Agent skill

Sandbox Check

by RyanAlberts in RyanAlberts/best-of-Agent-Harnesses

Sandbox audit that probes, from inside a live coding-agent session, what the agent can really reach: secret files it can open, secret-like environment variables, files that git, the shell, the…

MITAuto-check: notesDevOps & Cloud

Install Sandbox Check

skills CLI
$ npx skills add RyanAlberts/best-of-Agent-Harnesses --skill sandbox-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install RyanAlberts/best-of-Agent-Harnesses sandbox-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/RyanAlberts/best-of-Agent-Harnesses.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sandbox-check .claude/skills/sandbox-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sandbox-check
GitHub stars
1.1k
Token cost
~3.1k tokens
SKILL.md length
1,715 words
Files
8 (incl. scripts, references)
Repo updated
First seen
Licence
MIT

At a glance

Sandbox audit that probes, from inside a live coding-agent session, what the agent can really reach: secret files it can open, secret-like environment variables, files that git, the shell, the…

  • Works in 5 steps: Explain the probe in two or three… → Run the probe once, through your normal… → Offer the network check as its own… → …
  • The user asks what the agent can access
  • SKILL.md covers When to use, When not to use, What the probe touches and Steps, plus 3 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Sandbox Check is an agent skill from RyanAlberts/best-of-Agent-Harnesses. Sandbox audit that probes, from inside a live coding-agent session, what the agent can really reach: secret files it can open, secret-like environment variables, files that git, the shell, the editor, or the harness later run (git hooks, shell startup files, harness settings), writes outside the project, the Docker socket, the SSH agent, and passwordless sudo. Use when the user asks what the agent can access or write on this machine, whether the sandbox actually works, how big the blast radius is if the agent…

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `README.md`, `references/fixes.md` and `references/trust-handoff.md`). Compatibility notes: Python 3.9+ on macOS or Linux; Python 3.11+ to compare Codex settings. Without flags nothing touches the network. The optional --network flag makes DNS…

It sits in DevOps & Cloud, covering Authentication, Secrets management and Containers. It works with Git and Docker. The repository describes itself as: 🏆 Ranked list of 167 AI agent harnesses, plus templates, playbooks, MCP, and learning resources. Rescored weekly. The licence is MIT.

When your agent uses it

  • The user asks what the agent can access
  • Write on this machine
  • Whether the sandbox actually works
  • How big the blast radius is if the agent gets prompt-injected

Example prompts

  • “/sandbox-check”

Requirements

  • Python 3
  • Docker
  • Compatibility (from SKILL.md): Python 3.9+ on macOS or Linux; Python 3.11+ to compare Codex settings. Without flags nothing touches the network. The optional --network flag makes DNS lookups and TCP connections (no data sent) to github.com, pypi.org, and the cloud metadata address 169.254.169.254.

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Explain the probe in two or three sentences drawn from "What the probe touches", including
  2. Run the probe once, through your normal shell tool
  3. Offer the network check as its own choice. Say that it looks up github.com and pypi.org,
  4. Choose the fixes. Open references/fixes.md at the section for the harness named on the
  5. Report in the shape below. A fix that edits a settings file is a proposal: show the exact

What it can do on your machine

Read from SKILL.md and the folder at commit 4fa20bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Python 3.9+ on macOS or Linux; Python 3.11+ to compare Codex settings. Without flags nothing touches the network. The optional --network flag makes DNS lookups and TCP connections (no data sent) to github.com, pypi.org, and the cloud metadata address 169.254.169.254.

    From compatibility in the SKILL.md frontmatter.

Context cost

Sandbox Check loads about 3.1k tokens when it runs, and up to ~7.3k if it reads all its reference files. Until then it costs about 212 tokens; SKILL.md has 1,715 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~212
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:11
    whether SSH keys, cloud credentials, or .env files are
  • NoteMentions a .env fileSKILL.md:39
    ks whether SSH keys, cloud credentials, `.env` files, or tokens are exposed to the
  • NoteRuns commands with sudoSKILL.md:69
    - **sudo**: `sudo -n true`, the form that fails instead of asking for a password. The system log
  • NoteRuns commands with sudoSKILL.md:70
    record the attempt; `--skip-sudo` leaves sudo alone.
  • NoteRuns commands with sudoSKILL.md:76
    dit rules may log or flag the probe: the sudo attempt,
  • NoteRuns commands with sudoSKILL.md:91
    the sudo attempt and the login-items test file that security tools may flag. Done when the user
  • NoteRuns commands with sudoSKILL.md:134
    reach: running as root, sudo without a password, control of Docker, writes to git hooks.
  • NoteRuns commands with sudoSKILL.md:148
    items or SSH login keys, sudo without a password, running as root.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from RyanAlberts/best-of-Agent-Harnesses at commit 4fa20bc, republished under its MIT licence (© RyanAlberts). 1,715 words, ~3,078 tokens.

Download SKILL.mdSave it as .claude/skills/sandbox-check/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
sandbox-check
description
Sandbox audit that probes, from inside a live coding-agent session, what the agent can really reach: secret files it can open, secret-like environment variables, files that git, the shell, the editor, or the harness later run (git hooks, shell startup files, harness settings), writes outside the project, the Docker socket, the SSH agent, and passwordless sudo. Use when the user asks what the agent can access or write on this machine, whether the sandbox actually works, how big the blast radius is if the agent gets prompt-injected, whether SSH keys, cloud credentials, or .env files are exposed, or whether it could escape through Docker or sudo. Runs locally and edits no existing file: it creates and deletes one empty test file per folder it checks, and only the optional --network flag makes DNS lookups and TCP connections.
compatibility
Python 3.9+ on macOS or Linux; Python 3.11+ to compare Codex settings. Without flags nothing touches the network. The optional --network flag makes DNS lookups and TCP connections (no data sent) to github.com, pypi.org, and the cloud metadata address 169.254.169.254.
license
MIT
metadata.author
Ryan Alberts
metadata.version
1.0.0
metadata.source
https://github.com/RyanAlberts/best-of-Agent-Harnesses

Sandbox check

A coding agent's shell commands have whatever access that shell has, and a sandbox is only as good as what actually gets through it. This skill runs one probe through the agent's own shell tool and reports, headline first, what the agent can reach right now: secret files, secret-like environment variables, the files other programs later trust and run (a trust handoff), the Docker socket, the SSH agent, sudo, and, only when asked, the network. It reads no secret, prints no secret value, and sends nothing anywhere unless you add --network.

When to use

  • The user asks what the agent can read, write, or reach on this machine or in this container.
  • The user wants to know whether a sandbox really holds: Claude Code /sandbox, Codex sandbox modes, Gemini CLI --sandbox, or Cursor's sandbox.
  • The user worries about prompt injection or a rogue agent and asks for the blast radius.
  • The user asks whether SSH keys, cloud credentials, .env files, or tokens are exposed to the agent.
  • Before an agent works unattended or on an untrusted repository.

When not to use

  • Testing whether permission rules or hooks block dangerous commands: use guardrail-tester.
  • Stopping a session that loops or overspends: use runaway-guard.
  • Checking which instruction files each agent loads: use agents-md-checker.
  • Finding secrets committed to git history: use a secret scanner such as gitleaks. This skill checks access, not file contents.
  • Turning a sandbox on: that is a settings change. This skill measures the result, and references/fixes.md names the setting.

What the probe touches

Tell the user this, in short, before the first run. It is the whole contract:

  • Secret files: opened and closed without reading a byte. Files that macOS keeps only in the cloud are skipped, so they stay in the cloud.
  • Existing files other programs trust: opened for append and closed at once, so contents and modified times stay the same.
  • Folders: one empty file named .sandbox-check- plus random letters and .tmp is created and deleted at once. That includes the login-items folder (Library/LaunchAgents on macOS; the autostart and systemd user folders on Linux). The folder's own modified time changes, and a file watcher (a dev server, a sync app) may notice for a moment. A test file that cannot be deleted is named in the report.
  • Targets that do not exist stay absent: the probe tests only what is there.
  • Docker socket and SSH agent: connect, then close, with no data sent. A socket-activated Docker or Podman service starts when something connects, so the probe can start it.
  • sudo: sudo -n true, the form that fails instead of asking for a password. The system log may record the attempt; --skip-sudo leaves sudo alone.
  • Environment variables: names and value lengths only.
  • Settings files of Claude Code, Codex, and Gemini CLI: parsed for their sandbox keys, which are the only part the report shows.
  • Network: used only with --network.

On a work machine, endpoint security and audit rules may log or flag the probe: the sudo attempt, the test file in the login-items folder, and the write-opens of shell startup files and the SSH authorized_keys file. On Linux, each append check also sends a file-close event to any program watching that file.

scripts/targets.json lists every path the probe checks, so it names credential files by design. Each of those lines carries the marker skillscan:allow, which tells this repository's security scanner that the path is a probe target, not a file the skill reads.

Steps

<skill-dir> means the folder that holds this SKILL.md (Claude Code shows it as the skill's base directory). Run every command from the user's project folder.

  1. Explain the probe in two or three sentences drawn from "What the probe touches", including the sudo attempt and the login-items test file that security tools may flag. Done when the user says to go ahead. Wait for that answer before step 2.

  2. Run the probe once, through your normal shell tool:

    bash
    python3 "<skill-dir>/scripts/probe.py" --project .

    --project is the folder the agent works in. When python3.11 or newer is installed (such as python3.12 or python3.13), use it in place of python3: the stock macOS python3 is 3.9, which skips the Codex settings comparison. The run takes about a second and exits 0 even when checks are blocked: blocked checks are the result, not an error. Run it exactly as sandboxed as every other command in this session, and report what the sandbox blocked as blocked. Keep it out of any sandbox bypass (such as a dangerouslyDisableSandbox retry): an unsandboxed rerun measures a different shell and turns a good result into a false alarm. Done when the output starts with a bold headline sentence, or you have told the user the exact error. Exit code 2 means a bad argument or a missing project folder; Python also exits 2 when the script path is wrong.

  3. Offer the network check as its own choice. Say that it looks up github.com and pypi.org, opens and closes a TCP connection to each on port 443 and to the cloud metadata address 169.254.169.254 on port 80, sends no data, and waits at most 3 seconds per host. Run it only after a clear yes:

    bash
    python3 "<skill-dir>/scripts/probe.py" --project . --network

    Done when the user declined, or the new report's Network rows read open or blocked.

  4. Choose the fixes. Open references/fixes.md at the section for the harness named on the report's "agent" line, and pick the two or three fixes that close the most Critical and High rows. When that section has no fix for a row (the SSH agent, for example), use the section "For any harness". Use references/trust-handoff.md to explain why a row matters. Done when each chosen fix names the exact setting, flag, or command to change.

  5. Report in the shape below. A fix that edits a settings file is a proposal: show the exact change, and apply it only after a clear yes.

Show full SKILL.md (737 more words)Show less

Read the results

  • Headline: the sentence to lead with. It counts readable secret files, then names the worst reach: running as root, sudo without a password, control of Docker, writes to git hooks.
  • Score: N of M checks open, split by risk. Only checks that ran are counted: missing, skipped, hidden, and unknown checks and Info rows are left out.
  • Status of each check:
    • open: reachable from this shell. A read-only file in a writable folder also counts as open, because it can be replaced; its detail says so.
    • blocked: exists, but the open, write, or connect was refused. A folder that refuses lookups gets one blocked row.
    • hidden: inside a folder that refuses lookups, so the probe cannot tell whether it exists.
    • missing: not present, so not tested. A socket file with nothing listening reads missing too.
    • skipped: a cloud placeholder, --skip-sudo, or network not requested.
    • unknown: an unexpected error; --json has the detail.
  • Risk levels:
    • Critical: control Docker, write git hooks or git config, change shell startup files, add login items or SSH login keys, sudo without a password, running as root.
    • High: readable secret files, harness settings, hooks, skills, and subagents, the editor folder and virtualenv, new files in the home folder, the SSH agent, the cloud metadata address.
    • Medium: secret-like environment variables, new files in the parent folder, direct internet connections.
    • Info: the project folder itself, and DNS.
  • Where it runs: the user, the operating system, the harness (found from the variables each harness sets in its shell: CLAUDECODE, CODEX_SANDBOX and other CODEX_ variables, GEMINI_CLI, CURSOR_SANDBOX), container signs, and sandbox markers. "Agent: none found" means the probe ran in a plain terminal, so the results show what any program started there can reach.
  • Settings compared with what the probe found: gaps between what the settings of the harness that ran the probe claim and what got through.
    • "Settings say workspace-write, yet ~/.zshrc is writable" means the command ran outside the sandbox, or the sandbox allows more than its settings suggest.
    • "The sandbox leaves ./.vscode writable" is a trust handoff the sandbox allows by design; references/trust-handoff.md has the documented escapes that used it.
    • "The sandbox is off" is the finding that explains most open rows. The probe reads settings files only, so when writes to the home folder were blocked anyway, it turns this into a note: a sandbox from --settings or managed settings may be on.
  • Notes: what was not checked and why, such as a Codex config skipped on Python older than 3.11.
  • --json lists every target, missing ones included, each with id, category, group, risk, target, status, and detail, plus settings, gaps, and leftovers.

Report to the user

  1. The headline, verbatim, in bold.
  2. The report's table cut to rows with something open, eight rows at most: Critical rows first, then High. If any open row does not fit, name the dropped rows in one line under the table.
  3. The gaps from "Settings compared with what the probe found", one line each.
  4. The two or three fixes from step 4, each with the exact setting and a pointer to references/fixes.md.
  5. One closing line: offer the network check if it has not run, and name any test file the report says could not be deleted, so the user can remove it.

Quote paths exactly as the report prints them: it shows the home folder as ~, a folder moved by a variable as $VARIABLE, and names and lengths in place of secret values. Names from the file system and values from settings arrive as one plain line, with secret-shaped text masked and backticks and pipes replaced, and the Markdown report shows them inside inline code, so they stay inert text.

Files

  • scripts/probe.py: the probe. Python 3.9+, standard library only. Flags: --project, --network, --skip-sudo, --json, --out <path>, --fail-on critical|high|medium (exit 1 when a check at that level is open).
  • scripts/targets.json: every path, socket, variable pattern, harness marker, and settings file the probe checks, with the scanner marker on each credential line.
  • scripts/safe.py: the text cleaner that several skills in this repository share. It masks secret-shaped text and keeps each name from the file system or settings on one line, inside inline code in the Markdown report.
  • references/trust-handoff.md: why each target matters, with the Pillar Security and Cloud Security Alliance findings and their CVE ids.
  • references/fixes.md: fixes for Claude Code, Codex, Gemini CLI, Cursor, and OpenCode, plus fixes for any harness.

© RyanAlberts, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references) in skills/sandbox-check of RyanAlberts/best-of-Agent-Harnesses.

  • SKILL.md
  • LICENSE.txt
  • README.md
  • references/fixes.md
  • references/trust-handoff.md
  • scripts/probe.py
  • scripts/safe.py
  • scripts/targets.json

Open the folder on GitHubat commit 4fa20bc

Compare with similar skills

Sandbox Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sandbox Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sandbox Check this skillRyanAlberts/best-of-Agent-Harnesses1.1k—~3.1kAutomated safety check: NotesMIT
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
LangBot Deployment Guidelangbot-app/LangBot18k—~1.5kAutomated safety check: NotesApache-2.0
Ssh Skillbadseal/ssh-skill538—~2.4kAutomated safety check: NotesNone
Add Config Env Varbaserow/baserow6.1k—~1.1kAutomated safety check: PassCustom licence
Crabbox Quickstartopenclaw/crabbox1.5k—~1.6kAutomated safety check: NotesMIT

Similar skills

  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Ssh Skill

    badseal/ssh-skill

    A skill your agent uses when a task requires SSH or SCP/SFTP behavior, a remote server, server alias/IP/hostname/user@host, bastion or jump-host access, remote command execution, upload/download…

    538 GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Add Config Env Var

    baserow/baserow

    Add a Baserow configuration environment variable for the backend, frontend, or both, and propagate it through settings, Nuxt runtime config, Docker Compose, documentation, consumers, and tests as…

    6.1k GitHub stars~1.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Crabbox Quickstart

    openclaw/crabbox

    Gets you running your repository's tests in a disposable Docker or Podman container on your own machine with Crabbox, with no account and no cloud spend.

    1.5k GitHub stars~1.6k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Rtk Skill

    sopaco/deepwiki-rs

    A skill your agent uses when running shell commands that produce verbose output (git, test, build, lint, package managers, docker).

    3.1k GitHub stars~1.4k tokensUpdated 27 days ago
    DevOps & CloudAuto-check passed

More from RyanAlberts/best-of-Agent-Harnesses

All 9 skills in this repo
  • Agents Md Checker

    RyanAlberts/best-of-Agent-Harnesses

    Checks which instruction files (AGENTS.md, CLAUDE.md, GEMINI.md, Cursor rules, Copilot instructions) each coding agent loads from a repo, what gets cut or skipped, and whether the commands those…

    1.1k GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Claim Check

    RyanAlberts/best-of-Agent-Harnesses

    Claim checker that audits a coding agent's statements that tests pass or a build is clean against its own session transcripts: whether a matching run happened before the claim, whether it passed…

    1.1k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Guardrail Tester

    RyanAlberts/best-of-Agent-Harnesses

    Guardrail tester that checks whether the permission rules and PreToolUse hooks already set up in Claude Code, Codex, Gemini CLI, OpenCode, or Cursor stop a battery of dangerous commands, including…

    1.1k GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Harness Test Drive

    RyanAlberts/best-of-Agent-Harnesses

    Test-drives coding agents (Claude Code, Codex, Gemini CLI) on tasks mined from the user's own git history: each agent gets a past commit message in a fresh copy of the repo, and the repo's own tests…

    1.1k GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Regression Finder

    RyanAlberts/best-of-Agent-Harnesses

    Regression check for coding agents: shows how the agent behaved before and after each harness update, model switch, or week in the user's own Claude Code or Codex history, and finds the point where…

    1.1k GitHub stars~3k tokensUpdated 2 days ago
    Auto-check passed
  • Rules To Guards

    RyanAlberts/best-of-Agent-Harnesses

    Rule enforcer that finds which written rules in AGENTS.md, CLAUDE.md, and GEMINI.md a coding agent keeps breaking, counts every violation in recent Claude Code, Codex, Gemini CLI, and OpenCode…

    1.1k GitHub stars~2.7k tokensUpdated 2 days ago
    Auto-check: notes

Works with

Categories

Questions about Sandbox Check

What does Sandbox Check do?

Sandbox audit that probes, from inside a live coding-agent session, what the agent can really reach: secret files it can open, secret-like environment variables, files that git, the shell, the…. Sandbox Check is an agent skill from RyanAlberts/best-of-Agent-Harnesses. Sandbox audit that probes, from inside a live coding-agent session, what the agent can really reach: secret files it can open, secret-like environment variables, files that git, the shell, the editor, or the harness later run (git hooks, shell startup files, harness settings), writes outside the project, the Docker socket, the SSH agent, and passwordless sudo.

When should I use Sandbox Check?

Sandbox Check fits situations like: the user asks what the agent can access; write on this machine; whether the sandbox actually works; how big the blast radius is if the agent gets prompt-injected.

How do I install Sandbox Check in Claude Code?

Run `npx skills add RyanAlberts/best-of-Agent-Harnesses --skill sandbox-check -a claude-code`. Or copy the skill folder (skills/sandbox-check in RyanAlberts/best-of-Agent-Harnesses) into .claude/skills/sandbox-check in your project. Claude Code loads it when a task matches its description.

How do I install Sandbox Check in Codex?

Run `npx skills add RyanAlberts/best-of-Agent-Harnesses --skill sandbox-check -a codex`. Or copy the skill folder (skills/sandbox-check in RyanAlberts/best-of-Agent-Harnesses) into .agents/skills/sandbox-check in your project. Codex loads it when a task matches its description.

Can I use Sandbox Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add RyanAlberts/best-of-Agent-Harnesses --skill sandbox-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sandbox-check, .gemini/skills/sandbox-check, .github/skills/sandbox-check and .opencode/skills/sandbox-check in your project.

What does Sandbox Check need to run?

Going by SKILL.md and its folder, Sandbox Check needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3; Docker. Compatibility (from SKILL.md): Python 3.9+ on macOS or Linux; Python 3.11+ to compare Codex settings. Without flags nothing touches the network. The optional --network flag makes DNS lookups and TCP connections (no data sent) to github.com, pypi.org, and the cloud metadata address 169.254.169.254..

Does Sandbox Check access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sandbox Check safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Sandbox Check use?

Sandbox Check is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sandbox Check use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.2k tokens, read only when the agent opens those files.

What are the alternatives to Sandbox Check?

Skills that share tags, products or a category with Sandbox Check: Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), LangBot Deployment Guide (langbot-app/LangBot, 18k stars), Ssh Skill (badseal/ssh-skill, 538 stars) and Add Config Env Var (baserow/baserow, 6.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sandbox Check?

RyanAlberts (a GitHub user) maintains it in RyanAlberts/best-of-Agent-Harnesses, which has 1,133 GitHub stars. The repository was last updated on October 9, 2026.

Source: RyanAlberts/best-of-Agent-Harnesses on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.