via admin login. |
NAMESPACE | bootstrap | Defaults to openhands. Overridable via --namespace. |
bootstrap extracts all three env vars from Kubernetes secrets in one
step. Handy for cluster operators and CI, but the default HTTPS-only
workflow above is preferred for interactive admin use.
The k0s kubeconfig is root-owned, so the invocation runs under sudo:
eval "$(sudo -E python3 scripts/warm_runtime_configs.py bootstrap --namespace openhands)"The runtime-api is cluster-internal on Helm (chart default is
ingress.enabled: false). The Kubernetes service name is release-prefixed
via include "runtime-api.fullname", so it is not literally runtime-api
RUNTIME_API_URL:SVC=$(kubectl -n openhands get svc \
-l app.kubernetes.io/name=runtime-api \
-o jsonpath='{.items[0].metadata.name}')
kubectl -n openhands port-forward "svc/$SVC" 5000:5000 &
export RUNTIME_API_URL=http://localhost:5000
eval "$(python3 scripts/warm_runtime_configs.py bootstrap --namespace openhands --skip-url)"--skip-url leaves RUNTIME_API_URL alone. If the operator set
nameOverride on the runtime-api subchart, adjust the label selector to
match.
© OpenHands, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts) in plugins/runtime-api-configs of OpenHands/extensions.
Open the folder on GitHubat commit d008b81
Runtime API Configs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Runtime API Configs this skillOpenHands/extensions | 157 | — | ~2.5k | Automated safety check: Notes | MIT | |
| AWS Cdk Developmentzxkane/aws-skills | 367 | 2 repos | ~2.5k | Automated safety check: Pass | MIT | |
| Reproduce macOS Python FlavorsNuitka/Nuitka | 15k | — | ~1.7k | Automated safety check: Pass | AGPL-3.0 | |
| Env Var Conventionssgl-project/sglang | 37k | 2 repos | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Pymobiledevice3 Device Operatordoronz88/pymobiledevice3 | 2.8k | — | ~1.8k | Automated safety check: Notes | GPL-3.0 | |
| Vetatilladeniz/Kubeli | 387 | 2 repos | ~1.6k | Automated safety check: Pass | MIT |
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
Nuitka/Nuitka
Reproduce macOS Nuitka issues across Python distributions and GitHub Actions Python packaging.
sgl-project/sglang
Conventions for SGLang environment variables — where to define, how to access, how to name, and how to deprecate.
doronz88/pymobiledevice3
Operate iOS and iPadOS devices with pymobiledevice3, from a local checkout or straight from PyPI via uvx on a fresh workstation.
atilladeniz/Kubeli
Run vet immediately after ANY logical unit of code changes. An agent skill from atilladeniz/Kubeli.
henryqin1997/statem
A skill your agent uses when a long coding or research task should be managed with statem state-machine runbooks, including creating specs, starting or resuming runs, checking current state…
OpenHands/extensions
Evaluate how well a codebase supports autonomous AI-assisted development.
OpenHands/extensions
Build and automate Discord integrations (bots, webhooks, slash commands, and REST API workflows).
OpenHands/extensions
Interact with GitHub repositories, pull requests, issues, and workflows using the GITHUBTOKEN environment variable and GitHub CLI.
OpenHands/extensions
Create an automation that implements GitHub issues when a configurable trigger label is applied.
OpenHands/extensions
This skill should be used when the user asks to "monitor a GitHub repository", "watch GitHub for issues or PRs", "respond to @OpenHands mentions on GitHub", "set up an OpenHands GitHub integration"…
OpenHands/extensions
Create an automation that implements GitLab issues when a configurable trigger label is applied.
Works with
Categories
Manage warm sandbox pools on OpenHands Enterprise by driving the runtime-api admin endpoints (list, save, delete warm runtime configurations) from a Python CLI. Runtime API Configs is an agent skill from OpenHands/extensions. Manage warm sandbox pools on OpenHands Enterprise by driving the runtime-api admin endpoints (list, save, delete warm runtime configurations) from a Python CLI.
Runtime API Configs fits situations like: an OpenHands Enterprise administrator asks to add; inspect custom sandbox images; warm-runtime-configs; the docs point to enterprise/custom-sandbox-images/multiple-images-warm-pools.
Run `npx skills add OpenHands/extensions --skill runtime-api-configs -a claude-code`. Or copy the skill folder (plugins/runtime-api-configs in OpenHands/extensions) into .claude/skills/runtime-api-configs in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OpenHands/extensions --skill runtime-api-configs -a codex`. Or copy the skill folder (plugins/runtime-api-configs in OpenHands/extensions) into .agents/skills/runtime-api-configs in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OpenHands/extensions --skill runtime-api-configs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/runtime-api-configs, .gemini/skills/runtime-api-configs, .github/skills/runtime-api-configs and .opencode/skills/runtime-api-configs in your project.
Going by SKILL.md and its folder, Runtime API Configs needs Python for the scripts in its folder, the command-line tools its instructions call (python3 and kubectl) and credentials named API_KEY, ADMIN_PASSWORD and ADMIN_TOKEN. Our summary lists: Python 3; A credential in API_KEY; A credential in ADMIN_TOKEN.
SKILL.md names 1 domain. As links in the text: docs.openhands.dev. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Runtime API Configs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Runtime API Configs: AWS Cdk Development (zxkane/aws-skills, 367 stars), Reproduce macOS Python Flavors (Nuitka/Nuitka, 15k stars), Env Var Conventions (sgl-project/sglang, 37k stars) and Pymobiledevice3 Device Operator (doronz88/pymobiledevice3, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OpenHands (a GitHub organization) maintains it in OpenHands/extensions, which has 157 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.
Source: OpenHands/extensions on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.