Official agent skill

Vercel Sandbox

by vercel in vercel/vercel-plugin

Vercel Sandbox guidance — ephemeral Firecracker microVMs for running untrusted code safely.

OfficialCustom licenceAuto-check: notesMarketing & SEO

Install Vercel Sandbox

skills CLI
$ npx skills add vercel/vercel-plugin --skill vercel-sandbox -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vercel/vercel-plugin vercel-sandbox --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vercel/vercel-plugin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vercel-sandbox .claude/skills/vercel-sandbox && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vercel-sandbox
GitHub stars
301
Token cost
~6.2k tokens
SKILL.md length
2,129 words
Files
3
Skills in repo
38
Repo updated
First seen
Licence
Custom licence

At a glance

Vercel Sandbox guidance — ephemeral Firecracker microVMs for running untrusted code safely.

  • Executing user-generated
  • SKILL.md covers Install, Minimal example, Authentication and Creating a sandbox, plus 14 more sections
  • Calls vercel, apt-get and bash; reaches ai-gateway.vercel.sh; needs VERCEL_OIDC_TOKEN and VERCEL_TOKEN
  • AI-generated code in isolation

What it does

Vercel Sandbox is an agent skill from vercel/vercel-plugin, published by the product's own GitHub organization. Vercel Sandbox guidance — ephemeral Firecracker microVMs for running untrusted code safely. Supports AI agents, code generation, and experimentation. Use when executing user-generated or AI-generated code in isolation.

Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `overlay.yaml`).

It sits in Marketing & SEO, covering A/B testing. It works with Vercel and Python. The repository describes itself as: Comprehensive Vercel ecosystem plugin — relational knowledge graph, skills for every major product, specialized agents, and Vercel conventions. Turns any AI agent into a Vercel…

When your agent uses it

  • Executing user-generated
  • AI-generated code in isolation

Example prompts

  • “/vercel-sandbox”

Requirements

  • Python 3
  • Node.js
  • A credential in VERCEL_OIDC_TOKEN
  • A credential in VERCEL_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 82fa491. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • vercel
    • apt-get
    • bash
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • ai-gateway.vercel.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • VERCEL_OIDC_TOKEN
    • VERCEL_TOKEN
    • API_SECRET
    • AI_GATEWAY_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vercel Sandbox loads about 6.2k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 2,129 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:132
    v pull` to get a `VERCEL_OIDC_TOKEN` in `.env.local` (valid ~12h; re-pull when it expires).
  • NoteRuns commands with sudoSKILL.md:158
    as a **non-root** user (`ubuntu`, in the sudo group) by default; pass `sudo: true` for root.
  • NoteRuns commands with sudoSKILL.md:167
    // Root for one command (sudo is object-form only)
  • NoteRuns commands with sudoSKILL.md:296
    sandbox/ubuntu` | Minimal Ubuntu 26.04 + sudo |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 2,129 words (~6,227 tokens).

“Vercel Sandbox runs untrusted or AI-generated code inside an ephemeral Firecracker microVM. You get a real Linux VM with a filesystem and network — created on demand over an API, and stopped (or snapshotted) when you're done. Reach for it…”

— opening of SKILL.md by vercel, Custom licence
name
vercel-sandbox
summary
Run untrusted/AI-generated code in ephemeral Firecracker microVMs via @vercel/sandbox. Core loop: `const s = await Sandbox.create(); try { const r = await…
metadata.priority
4
metadata.docs
https://vercel.com/docs/sandbox
metadata.sitemap
https://vercel.com/sitemap.xml
metadata.importPatterns
@vercel/sandbox
metadata.bashPatterns
\bnpm\s+(install|i|add)\s+[^\n]*@vercel/sandbox\b, \bpnpm\s+(install|i|add)\s+[^\n]*@vercel/sandbox\b, \bbun\s+(install|i|add)\s+[^\n]*@vercel/sandbox\b…
retrieval.aliases
code sandbox, microvm, isolated execution, safe code runner
retrieval.intents
run untrusted code, execute code safely, create sandbox, isolate code execution
retrieval.entities
Vercel Sandbox, Firecracker, microVM, isolated execution

Read the full SKILL.md on GitHub

Files

SKILL.md and 2 other files in skills/vercel-sandbox of vercel/vercel-plugin.

  • SKILL.md
  • .vercel.approvers
  • overlay.yaml

Open the folder on GitHubat commit 82fa491

Compare with similar skills

Vercel Sandbox next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vercel Sandbox compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vercel Sandbox this skillvercel/vercel-plugin301—~6.2kAutomated safety check: NotesCustom licence
Ab Test Analysiskillvxk/pm-skills-zh168—~480Automated safety check: PassMIT
A/B Test Analysisphuryn/pm-skills27k—~893Automated safety check: PassMIT
Ab Testingcoreyhaines31/marketingskills54k3 repos~2.8kAutomated safety check: PassMIT
AnalyticsNexus-JPF/note-companion8707 repos~2.2kAutomated safety check: PassMIT
Ab Test Setupfreekmurze/dotfiles1k15 repos~1.8kAutomated safety check: PassNone

Similar skills

  • Ab Test Analysis

    killvxk/pm-skills-zh

    分析 A/B 测试结果,涵盖统计显著性检验、样本量验证、置信区间计算及上线/延长/停止的决策建议。适用于评估实验结果、判断测试是否达到显著性、解读分流测试数据,或决定是否上线某个实验组。

    168 GitHub stars~480 tokensUpdated 6 mo ago
    Marketing & SEOAuto-check passed
  • A/B Test Analysis

    phuryn/pm-skills

    Validates an experiment's setup, works out lift, p-value and confidence interval from A/B test data, and recommends whether to ship, extend or stop.

    27k GitHub stars~893 tokensUpdated 23 days ago
    Data & AnalyticsAuto-check passed
  • Ab Testing

    coreyhaines31/marketingskills

    When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program.

    54k GitHub starsUsed in 3 repos~2.8k tokens
    Marketing & SEOAuto-check passed
  • Analytics

    Nexus-JPF/note-companion

    When the user wants to set up, improve, or audit analytics tracking and measurement.

    870 GitHub starsUsed in 7 repos~2.2k tokens
    Marketing & SEOAuto-check passed
  • Ab Test Setup

    freekmurze/dotfiles

    When the user wants to plan, design, or implement an A/B test or experiment.

    1k GitHub starsUsed in 15 repos~1.8k tokens
    Marketing & SEOAuto-check passed
  • Ad Test Designer

    aaron-he-zhu/aaron-marketing-skills

    A skill your agent uses when the user asks to "design an A/B test", "set up a creative/landing test", "run an incrementality test", or "is this result statistically and practically material?"…

    2.9k GitHub starsUsed in 2 repos~2.8k tokens
    Marketing & SEOAuto-check passed

More from vercel/vercel-plugin

All 38 skills in this repo
  • Deployments Cicd

    vercel/vercel-plugin

    Official

    Vercel deployment and CI/CD expert guidance. An agent skill from vercel/vercel-plugin.

    301 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed
  • Plugin Audit

    vercel/vercel-plugin

    Official

    Audit vercel-plugin performance on real-world projects. An agent skill from vercel/vercel-plugin.

    301 GitHub stars~739 tokensUpdated yesterday
    Auto-check passed
  • Vercel CLI

    vercel/vercel-plugin

    Official

    Vercel CLI expert guidance. An agent skill from vercel/vercel-plugin.

    301 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • AI Gateway

    vercel/vercel-plugin

    Official

    Vercel AI Gateway guidance for setup, model discovery, authentication, routing, fallbacks, virtual models, evaluation models, BYOK, budgets, spend reporting, observability, compatible APIs, and…

    301 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check: notes
  • Vercel Services

    vercel/vercel-plugin

    Official

    Configure and troubleshoot Vercel Services for multiple frontends and backends in one project.

    301 GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Official

    Access and test Vercel deployments protected by Vercel Authentication, SSO, or Deployment Protection.

    301 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check: notes

Works with

Categories

Questions about Vercel Sandbox

What does Vercel Sandbox do?

Vercel Sandbox guidance — ephemeral Firecracker microVMs for running untrusted code safely. Vercel Sandbox is an agent skill from vercel/vercel-plugin, published by the product's own GitHub organization. Vercel Sandbox guidance — ephemeral Firecracker microVMs for running untrusted code safely.

When should I use Vercel Sandbox?

Vercel Sandbox fits situations like: executing user-generated; AI-generated code in isolation.

How do I install Vercel Sandbox in Claude Code?

Run `npx skills add vercel/vercel-plugin --skill vercel-sandbox -a claude-code`. Or copy the skill folder (skills/vercel-sandbox in vercel/vercel-plugin) into .claude/skills/vercel-sandbox in your project. Claude Code loads it when a task matches its description.

How do I install Vercel Sandbox in Codex?

Run `npx skills add vercel/vercel-plugin --skill vercel-sandbox -a codex`. Or copy the skill folder (skills/vercel-sandbox in vercel/vercel-plugin) into .agents/skills/vercel-sandbox in your project. Codex loads it when a task matches its description.

Can I use Vercel Sandbox in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vercel/vercel-plugin --skill vercel-sandbox -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vercel-sandbox, .gemini/skills/vercel-sandbox, .github/skills/vercel-sandbox and .opencode/skills/vercel-sandbox in your project.

What does Vercel Sandbox need to run?

Going by SKILL.md and its folder, Vercel Sandbox needs the command-line tools its instructions call (vercel, apt-get, bash and pnpm) and credentials named VERCEL_OIDC_TOKEN, VERCEL_TOKEN, API_SECRET and AI_GATEWAY_API_KEY. Our summary lists: Python 3; Node.js; A credential in VERCEL_OIDC_TOKEN; A credential in VERCEL_TOKEN.

Does Vercel Sandbox access the network?

SKILL.md names 1 domain. In commands or code: ai-gateway.vercel.sh; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Vercel Sandbox safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Vercel Sandbox use?

Vercel Sandbox has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Vercel Sandbox use?

About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vercel Sandbox?

Skills that share tags, products or a category with Vercel Sandbox: Ab Test Analysis (killvxk/pm-skills-zh, 168 stars), A/B Test Analysis (phuryn/pm-skills, 27k stars), Ab Testing (coreyhaines31/marketingskills, 54k stars) and Analytics (Nexus-JPF/note-companion, 870 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vercel Sandbox?

vercel (a GitHub organization, an official publisher) maintains it in vercel/vercel-plugin, which has 301 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 7, 2026.

Source: vercel/vercel-plugin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.