Agent skill

Sandbox SDK

by swyxio in swyxio/skills

Build or debug applications that specifically use Cloudflare Sandbox SDK (@cloudflare/sandbox) for isolated command execution, code interpretation, files, processes, sessions, or preview URLs.

MITAuto-check passedDevelopment

Install Sandbox SDK

skills CLI
$ npx skills add swyxio/skills --skill sandbox-sdk -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install swyxio/skills sandbox-sdk --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/swyxio/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/sandbox-sdk .claude/skills/sandbox-sdk && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sandbox-sdk
GitHub stars
175
Token cost
~704 tokens
SKILL.md length
335 words
Files
3 (incl. references)
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

Build or debug applications that specifically use Cloudflare Sandbox SDK (@cloudflare/sandbox) for isolated command execution, code interpretation, files, processes, sessions, or preview URLs.

  • Generic container design
  • SKILL.md covers Establish the isolation contract, Configure from current docs, Choose execution deliberately and Verify the real lifecycle
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Local shell scripting

What it does

Sandbox SDK is an agent skill from swyxio/skills. Build or debug applications that specifically use Cloudflare Sandbox SDK (@cloudflare/sandbox) for isolated command execution, code interpretation, files, processes, sessions, or preview URLs. Do not trigger for generic container design, local shell scripting, or unrelated sandbox products.

Its SKILL.md is about 700 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/api-quick-ref.md` and `references/examples.md`).

It sits in Development, covering Shell scripting. It works with Cloudflare and Bash. The repository describes itself as: Agent skills for Claude Code and other AI agents. The licence is MIT.

When your agent uses it

  • Generic container design
  • Local shell scripting
  • Unrelated sandbox products

Example prompts

  • “/sandbox-sdk”

What it can do on your machine

Read from SKILL.md and the folder at commit 038ef34. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sandbox SDK loads about 704 tokens when it runs, and up to ~1.9k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 335 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~704
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from swyxio/skills at commit 038ef34, republished under its MIT licence (© swyxio). 335 words, ~704 tokens.

Download SKILL.mdSave it as .claude/skills/sandbox-sdk/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
sandbox-sdk
description
Build or debug applications that specifically use Cloudflare Sandbox SDK (`@cloudflare/sandbox`) for isolated command execution, code interpretation, files, processes, sessions, or preview URLs. Do not trigger for generic container design, local shell scripting, or unrelated sandbox products.

Cloudflare Sandbox SDK

Use current Cloudflare docs and the installed package as the API contract. The SDK and its container topology evolve quickly; inspect package exports, types, Wrangler schema, and generated configuration before coding.

Establish the isolation contract

Identify:

  • who chooses the sandbox ID and how it is scoped to a tenant or session;
  • which code, files, environment variables, and network access are untrusted;
  • what must survive container sleep or recreation;
  • which operations need a shared session versus isolated execution; and
  • whether an exposed service is private, temporary, or public.

A Sandbox is backed by a Durable Object and its container starts lazily. The same ID selects the same logical Sandbox, but container-local files, processes, and shell state can be lost after sleep or restart. Put durable application state outside the ephemeral container filesystem.

Configure from current docs

Verify the exact container, Durable Object binding, and class lifecycle required by the installed SDK. Re-export the SDK's Sandbox class from the Worker when the current integration requires it. Do not copy a pinned image tag, lifecycle declaration, instance type, or preview-domain configuration from this skill.

Use api-quick-ref.md only after checking installed types. Use examples.md to locate a relevant upstream example rather than combining several patterns speculatively.

Choose execution deliberately

  • Use command/process APIs when exit status, streams, or process lifecycle is the contract.
  • Use code-interpreter APIs when structured rich results or a deliberate session is required.
  • Disable or avoid shared default sessions when calls must be isolated.
  • Scope IDs and credentials so one tenant cannot address another tenant's sandbox.
  • Bound input, runtime, output, files, processes, and cleanup according to the untrusted-code threat model.
  • Treat preview URLs as public capabilities unless an owning authentication layer proves otherwise. Check current custom-domain and tunnel requirements.

Verify the real lifecycle

Test the exact package version and generated Worker bundle. Exercise creation, one representative command or code run, expected file/session behavior, sleep/recreation when persistence matters, cleanup, and any exposed route. Successful object creation alone does not prove container execution or preview routing.

© swyxio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in sandbox-sdk of swyxio/skills.

  • SKILL.md
  • references/api-quick-ref.md
  • references/examples.md

Open the folder on GitHubat commit 038ef34

Compare with similar skills

Sandbox SDK next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sandbox SDK compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sandbox SDK this skillswyxio/skills175—~704Automated safety check: PassMIT
Mole Bug Patternstw93/Mole70k—~2kAutomated safety check: PassGPL-3.0
CLI DeveloperJeffallan/claude-skills12k1 repos~1.2kAutomated safety check: PassMIT
JSON Processing with jqcharmbracelet/crush29k—~746Automated safety check: PassCustom licence
Shellm Architecture Referencelaude-institute/headlong1.2k—~2kAutomated safety check: NotesApache-2.0
Cppcrazyguitar/cppcheatsheet290—~1.8kAutomated safety check: PassMIT

Similar skills

  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    70k GitHub stars~2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • CLI Developer

    Jeffallan/claude-skills

    Walks through designing, building and polishing a command-line tool: user workflow and command hierarchy, implementation in commander, click, typer or cobra, completions and cross-platform testing.

    12k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed
  • JSON Processing with jq

    charmbracelet/crush

    Explains the jq command built into Crush for querying, filtering and reshaping JSON, including its supported flags and where it differs from standard jq.

    29k GitHub stars~746 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Shellm Architecture Reference

    laude-institute/headlong

    Explains how shellm's bash-based recursive LLM shell fits together - its core engine, identity system, memory, skills and trajectory log.

    1.2k GitHub stars~2k tokensUpdated 3 days ago
    DevelopmentAuto-check: notes
  • Cpp

    crazyguitar/cppcheatsheet

    Comprehensive C/C++ programming reference covering everything from C11-C23 and C++11-C++23, system programming, CUDA GPU computing, debugging tools, Rust interop, and advanced topics.

    290 GitHub stars~1.8k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Bash Scripting

    promovaweb/setupvibe

    Bash scripting workflow for creating production-ready shell scripts with defensive patterns, error handling, and testing.

    102 GitHub starsUsed in 4 repos~1.2k tokens
    DevelopmentAuto-check passed

More from swyxio/skills

All 89 skills in this repo
  • Programmatic Agents

    swyxio/skills

    Run a selected coding-agent CLI programmatically, with latency, error, usage, cost, and trace logging.

    175 GitHub stars~2.2k tokensUpdated 5 days ago
    Auto-check passed
  • Design, implement, audit, or refresh protected username and handle namespaces for public products.

    175 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • New Mac Setup

    swyxio/skills

    Fully automated new Mac setup for fullstack web developers and AI engineers.

    175 GitHub stars~4.3k tokensUpdated 5 days ago
    Auto-check passed
  • Youtube API

    swyxio/skills

    Manage YouTube videos programmatically via the YouTube Data API v3 — upload video files, upload custom thumbnails, update video metadata (titles, descriptions, tags), and query video/channel info…

    175 GitHub stars~2.2k tokensUpdated 5 days ago
    Auto-check passed
  • Batch YouTube Studio upload workflow for videos sourced from Airtable, Google Drive, Loom, YouTube, or local files.

    175 GitHub stars~1.5k tokensUpdated 5 days ago
    Auto-check: warnings
  • Reconstruct and visually analyze paired agent, game, or policy trajectories to determine whether changed actions produced their intended effects.

    175 GitHub stars~1.8k tokensUpdated 5 days ago
    Auto-check passed

Works with

Categories

Questions about Sandbox SDK

What does Sandbox SDK do?

Build or debug applications that specifically use Cloudflare Sandbox SDK (@cloudflare/sandbox) for isolated command execution, code interpretation, files, processes, sessions, or preview URLs. Sandbox SDK is an agent skill from swyxio/skills. Build or debug applications that specifically use Cloudflare Sandbox SDK (@cloudflare/sandbox) for isolated command execution, code interpretation, files, processes, sessions, or preview URLs.

When should I use Sandbox SDK?

Sandbox SDK fits situations like: generic container design; local shell scripting; unrelated sandbox products.

How do I install Sandbox SDK in Claude Code?

Run `npx skills add swyxio/skills --skill sandbox-sdk -a claude-code`. Or copy the skill folder (sandbox-sdk in swyxio/skills) into .claude/skills/sandbox-sdk in your project. Claude Code loads it when a task matches its description.

How do I install Sandbox SDK in Codex?

Run `npx skills add swyxio/skills --skill sandbox-sdk -a codex`. Or copy the skill folder (sandbox-sdk in swyxio/skills) into .agents/skills/sandbox-sdk in your project. Codex loads it when a task matches its description.

Can I use Sandbox SDK in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add swyxio/skills --skill sandbox-sdk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sandbox-sdk, .gemini/skills/sandbox-sdk, .github/skills/sandbox-sdk and .opencode/skills/sandbox-sdk in your project.

What does Sandbox SDK need to run?

SKILL.md names no scripts, command-line tools or credentials: Sandbox SDK is instructions for the agent only.

Does Sandbox SDK access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sandbox SDK safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sandbox SDK use?

Sandbox SDK is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sandbox SDK use?

About 704 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Sandbox SDK?

Skills that share tags, products or a category with Sandbox SDK: Mole Bug Patterns (tw93/Mole, 70k stars), CLI Developer (Jeffallan/claude-skills, 12k stars), JSON Processing with jq (charmbracelet/crush, 29k stars) and Shellm Architecture Reference (laude-institute/headlong, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sandbox SDK?

swyxio (a GitHub user) maintains it in swyxio/skills, which has 175 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on October 5, 2026.

Source: swyxio/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.