Agent skill

Release Sandbox Tools

by UKGovernmentBEIS in UKGovernmentBEIS/inspect_ai

Land a PR that requires new inspect-sandbox-tools injectable binaries to be built and published.

MITAuto-check passed

Install Release Sandbox Tools

skills CLI
$ npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install UKGovernmentBEIS/inspect_ai release-sandbox-tools --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/UKGovernmentBEIS/inspect_ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/release-sandbox-tools .claude/skills/release-sandbox-tools && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release-sandbox-tools
GitHub stars
3k
Token cost
~1.1k tokens
SKILL.md length
599 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Land a PR that requires new inspect-sandbox-tools injectable binaries to be built and published.

  • Works in 4 steps: Confirm the trigger. The PR is approved… → Get a checkout of the PR's head branch… → Run the wizard from that checkout's repo… → …
  • Asked to build/validate/upload sandbox tools binaries
  • SKILL.md covers What you do and If the wizard fails or can't…
  • Calls aws

What it does

Release Sandbox Tools is an agent skill from UKGovernmentBEIS/inspect_ai. Land a PR that requires new inspect-sandbox-tools injectable binaries to be built and published. Use when asked to land/merge a PR that changed code under src/inspectsandboxtools/ (typically its slow-tool-tests-release check fails on missing published binaries), or when asked to build/validate/upload sandbox tools binaries.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Amazon Web Services. The repository describes itself as: Inspect: A framework for large language model evaluations. The licence is MIT.

When your agent uses it

  • Asked to build/validate/upload sandbox tools binaries

Example prompts

  • “/release-sandbox-tools”

Requirements

  • Docker

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the trigger. The PR is approved and slow-tool-tests-release
  2. Get a checkout of the PR's head branch (a git worktree is ideal) and
  3. Run the wizard from that checkout's repo root
  4. Confirm CI goes green. The digest push triggers a fresh run; watch

What it can do on your machine

Read from SKILL.md and the folder at commit a1dbea8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release Sandbox Tools loads about 1.1k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 599 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from UKGovernmentBEIS/inspect_ai at commit a1dbea8, republished under its MIT licence (© UKGovernmentBEIS). 599 words, ~1,110 tokens.

Download SKILL.mdSave it as .claude/skills/release-sandbox-tools/SKILL.md (or your agent's skills folder).
name
release-sandbox-tools
description
Land a PR that requires new inspect-sandbox-tools injectable binaries to be built and published. Use when asked to land/merge a PR that changed code under src/inspect_sandbox_tools/ (typically its slow-tool-tests-release check fails on missing published binaries), or when asked to build/validate/upload sandbox tools binaries.

Landing a PR that ships new sandbox tools injectables

Unblocks landing a PR that changed code under src/inspect_sandbox_tools/ and bumped the injectable version: builds the four artifacts (amd64/arm64 × glibc/musl) from the PR branch, validates them across Linux distros, publishes them to S3, and commits the pinned digests back to the PR branch.

The whole procedure is scripted as an interactive wizard:

sh
scripts/release-sandbox-tools.sh [--dry-run] [--auto]

Agents: run it with --auto. In auto mode every confirmation resolves to a safe default, and anything that needs a human mid-run (starting Docker, aws sso login) aborts with instructions instead of waiting. Without --auto the prompts need a terminal, so a run from your shell exits immediately. Before starting, check aws sts get-caller-identity; if credentials are stale, ask the user to run aws sso login first — the upload uses their ambient AWS session. Run the wizard in the background and monitor it: build plus validation can exceed 20 minutes.

Typically run by a maintainer. The PR is often a contributor's — they can write the code and bump the version, but they don't have credentials to upload the binaries to S3, so a maintainer performs this final step.

When to run: once the PR is approved and the only failing CI check is slow-tool-tests-release — it fails at the "Fetch and verify published non-dev sandbox-tools binaries" step, either on the SHA256SUMS lockstep check or with a message naming the missing S3 object, because the bumped version's artifacts aren't published (and their digests committed) yet. Running earlier wastes builds if review rounds change the injectable source.

What you do

  1. Confirm the trigger. The PR is approved and slow-tool-tests-release is the failing check (per "When to run" above). If check-version-bump is the failing check instead, the fix is a committed version bump in src/inspect_ai/tool/_sandbox_tools_utils/sandbox_tools_version.txt (exactly one greater than origin/main's) — the wizard requires it and won't write it.
  2. Get a checkout of the PR's head branch (a git worktree is ideal) and make sure it's up to date — the binaries must be built from the exact code being merged. Offer to set this up.
  3. Run the wizard from that checkout's repo root: scripts/release-sandbox-tools.sh --auto (add --dry-run to build and validate without publishing anything). The wizard itself checks preconditions (branch, PR approval, version bump, Docker), builds, validates across distros, uploads to S3, commits and pushes the rewritten SHA256SUMS, and verifies the published bytes — don't redo those steps around it. It also resumes: re-runs skip the slow build/validation stages when a recorded fingerprint proves they already ran against the current source, so stopping and re-running (or dry-run then real run) is cheap.
  4. Confirm CI goes green. The digest push triggers a fresh run; watch slow-tool-tests-release pass. If the wizard ended without pushing the digests (its closing summary lists the commit as still to do), commit the rewritten SHA256SUMS to the PR branch and push it yourself — CI stays red until it lands. Do not merge the PR — that happens through the normal review process. PyPI bundling is also not part of this process: the release script pulls the glibc binaries from S3 automatically.
Show full SKILL.md (87 more words)Show less

If the wizard fails or can't be used

The underlying commands and mechanism are documented in src/inspect_sandbox_tools/design/RELEASING.md. Two rules survive any manual fallback:

  • Published versions are immutable. If an object for the version already exists on S3 with different bytes (the upload script's guard aborts on this), never force over it — bump the version and publish fresh artifacts.
  • Binaries must come from the exact PR code. Artifact filenames only encode the version, so files lying around from an earlier review round look identical; when in doubt, rebuild.

© UKGovernmentBEIS, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/release-sandbox-tools of UKGovernmentBEIS/inspect_ai.

Open the folder on GitHubat commit a1dbea8

Compare with similar skills

Release Sandbox Tools next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release Sandbox Tools compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release Sandbox Tools this skillUKGovernmentBEIS/inspect_ai3k—~1.1kAutomated safety check: PassMIT
SageMaker IAM Role Preflighthuggingface/skills11k1 repos~1.8kAutomated safety check: PassApache-2.0
SageMaker Serving Image Selectionhuggingface/skills11k1 repos~4.6kAutomated safety check: PassApache-2.0
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Python Environment Setup for SageMakerhuggingface/skills11k2 repos~1.7kAutomated safety check: PassApache-2.0
Agent Squad Python Guide2FastLabs/agent-squad7.8k—~4.7kAutomated safety check: PassApache-2.0

Similar skills

  • Official

    Finds or validates a usable SageMaker execution role before deploying or training, so scripts do not try to create IAM roles they lack permission to create.

    11k GitHub starsUsed in 1 repo~1.8k tokens
    DevOps & CloudAuto-check passed
  • Official

    Chooses the right serving container and current image URI for deploying a Hugging Face model to a SageMaker endpoint, preferring Hugging Face images over generic ones.

    11k GitHub starsUsed in 1 repo~4.6k tokens
    AI & LLM EngineeringAuto-check passed
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Official

    Sets up an isolated Python environment with a supported interpreter and current boto3 before any SageMaker deployment, training or AWS automation code runs.

    11k GitHub starsUsed in 2 repos~1.7k tokens
    AI & LLM EngineeringAuto-check passed
  • Agent Squad Python Guide

    2FastLabs/agent-squad

    Map of the agent-squad Python framework for async multi-agent orchestration: which agent, classifier, storage and tool provider to pick, and the pitfalls to avoid.

    7.8k GitHub stars~4.7k tokensUpdated 3 days ago
    AI & LLM EngineeringAuto-check passed
  • Paperclip Page

    paperclipai/paperclip

    Publish static HTML pages and asset folders to the Paperclip S3/CloudFront page host.

    100k GitHub stars~1k tokensUpdated today
    Frontend & DesignAuto-check passed

More from UKGovernmentBEIS/inspect_ai

  • CI Perf

    UKGovernmentBEIS/inspect_ai

    Measure PR CI speed, queue and execution time, slow tests, suite growth, and runner waste.

    3k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Land TS Mono

    UKGovernmentBEIS/inspect_ai

    Land a PR that requires a coordinated ts-mono submodule change.

    3k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Slow Tests

    UKGovernmentBEIS/inspect_ai

    Run the gated test classes that plain pytest skips (slow Docker/sandbox tests, live model-provider API tests, flaky tests, trio variants).

    3k GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Questions about Release Sandbox Tools

What does Release Sandbox Tools do?

Land a PR that requires new inspect-sandbox-tools injectable binaries to be built and published. Release Sandbox Tools is an agent skill from UKGovernmentBEIS/inspect_ai. Land a PR that requires new inspect-sandbox-tools injectable binaries to be built and published.

When should I use Release Sandbox Tools?

Release Sandbox Tools fits situations like: asked to build/validate/upload sandbox tools binaries.

How do I install Release Sandbox Tools in Claude Code?

Run `npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a claude-code`. Or copy the skill folder (.agents/skills/release-sandbox-tools in UKGovernmentBEIS/inspect_ai) into .claude/skills/release-sandbox-tools in your project. Claude Code loads it when a task matches its description.

How do I install Release Sandbox Tools in Codex?

Run `npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a codex`. Or copy the skill folder (.agents/skills/release-sandbox-tools in UKGovernmentBEIS/inspect_ai) into .agents/skills/release-sandbox-tools in your project. Codex loads it when a task matches its description.

Can I use Release Sandbox Tools in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-sandbox-tools, .gemini/skills/release-sandbox-tools, .github/skills/release-sandbox-tools and .opencode/skills/release-sandbox-tools in your project.

What does Release Sandbox Tools need to run?

Going by SKILL.md and its folder, Release Sandbox Tools needs the command-line tools its instructions call (aws). Our summary lists: Docker.

Does Release Sandbox Tools access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Release Sandbox Tools safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Release Sandbox Tools use?

Release Sandbox Tools is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release Sandbox Tools use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Release Sandbox Tools?

Skills that share tags, products or a category with Release Sandbox Tools: SageMaker IAM Role Preflight (huggingface/skills, 11k stars), SageMaker Serving Image Selection (huggingface/skills, 11k stars), Cloud Cost Optimization (wshobson/agents, 40k stars) and Python Environment Setup for SageMaker (huggingface/skills, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release Sandbox Tools?

UKGovernmentBEIS (a GitHub organization) maintains it in UKGovernmentBEIS/inspect_ai, which has 2,974 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.

Source: UKGovernmentBEIS/inspect_ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.