SageMaker IAM Role Preflight
huggingface/skills
Finds or validates a usable SageMaker execution role before deploying or training, so scripts do not try to create IAM roles they lack permission to create.
Land a PR that requires new inspect-sandbox-tools injectable binaries to be built and published.
$ npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install UKGovernmentBEIS/inspect_ai release-sandbox-tools --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/UKGovernmentBEIS/inspect_ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/release-sandbox-tools .claude/skills/release-sandbox-tools && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "release-sandbox-tools" agent skill from https://github.com/UKGovernmentBEIS/inspect_ai/tree/main/.agents/skills/release-sandbox-tools into .claude/skills/release-sandbox-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-sandbox-tools", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/UKGovernmentBEIS/inspect_ai/tree/main/.agents/skills/release-sandbox-toolsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install UKGovernmentBEIS/inspect_ai release-sandbox-tools --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/UKGovernmentBEIS/inspect_ai.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/release-sandbox-tools .agents/skills/release-sandbox-tools && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "release-sandbox-tools" agent skill from https://github.com/UKGovernmentBEIS/inspect_ai/tree/main/.agents/skills/release-sandbox-tools into .agents/skills/release-sandbox-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-sandbox-tools", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install UKGovernmentBEIS/inspect_ai release-sandbox-tools --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/UKGovernmentBEIS/inspect_ai.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/release-sandbox-tools .cursor/skills/release-sandbox-tools && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "release-sandbox-tools" agent skill from https://github.com/UKGovernmentBEIS/inspect_ai/tree/main/.agents/skills/release-sandbox-tools into .cursor/skills/release-sandbox-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-sandbox-tools", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/UKGovernmentBEIS/inspect_ai.git --path .agents/skills/release-sandbox-tools--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install UKGovernmentBEIS/inspect_ai release-sandbox-tools --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/UKGovernmentBEIS/inspect_ai.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/release-sandbox-tools .gemini/skills/release-sandbox-tools && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "release-sandbox-tools" agent skill from https://github.com/UKGovernmentBEIS/inspect_ai/tree/main/.agents/skills/release-sandbox-tools into .gemini/skills/release-sandbox-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-sandbox-tools", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install UKGovernmentBEIS/inspect_ai release-sandbox-toolsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/UKGovernmentBEIS/inspect_ai.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/release-sandbox-tools .github/skills/release-sandbox-tools && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "release-sandbox-tools" agent skill from https://github.com/UKGovernmentBEIS/inspect_ai/tree/main/.agents/skills/release-sandbox-tools into .github/skills/release-sandbox-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-sandbox-tools", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install UKGovernmentBEIS/inspect_ai release-sandbox-tools --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/UKGovernmentBEIS/inspect_ai.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/release-sandbox-tools .opencode/skills/release-sandbox-tools && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "release-sandbox-tools" agent skill from https://github.com/UKGovernmentBEIS/inspect_ai/tree/main/.agents/skills/release-sandbox-tools into .opencode/skills/release-sandbox-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-sandbox-tools", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
release-sandbox-toolsLand a PR that requires new inspect-sandbox-tools injectable binaries to be built and published.
Release Sandbox Tools is an agent skill from UKGovernmentBEIS/inspect_ai. Land a PR that requires new inspect-sandbox-tools injectable binaries to be built and published. Use when asked to land/merge a PR that changed code under src/inspectsandboxtools/ (typically its slow-tool-tests-release check fails on missing published binaries), or when asked to build/validate/upload sandbox tools binaries.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with Amazon Web Services. The repository describes itself as: Inspect: A framework for large language model evaluations. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit a1dbea8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
awsFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Release Sandbox Tools loads about 1.1k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 599 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from UKGovernmentBEIS/inspect_ai at commit a1dbea8, republished under its MIT licence (© UKGovernmentBEIS). 599 words, ~1,110 tokens.
.claude/skills/release-sandbox-tools/SKILL.md (or your agent's skills folder).Unblocks landing a PR that changed code under src/inspect_sandbox_tools/ and
bumped the injectable version: builds the four artifacts (amd64/arm64 ×
glibc/musl) from the PR branch, validates them across Linux distros, publishes
them to S3, and commits the pinned digests back to the PR branch.
The whole procedure is scripted as an interactive wizard:
scripts/release-sandbox-tools.sh [--dry-run] [--auto]Agents: run it with --auto. In auto mode every confirmation resolves to
a safe default, and anything that needs a human mid-run (starting Docker,
aws sso login) aborts with instructions instead of waiting. Without
--auto the prompts need a terminal, so a run from your shell exits
immediately. Before starting, check aws sts get-caller-identity; if
credentials are stale, ask the user to run aws sso login first — the upload
uses their ambient AWS session. Run the wizard in the background and monitor
it: build plus validation can exceed 20 minutes.
Typically run by a maintainer. The PR is often a contributor's — they can write the code and bump the version, but they don't have credentials to upload the binaries to S3, so a maintainer performs this final step.
When to run: once the PR is approved and the only failing CI check is
slow-tool-tests-release — it fails at the "Fetch and verify published
non-dev sandbox-tools binaries" step, either on the SHA256SUMS lockstep
check or with a message naming the missing S3 object, because the bumped
version's artifacts aren't published (and their digests committed) yet.
Running earlier wastes builds if review rounds change the injectable source.
slow-tool-tests-release
is the failing check (per "When to run" above). If check-version-bump is
the failing check instead, the fix is a committed version bump in
src/inspect_ai/tool/_sandbox_tools_utils/sandbox_tools_version.txt
(exactly one greater than origin/main's) — the wizard requires it and
won't write it.scripts/release-sandbox-tools.sh --auto (add --dry-run to build and
validate without publishing anything). The wizard itself checks
preconditions (branch, PR approval, version bump, Docker), builds,
validates across distros, uploads to S3, commits and pushes the rewritten
SHA256SUMS, and verifies the published bytes — don't redo those steps
around it. It also resumes: re-runs skip the slow build/validation stages
when a recorded fingerprint proves they already ran against the current
source, so stopping and re-running (or dry-run then real run) is cheap.slow-tool-tests-release pass. If the wizard ended without pushing the
digests (its closing summary lists the commit as still to do), commit the
rewritten SHA256SUMS to the PR branch and push it yourself — CI stays
red until it lands. Do not merge the PR — that happens through
the normal review process. PyPI bundling is also not part of this process:
the release script pulls the glibc binaries from S3 automatically.The underlying commands and mechanism are documented in
src/inspect_sandbox_tools/design/RELEASING.md. Two rules survive any manual
fallback:
© UKGovernmentBEIS, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/release-sandbox-tools of UKGovernmentBEIS/inspect_ai.
Open the folder on GitHubat commit a1dbea8
Release Sandbox Tools next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Release Sandbox Tools this skillUKGovernmentBEIS/inspect_ai | 3k | — | ~1.1k | Automated safety check: Pass | MIT | |
| SageMaker IAM Role Preflighthuggingface/skills | 11k | 1 repos | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| SageMaker Serving Image Selectionhuggingface/skills | 11k | 1 repos | ~4.6k | Automated safety check: Pass | Apache-2.0 | |
| Cloud Cost Optimizationwshobson/agents | 40k | 14 repos | ~1.7k | Automated safety check: Pass | MIT | |
| Python Environment Setup for SageMakerhuggingface/skills | 11k | 2 repos | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Agent Squad Python Guide2FastLabs/agent-squad | 7.8k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 |
huggingface/skills
Finds or validates a usable SageMaker execution role before deploying or training, so scripts do not try to create IAM roles they lack permission to create.
huggingface/skills
Chooses the right serving container and current image URI for deploying a Hugging Face model to a SageMaker endpoint, preferring Hugging Face images over generic ones.
wshobson/agents
Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.
huggingface/skills
Sets up an isolated Python environment with a supported interpreter and current boto3 before any SageMaker deployment, training or AWS automation code runs.
2FastLabs/agent-squad
Map of the agent-squad Python framework for async multi-agent orchestration: which agent, classifier, storage and tool provider to pick, and the pitfalls to avoid.
paperclipai/paperclip
Publish static HTML pages and asset folders to the Paperclip S3/CloudFront page host.
UKGovernmentBEIS/inspect_ai
Measure PR CI speed, queue and execution time, slow tests, suite growth, and runner waste.
UKGovernmentBEIS/inspect_ai
Land a PR that requires a coordinated ts-mono submodule change.
UKGovernmentBEIS/inspect_ai
Run the gated test classes that plain pytest skips (slow Docker/sandbox tests, live model-provider API tests, flaky tests, trio variants).
Works with
Land a PR that requires new inspect-sandbox-tools injectable binaries to be built and published. Release Sandbox Tools is an agent skill from UKGovernmentBEIS/inspect_ai. Land a PR that requires new inspect-sandbox-tools injectable binaries to be built and published.
Release Sandbox Tools fits situations like: asked to build/validate/upload sandbox tools binaries.
Run `npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a claude-code`. Or copy the skill folder (.agents/skills/release-sandbox-tools in UKGovernmentBEIS/inspect_ai) into .claude/skills/release-sandbox-tools in your project. Claude Code loads it when a task matches its description.
Run `npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a codex`. Or copy the skill folder (.agents/skills/release-sandbox-tools in UKGovernmentBEIS/inspect_ai) into .agents/skills/release-sandbox-tools in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add UKGovernmentBEIS/inspect_ai --skill release-sandbox-tools -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-sandbox-tools, .gemini/skills/release-sandbox-tools, .github/skills/release-sandbox-tools and .opencode/skills/release-sandbox-tools in your project.
Going by SKILL.md and its folder, Release Sandbox Tools needs the command-line tools its instructions call (aws). Our summary lists: Docker.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Release Sandbox Tools is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Release Sandbox Tools: SageMaker IAM Role Preflight (huggingface/skills, 11k stars), SageMaker Serving Image Selection (huggingface/skills, 11k stars), Cloud Cost Optimization (wshobson/agents, 40k stars) and Python Environment Setup for SageMaker (huggingface/skills, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
UKGovernmentBEIS (a GitHub organization) maintains it in UKGovernmentBEIS/inspect_ai, which has 2,974 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.
Source: UKGovernmentBEIS/inspect_ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.