Install the "sandbox-execution-guide" agent skill from https://github.com/wentorai/research-plugins/tree/main/skills/tools/code-exec/sandbox-execution-guide into .claude/skills/sandbox-execution-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-execution-guide", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add wentorai/research-plugins --skill sandbox-execution-guide -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "sandbox-execution-guide" agent skill from https://github.com/wentorai/research-plugins/tree/main/skills/tools/code-exec/sandbox-execution-guide into .agents/skills/sandbox-execution-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-execution-guide", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add wentorai/research-plugins --skill sandbox-execution-guide -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "sandbox-execution-guide" agent skill from https://github.com/wentorai/research-plugins/tree/main/skills/tools/code-exec/sandbox-execution-guide into .cursor/skills/sandbox-execution-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-execution-guide", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add wentorai/research-plugins --skill sandbox-execution-guide -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "sandbox-execution-guide" agent skill from https://github.com/wentorai/research-plugins/tree/main/skills/tools/code-exec/sandbox-execution-guide into .gemini/skills/sandbox-execution-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-execution-guide", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add wentorai/research-plugins --skill sandbox-execution-guide -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "sandbox-execution-guide" agent skill from https://github.com/wentorai/research-plugins/tree/main/skills/tools/code-exec/sandbox-execution-guide into .github/skills/sandbox-execution-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-execution-guide", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add wentorai/research-plugins --skill sandbox-execution-guide -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "sandbox-execution-guide" agent skill from https://github.com/wentorai/research-plugins/tree/main/skills/tools/code-exec/sandbox-execution-guide into .opencode/skills/sandbox-execution-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sandbox-execution-guide", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
sandbox-execution-guide
GitHub stars
298
Used in
1 other repo
Token cost
~1.5k tokens
SKILL.md length
190 words
Files
1
Skills in repo
405
Repo updated
First seen
Licence
MIT
At a glance
Secure sandboxed code execution environments for reproducible research computing
Works in 6 steps: Network isolation: Use --network=none in… → Filesystem restrictions: Mount data as… → Resource caps: Always set CPU, memory,… → …
Tasks that involve Reproducible research
SKILL.md covers Why Sandboxed Execution?, Docker-Based Sandboxes, Python Sandbox with Resource… and Nix-Based Reproducible…, plus 2 more sections
Calls docker and nix; reaches github.com
What it does
Sandbox Execution Guide is an agent skill from wentorai/research-plugins. Secure sandboxed code execution environments for reproducible research computing
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Research & Science, covering Reproducible research. The repository describes itself as: 350+ academic research skills, MCP configs, and plugins for Research-Claw and AI agents. The licence is MIT.
When your agent uses it
Tasks that involve Reproducible research
Example prompts
“/sandbox-execution-guide”
Requirements
Python 3
Docker
Workflow steps
6 steps, taken from the first numbered list in SKILL.md.
1Network isolation: Use --network=none in Docker to prevent data exfiltration
2Filesystem restrictions: Mount data as read-only, limit writable paths
3Resource caps: Always set CPU, memory, and time limits
4User isolation: Run as non-root user inside the container
5Syscall filtering: Use seccomp profiles to restrict system calls
6Output sanitization: Validate and sanitize all output before processing
What it can do on your machine
Read from SKILL.md and the folder at commit bf44b3c. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
docker
nix
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
github.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Sandbox Execution Guide loads about 1.5k tokens when it runs. Until then it costs about 26 tokens; SKILL.md has 190 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~26
When it runs· the whole SKILL.md, loaded when a task matches
~1.5k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/sandbox-execution-guide/SKILL.md (or your agent's skills folder).
name
sandbox-execution-guide
description
Secure sandboxed code execution environments for reproducible research computing
Sandbox Execution Guide
A skill for setting up and using sandboxed code execution environments for research computing. Covers containerized execution, security considerations, resource management, and integration with research workflows.
Why Sandboxed Execution?
Research code often requires:
Isolation from the host system for security
Reproducible environments across machines
Resource limits to prevent runaway computations
Multi-language support (Python, R, Julia, MATLAB)
Docker-Based Sandboxes
Creating a Research Container
dockerfile
# Dockerfile for a reproducible research environment
FROM python:3.11-slim
# System dependencies
RUN apt-get update && apt-get install -y --no-install-recommends \
build-essential \
gfortran \
libopenblas-dev \
&& rm -rf /var/lib/apt/lists/*
# Create non-root user for security
RUN useradd -m -s /bin/bash researcher
USER researcher
WORKDIR /home/researcher
# Pin all dependencies
COPY requirements.txt .
RUN pip install --user --no-cache-dir -r requirements.txt
# Copy project files
COPY --chown=researcher:researcher . /home/researcher/project
WORKDIR /home/researcher/project
# Resource limits set at runtime, not build time
CMD ["python", "main.py"]
Running with Resource Limits
bash
# Run with CPU, memory, and time constraints
docker run \
--cpus="2.0" \
--memory="4g" \
--memory-swap="4g" \
--pids-limit=100 \
--network=none \
--read-only \
--tmpfs /tmp:size=512m \
--timeout 3600 \
research-sandbox:latest python analysis.py
# Mount data as read-only, output directory as writable
docker run \
-v /data/raw:/data:ro \
-v /data/results:/output:rw \
--cpus="4.0" \
--memory="16g" \
research-sandbox:latest python pipeline.py
Python Sandbox with Resource Limits
Process-Level Isolation
python
import subprocess
import resource
import signal
import tempfile
import os
def run_sandboxed(code: str, timeout: int = 60,
max_memory_mb: int = 512) -> dict:
"""
Execute Python code in a sandboxed subprocess with resource limits.
Args:
code: Python code string to execute
timeout: Maximum execution time in seconds
max_memory_mb: Maximum memory in megabytes
"""
with tempfile.NamedTemporaryFile(mode='w', suffix='.py', delete=False) as f:
f.write(code)
script_path = f.name
try:
result = subprocess.run(
['python', '-u', script_path],
capture_output=True,
text=True,
timeout=timeout,
env={
'PATH': '/usr/bin:/usr/local/bin',
'HOME': '/tmp',
'PYTHONDONTWRITEBYTECODE': '1'
}
)
return {
'stdout': result.stdout,
'stderr': result.stderr,
'returncode': result.returncode,
'timed_out': False
}
except subprocess.TimeoutExpired:
return {
'stdout': '',
'stderr': f'Execution timed out after {timeout}s',
'returncode': -1,
'timed_out': True
}
finally:
os.unlink(script_path)
# Example usage
result = run_sandboxed("""
import numpy as np
data = np.random.randn(1000)
print(f"Mean: {data.mean():.4f}")
print(f"Std: {data.std():.4f}")
""", timeout=30, max_memory_mb=256)
print(result['stdout'])
Nix-Based Reproducible Environments
For maximum reproducibility, use Nix to pin every dependency including system libraries:
nix
# shell.nix for a research project
{ pkgs ? import (fetchTarball {
url = "https://github.com/NixOS/nixpkgs/archive/nixos-23.11.tar.gz";
}) {} }:
pkgs.mkShell {
buildInputs = with pkgs; [
python311
python311Packages.numpy
python311Packages.scipy
python311Packages.pandas
python311Packages.matplotlib
python311Packages.scikit-learn
R
rPackages.ggplot2
rPackages.dplyr
];
shellHook = ''
echo "Research sandbox activated"
echo "Python: $(python --version)"
echo "R: $(R --version | head -1)"
'';
}
bash
# Enter the reproducible environment
nix-shell shell.nix
# Or use flakes for even better reproducibility
nix develop
Security Best Practices
When running untrusted or third-party code:
Network isolation: Use --network=none in Docker to prevent data exfiltration
Filesystem restrictions: Mount data as read-only, limit writable paths
Resource caps: Always set CPU, memory, and time limits
User isolation: Run as non-root user inside the container
Syscall filtering: Use seccomp profiles to restrict system calls
Output sanitization: Validate and sanitize all output before processing
Integration with CI/CD
Automate research pipeline execution with GitHub Actions:
This ensures every commit triggers a fresh, sandboxed execution of the full pipeline, catching environment-dependent bugs and ensuring reproducibility.
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in wentorai/research-plugins, which our catalogue first saw on October 7, 2026.
Sandbox Execution Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Sandbox Execution Guide compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Sandbox Execution Guide this skillwentorai/research-plugins
Guides an agent through reproducing papers built on the CHARLS health and retirement survey, from variable mapping to cognition, depression and isolation scores.
Secure sandboxed code execution environments for reproducible research computing. Sandbox Execution Guide is an agent skill from wentorai/research-plugins.
How do I install Sandbox Execution Guide in Claude Code?
Run `npx skills add wentorai/research-plugins --skill sandbox-execution-guide -a claude-code`. Or copy the skill folder (skills/tools/code-exec/sandbox-execution-guide in wentorai/research-plugins) into .claude/skills/sandbox-execution-guide in your project. Claude Code loads it when a task matches its description.
How do I install Sandbox Execution Guide in Codex?
Run `npx skills add wentorai/research-plugins --skill sandbox-execution-guide -a codex`. Or copy the skill folder (skills/tools/code-exec/sandbox-execution-guide in wentorai/research-plugins) into .agents/skills/sandbox-execution-guide in your project. Codex loads it when a task matches its description.
Can I use Sandbox Execution Guide in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wentorai/research-plugins --skill sandbox-execution-guide -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sandbox-execution-guide, .gemini/skills/sandbox-execution-guide, .github/skills/sandbox-execution-guide and .opencode/skills/sandbox-execution-guide in your project.
What does Sandbox Execution Guide need to run?
Going by SKILL.md and its folder, Sandbox Execution Guide needs the command-line tools its instructions call (docker and nix). Our summary lists: Python 3; Docker.
Does Sandbox Execution Guide access the network?
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Is Sandbox Execution Guide safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Sandbox Execution Guide use?
Sandbox Execution Guide is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Sandbox Execution Guide use?
About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Sandbox Execution Guide?
Skills that share tags, products or a category with Sandbox Execution Guide: Bio Workflow Management Nf Core Pipelines (GPTomics/bioSkills, 1.2k stars), Peer Review (K-Dense-AI/claude-scientific-writer, 2.4k stars), Compute Environment Setup (aipoch/open-science, 5.5k stars) and CHARLS Paper Reproduction Guide (xjtulyc/MedgeClaw, 617 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Sandbox Execution Guide?
wentorai (a GitHub user) maintains it in wentorai/research-plugins, which has 298 GitHub stars. The repository holds 405 skills in this directory. The repository was last updated on June 19, 2026.
Source: wentorai/research-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.