Vercel Composition Patterns
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
Author or edit a Strands Box policy (policy.dw) — turn an operator's natural-language allow/deny intent into a validated Dogwood policy over the box's fixed action vocabulary, including when…
$ npx skills add strands-agents/box --skill authoring-box-policy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install strands-agents/box authoring-box-policy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/strands-agents/box.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/authoring-box-policy .claude/skills/authoring-box-policy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "authoring-box-policy" agent skill from https://github.com/strands-agents/box/tree/main/.agents/skills/authoring-box-policy into .claude/skills/authoring-box-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authoring-box-policy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/strands-agents/box/tree/main/.agents/skills/authoring-box-policyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add strands-agents/box --skill authoring-box-policy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install strands-agents/box authoring-box-policy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/strands-agents/box.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/authoring-box-policy .agents/skills/authoring-box-policy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "authoring-box-policy" agent skill from https://github.com/strands-agents/box/tree/main/.agents/skills/authoring-box-policy into .agents/skills/authoring-box-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authoring-box-policy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add strands-agents/box --skill authoring-box-policy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install strands-agents/box authoring-box-policy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/strands-agents/box.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/authoring-box-policy .cursor/skills/authoring-box-policy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "authoring-box-policy" agent skill from https://github.com/strands-agents/box/tree/main/.agents/skills/authoring-box-policy into .cursor/skills/authoring-box-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authoring-box-policy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/strands-agents/box.git --path .agents/skills/authoring-box-policy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add strands-agents/box --skill authoring-box-policy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install strands-agents/box authoring-box-policy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/strands-agents/box.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/authoring-box-policy .gemini/skills/authoring-box-policy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "authoring-box-policy" agent skill from https://github.com/strands-agents/box/tree/main/.agents/skills/authoring-box-policy into .gemini/skills/authoring-box-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authoring-box-policy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install strands-agents/box authoring-box-policyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add strands-agents/box --skill authoring-box-policy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/strands-agents/box.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/authoring-box-policy .github/skills/authoring-box-policy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "authoring-box-policy" agent skill from https://github.com/strands-agents/box/tree/main/.agents/skills/authoring-box-policy into .github/skills/authoring-box-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authoring-box-policy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add strands-agents/box --skill authoring-box-policy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install strands-agents/box authoring-box-policy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/strands-agents/box.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/authoring-box-policy .opencode/skills/authoring-box-policy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "authoring-box-policy" agent skill from https://github.com/strands-agents/box/tree/main/.agents/skills/authoring-box-policy into .opencode/skills/authoring-box-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authoring-box-policy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
authoring-box-policyAuthor or edit a Strands Box policy (policy.dw) — turn an operator's natural-language allow/deny intent into a validated Dogwood policy over the box's fixed action vocabulary, including when…
Authoring Box Policy is an agent skill from strands-agents/box. Author or edit a Strands Box policy (policy.dw) — turn an operator's natural-language allow/deny intent into a validated Dogwood policy over the box's fixed action vocabulary, including when temporal { … } history rules. Use when writing, editing, reviewing, or converting an intent into a box policy. This skill CREATES or EDITS a policy against the box's built-in schema — you never author a Dogwood schema, because the box ships a fixed one.
Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including reference files (for example `examples/README.md`, `references/dogwood-policy-language.md` and `references/dogwood-temporal-expressions.md`).
It sits in Development. The repository describes itself as: Run AI agents in a sandbox that restricts what they can execute, read, write, and reach on the network. Box combines OS isolation with default-deny Dogwood policies and… The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ff8e809. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Authoring Box Policy loads about 5.4k tokens when it runs, and up to ~29k if it reads all its reference files. Until then it costs about 117 tokens; SKILL.md has 2,858 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from strands-agents/box at commit ff8e809, republished under its Apache-2.0 licence (© strands-agents). 2,858 words, ~5,445 tokens.
.claude/skills/authoring-box-policy/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.Your job: turn a natural-language authorization intent into a Dogwood policy.dw for a Strands
Box that loads clean and means what the operator actually intended. This is a formalization task
— the hard part is not the syntax (that is documented; see Ground truth)
but pinning down ambiguous intent and mapping it onto the right construct over the box's fixed
vocabulary.
This is an interactive session, not a one-shot generator. You work with the operator: draw out the intent, ask a sharp question rather than guess when a requirement is underspecified, propose rules, and confirm what stays refused. Do not return a policy you have not loaded.
You author rules, not a schema. A generic Dogwood deployment makes the operator author an action
schema and a service schema. Strands Box does not — the box ships a fixed, built-in schema, so the
vocabulary of actions, the one principal, and the context shape are already set. You write the
permit and forbid rules against that schema — the fixed vocabulary is
below.
Follow the loop in order:
policy.dw.Treat these as authoritative; do not invent syntax, an action, or a field from memory. If a construct is not in these sources, it does not exist.
Box-specific — the vocabulary and the floors:
box policy generate-schema, which writes .strands-box/actions.cedarschema (actions and
their context) and .strands-box/events.dwschema (what a when temporal { … } rule observes).
The generated files also carry each declared MCP server's per-tool actions, which a static copy
cannot.examples/ — whole agent policies and single-shape refinements to copy from. See
examples/README.md.docs/design/decisions.md: the
closed action vocabulary,
the filesystem actions,
temporal rules, and
a credential binding is not an authorization.Language grammar — bundled in this skill's references/:
references/dogwood-policy-language.md — core policy syntax: permit/forbid, the
(principal, action, resource) scope, when/unless, and the full Cedar expression language
(operators, literals, methods, has/like/is, sets/records). See its "Condition expression
language" and "What parses but is rejected" sections.references/dogwood-temporal-expressions.md — the temporal { … } sublanguage:
formerly/previous/since, windows, exists/tp, count/sum, and the acceptance rules.
Read "Writing temporal expressions that are accepted" in full before writing any history rule.Every request is (principal, action, resource, context). The principal is always
Box::Agent::"self" (leave it a bare principal) and the resource is always
Box::Resource::"unused", so the action scopes a rule and every readable field rides
context.input. There is no context.system, no context.principal, and no now; the only field
outside input is output, on a ::response, read only by a temporal rule: output.result on a
filesystem response, output.status on an http:request response, and the exit output.status on a
shell:exec or shell:spawn response.
The actions are a closed set. A policy names one; it cannot add one. The last column is the exact
context.input fields you scope on.
| Action | context.input fields |
|---|---|
fs:read / fs:write / fs:delete / fs:move / fs:other | path: String, operation: Fs<Kind>Operation |
net:connect | host: String, ip?: ipaddr, port: Long |
http:request | host, port, method, path (a URL path), body_bytes: Long, intercepted: Bool; the reply's status: Long is on output, matched as ::response{ output.status: 500 } in a temporal predicate |
shell:exec | command, program, arg1?, arg2?, arg_count: Long, cwd; the exit status: Long is on output, matched as ::response{ output.status: 0 } in a temporal predicate (a signal reports 128 plus its number, a permitted binary that cannot start reports 126, a command with no reported status reports -1, and a background & command records its status when it ends) |
shell:spawn | the shell:exec fields plus program_path: String, and the same output.status. The workload can set a shell:exec status (a shell function of the same name does it), so a precondition on a host binary's success reads shell:spawn and pins program_path |
mcp:call | server, method, tool?, prompt?, uri? |
<server>::Action::"<tool>" | per-tool, emitted by box policy generate-schema |
Filesystem operation enums (narrow within an fs: action):
FsReadOperation = read_content, read_metadata, enumerate, read_link, change_dir, exec;
FsWriteOperation = write_content, create_dir, set_permissions, symlink;
FsDeleteOperation = remove_file, remove_dir; FsMoveOperation = rename;
FsOtherOperation = other.
Rules that bite:
fs:read does not cover fs:write; cover a family one clause per action.net:connect (port, before TLS) and http:request
(host, after TLS).has (arg1, arg2, tool, prompt, uri, ip); an unguarded
read is a load error.path is a filesystem path on fs:* and a URL path on http:request; only fs:* carries
operation, so guard a filesystem rule with context.input has operation.program (what the first word resolved to), not command. Do not read ip
in a temporal predicate — it faults.tool:invoke, model:invoke, agent:invoke, and cred:inject are removed — naming one is an
UnknownAction load error.Temporal event shape. For action A: a A::request (its input fields), a A::response (its
input and output fields, only for an effect that happened), and a A::error. Key a
precondition on ::response; a window is mandatory and capped at 24h; there is no ||.
For the rationale behind the vocabulary, read the ## Policy section of
docs/design/decisions.md.
A policy only ever adds reachability. Some things hold whatever a rule says:
forbid always beats a permit.
An exception to a broad allow is a forbid that carves a hole, never a narrower permit..strands-box directory and every write to the
box.toml and policy this run loaded, beneath policy, in every box. No rule widens it.[egress.*] entry in box.toml says
only what is attached to a request the policy already permitted. It never makes a destination
reachable — reachability is this policy's decision alone. The two must name the same host.Provider::Name(args) call or a guardrails { … }
clause aborts box startup. Do not reach for a computed fact — there is no provider path in the box.A prose intent almost always leaves gaps that change the formal policy. Resolve every gap that affects the output. If you can infer the answer from an obvious convention, state your assumption and proceed; otherwise ask. Prefer a few sharp, batched questions over silently guessing.
Every policy needs egress to an LLM provider. The agent cannot run without reaching a model, so
a policy that grants no provider access does not work — confirm which one (Amazon Bedrock, OpenAI, or
Anthropic) and write its two egress legs (net:connect and http:request) before anything else.
Match the provider to the box's configured endpoint. See the three agent examples in examples/.
permit) or restricting (forbid)? The box is default-deny
with deny-overrides. "The agent may X" → a permit. "Never X" / "block X when Y" → a forbid
that carves a hole out of the permits.fs: verb), and two legs for one outbound host (net:connect and
http:request).context.input.<field> — confirm the field name
and type against the table. There is no principal/resource attribute to read (both are fixed), no
context.system, and no provider for a computed fact. A fact about the past goes to the
temporal sublanguage (Step 2b).~-relative paths so the file is portable. For a host, get the exact hostname and port.formerly within W.previous within W.left since within W right;
"has NOT happened since" → a negated since left (there is no dedicated operator).W is mandatory (s/m/h/d; no week/month/year) and capped at 24h in
the box. If the operator says "recently" without a number, ask — there is no default, and you
cannot raise the cap (the event schema is fixed).input.path: context.input.path. With one principal, principal-correlation is automatic;
correlate anything else (same path, same host) explicitly, or "the same X" silently becomes
"any X".count/sum (no min/max/avg). Confirm the threshold and operator.::response, never ::request. A ::request event exists even for a denied
attempt, so a step-up keyed on ::request is defeated by asking and being refused. A
::response exists only for an effect that happened.has guard)? Inclusive boundary
(windows are closed)? Surface these and pick a defensible default, stating it.Tie each question to how it changes the policy — "'recent' — within what window (e.g. 1h)? And
the same host the agent reached, or any host?" — not a vague "can you clarify?".
Map the disambiguated intent onto the rule shape (doc comment, @id, @description on a forbid,
effect, scope, when/unless, ;). Lead each rule with a // comment in the operator's words and
an @id("…"). Keep the scope as the coarse filter (the action) and put fine logic in when/unless.
Give every forbid a @description("…") that the agent can act on. The box prints every
@description on a determining forbid into the denial message that the agent sees, so the string
is how the policy talks to the agent about why a request was refused. Say what is refused and what
the agent should do instead — a sentence the agent can read and take a different action from, not an
internal note. A @description on a permit is ignored, so put the author's reason there in a
leading // comment instead.
// Refuse setting permissions anywhere, whatever a write permit allows.
@id("no_chmod")
@description("This workload cannot change file permissions. Make the file writable before the box starts, or ask the operator to add a chmod rule.")
forbid ( principal, action == Box::Action::"fs:write", resource )
when { context.input.operation == Box::FsWriteOperation::"set_permissions" };Use the operator/method vocabulary from references/dogwood-policy-language.md. Watch the type rules
it calls out: decimals are equality-only, / and % are unsupported, and there is no let … in.
temporal { … })Attach when temporal { … } (or unless temporal { … } for absence) and build the body from
predicates and the formerly/previous/since operators. Every field a predicate reads is derived
from the action's input record.
// Refuse a write once six writes have completed in the last 60 seconds.
@id("write_budget")
forbid ( principal, action == Box::Action::"fs:write", resource )
when temporal {
exists (total: Long). (
(count for (t: Timepoint). where (
formerly within 60s (
Box::Action::"fs:write"::response{ input.path: _, input.operation: Box::FsWriteOperation::"write_content" } && tp(t)
)
)) == total
&& total >= 6
)
};A cap is a forbid. A permit only adds permission, so a permit cannot narrow another permit:
permit … when temporal { total < 6 } beside a broader fs:write permit caps nothing, and the box
refuses that shape at load. Write the budget as a forbid that fires at or above the cap. The permit
shape is correct only when it is the sole permit for that action; then write that reason in a
comment above the rule.
The sublanguage has strict acceptance rules — closedness, range restriction, conjunct order,
aggregates as operands, tp-dependence — and a plausible-looking rule is routinely rejected. Read
"Writing temporal expressions that are accepted" in references/dogwood-temporal-expressions.md
before you write one, and copy the budget shape above from examples/temporal-write-budget.dw.
There is no || — "A or B" is two rules.
Not available. The box aborts startup on an information provider or a guardrails clause. If the
intent needs a computed fact (a regex denylist, a risk score), it cannot be expressed as box policy —
say so rather than reach for a provider.
Every policy MUST load into the box before you present it. There is no standalone validator, no
dogwood CLI in this repository, and no validate verb on the box. The box validates the policy
at load, fail-closed: an unknown action or a mistyped attribute aborts startup with a load error,
so an unloaded policy is a guess.
strands-box run re-reads box.toml and policy.dw every time, so the whole loop is: edit a rule,
run again, read the result.
How to test the policy you just wrote. Use the existing
Strands getting-started guide for a complete configuration.
From a project with .strands-box/box.toml and .strands-box/policy.dw, run its configured agent:
strands-box run --config .strands-box/box.tomlAsk the agent to perform one permitted action and one forbidden action. Inspect the decision log for the expected rules. Edit the policy and run the same configuration again.
A load proves the policy is legal, not that a temporal rule means what you intended — the box has no replay or trace tool. For a history rule, reason carefully against the acceptance rules and, where you can, exercise the box to see the effect deny as expected.
A runtime denial is often a box.toml problem, not a policy bug — read box.toml before you
touch the policy. The policy decides only reachability; box.toml decides which endpoint the
agent calls, what environment it runs in, and which credential is attached. When a run is refused,
check box.toml for these before editing a rule:
AWS_REGION against the destination in box.toml and the host in the policy.AWS_REGION and other workload variables in box.toml's [agent.env] table.
Box reserves its proxy routing, certificate, and identity variables.[egress.<name>] entry naming a reference (env://VAR, aws://<profile>), never a literal. A
binding is not an authorization — it and the policy must name the same host.So a 403 or a refused host is frequently the policy working correctly over a box.toml that points
the agent, its environment, or its credential somewhere the policy does not grant.
Only after the policy loads, do a final intent check and present the result. Re-read the policy back into English and confirm the effect (permit vs forbid), the correlation pins ("same" vs "any"), the window, and inclusive boundaries.
Return, in this order:
policy.dw rules, each with a // comment, an @id, and (on every forbid) a
@description the agent can act on.Keep the policy minimal and idiomatic — match the bundled examples/. Do not add rules the operator
did not ask for.
Point the operator at the bundled examples/; these are the patterns that recur.
examples/agent-anthropic.dw.context.input.path == "~/project" or context.input.path like "~/project/*". A bare prefix
also matches a sibling whose name merely starts the same way.forbid on the exact action. See
examples/forbid-delete.dw.forbid on shell:exec with a has-guarded argument read. See
examples/shell-guard.dw.forbid with a when temporal { … } count over one action, keyed
on ::response, that fires at or above the cap. A permit cannot narrow another permit, so a cap is
a forbid. See examples/temporal-write-budget.dw.[egress.*] binding to make a host reachable — write the net:connect and
http:request rules.forbid.::request, and do not read ip in a temporal predicate.permit beside another permit for the same action; the box refuses it
at load, because the permit cannot narrow the other one.forbid without a @description. The agent reads that string on a denial, so an
absent one leaves it to retry the same request.© strands-agents, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (references) in .agents/skills/authoring-box-policy of strands-agents/box.
Open the folder on GitHubat commit ff8e809
Authoring Box Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Authoring Box Policy this skillstrands-agents/box | 315 | — | ~5.4k | Automated safety check: Pass | Apache-2.0 | |
| Vercel Composition Patternssupabase/supabase | 111k | 58 repos | ~726 | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 297k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Typescript Advanced Typesrolling-scopes/rsschool-app | 10k | 25 repos | ~4.2k | Automated safety check: Pass | MPL-2.0 | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 4 repos | ~1.1k | Automated safety check: Pass | MIT |
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
rolling-scopes/rsschool-app
Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
onyx-dot-app/onyx
Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.
strands-agents/box
Debug a CI failure on an OS you are not on (you are on Linux, it fails on macos-latest, or the reverse) without opening a pull request per attempt.
strands-agents/box
Find the gaps in the Box documentation and produce a prioritized backlog for docs/user/ and docs/design/.
strands-agents/box
Draft or rewrite a Box documentation page in docs/user/ (tutorial, how-to, or reference for an operator) or docs/design/ (explanation for a security evaluator or a contributor), or a crate README.md…
strands-agents/box
Deep-dive a SINGLE key decision. An agent skill from strands-agents/box.
strands-agents/box
Walk through spec-driven development, design then requirements, producing a local .spec.md and .requirements.md for one feature.
strands-agents/box
Assess an existing Box documentation page (docs/user/, docs/design/, or a crate README.md) for accuracy against the code and its tests, placement, and voice, and recommend what to fix.
Categories
Author or edit a Strands Box policy (policy.dw) — turn an operator's natural-language allow/deny intent into a validated Dogwood policy over the box's fixed action vocabulary, including when…. Authoring Box Policy is an agent skill from strands-agents/box.dw) — turn an operator's natural-language allow/deny intent into a validated Dogwood policy over the box's fixed action vocabulary, including when temporal { … } history rules.
Authoring Box Policy fits situations like: converting an intent into a box policy.
Run `npx skills add strands-agents/box --skill authoring-box-policy -a claude-code`. Or copy the skill folder (.agents/skills/authoring-box-policy in strands-agents/box) into .claude/skills/authoring-box-policy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add strands-agents/box --skill authoring-box-policy -a codex`. Or copy the skill folder (.agents/skills/authoring-box-policy in strands-agents/box) into .agents/skills/authoring-box-policy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add strands-agents/box --skill authoring-box-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authoring-box-policy, .gemini/skills/authoring-box-policy, .github/skills/authoring-box-policy and .opencode/skills/authoring-box-policy in your project.
SKILL.md names no scripts, command-line tools or credentials: Authoring Box Policy is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Authoring Box Policy is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Authoring Box Policy: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
strands-agents (a GitHub organization) maintains it in strands-agents/box, which has 315 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 11, 2026.
Source: strands-agents/box on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.