Agent skill

Sandbox Execution Guide

by wentorai in wentorai/research-plugins

Secure sandboxed code execution environments for reproducible research computing

MITAuto-check passedResearch & Science

Install Sandbox Execution Guide

skills CLI
$ npx skills add wentorai/research-plugins --skill sandbox-execution-guide -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install wentorai/research-plugins sandbox-execution-guide --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/wentorai/research-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tools/code-exec/sandbox-execution-guide .claude/skills/sandbox-execution-guide && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sandbox-execution-guide
GitHub stars
298
Used in
1 other repo
Token cost
~1.5k tokens
SKILL.md length
190 words
Files
1
Skills in repo
405
Repo updated
First seen
Licence
MIT

At a glance

Secure sandboxed code execution environments for reproducible research computing

  • Works in 6 steps: Network isolation: Use --network=none in… → Filesystem restrictions: Mount data as… → Resource caps: Always set CPU, memory,… → …
  • Tasks that involve Reproducible research
  • SKILL.md covers Why Sandboxed Execution?, Docker-Based Sandboxes, Python Sandbox with Resource… and Nix-Based Reproducible…, plus 2 more sections
  • Calls docker and nix; reaches github.com

What it does

Sandbox Execution Guide is an agent skill from wentorai/research-plugins. Secure sandboxed code execution environments for reproducible research computing

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Research & Science, covering Reproducible research. The repository describes itself as: 350+ academic research skills, MCP configs, and plugins for Research-Claw and AI agents. The licence is MIT.

When your agent uses it

  • Tasks that involve Reproducible research

Example prompts

  • “/sandbox-execution-guide”

Requirements

  • Python 3
  • Docker

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Network isolation: Use --network=none in Docker to prevent data exfiltration
  2. Filesystem restrictions: Mount data as read-only, limit writable paths
  3. Resource caps: Always set CPU, memory, and time limits
  4. User isolation: Run as non-root user inside the container
  5. Syscall filtering: Use seccomp profiles to restrict system calls
  6. Output sanitization: Validate and sanitize all output before processing

What it can do on your machine

Read from SKILL.md and the folder at commit bf44b3c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • nix

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sandbox Execution Guide loads about 1.5k tokens when it runs. Until then it costs about 26 tokens; SKILL.md has 190 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~26
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from wentorai/research-plugins at commit bf44b3c, republished under its MIT licence (© wentorai). 190 words, ~1,461 tokens.

Download SKILL.mdSave it as .claude/skills/sandbox-execution-guide/SKILL.md (or your agent's skills folder).
name
sandbox-execution-guide
description
Secure sandboxed code execution environments for reproducible research computing

Sandbox Execution Guide

A skill for setting up and using sandboxed code execution environments for research computing. Covers containerized execution, security considerations, resource management, and integration with research workflows.

Why Sandboxed Execution?

Research code often requires:

  • Isolation from the host system for security
  • Reproducible environments across machines
  • Resource limits to prevent runaway computations
  • Multi-language support (Python, R, Julia, MATLAB)

Docker-Based Sandboxes

Creating a Research Container
dockerfile
# Dockerfile for a reproducible research environment
FROM python:3.11-slim

# System dependencies
RUN apt-get update && apt-get install -y --no-install-recommends \
    build-essential \
    gfortran \
    libopenblas-dev \
    && rm -rf /var/lib/apt/lists/*

# Create non-root user for security
RUN useradd -m -s /bin/bash researcher
USER researcher
WORKDIR /home/researcher

# Pin all dependencies
COPY requirements.txt .
RUN pip install --user --no-cache-dir -r requirements.txt

# Copy project files
COPY --chown=researcher:researcher . /home/researcher/project
WORKDIR /home/researcher/project

# Resource limits set at runtime, not build time
CMD ["python", "main.py"]
Running with Resource Limits
bash
# Run with CPU, memory, and time constraints
docker run \
  --cpus="2.0" \
  --memory="4g" \
  --memory-swap="4g" \
  --pids-limit=100 \
  --network=none \
  --read-only \
  --tmpfs /tmp:size=512m \
  --timeout 3600 \
  research-sandbox:latest python analysis.py

# Mount data as read-only, output directory as writable
docker run \
  -v /data/raw:/data:ro \
  -v /data/results:/output:rw \
  --cpus="4.0" \
  --memory="16g" \
  research-sandbox:latest python pipeline.py

Python Sandbox with Resource Limits

Process-Level Isolation
python
import subprocess
import resource
import signal
import tempfile
import os

def run_sandboxed(code: str, timeout: int = 60,
                   max_memory_mb: int = 512) -> dict:
    """
    Execute Python code in a sandboxed subprocess with resource limits.

    Args:
        code: Python code string to execute
        timeout: Maximum execution time in seconds
        max_memory_mb: Maximum memory in megabytes
    """
    with tempfile.NamedTemporaryFile(mode='w', suffix='.py', delete=False) as f:
        f.write(code)
        script_path = f.name

    try:
        result = subprocess.run(
            ['python', '-u', script_path],
            capture_output=True,
            text=True,
            timeout=timeout,
            env={
                'PATH': '/usr/bin:/usr/local/bin',
                'HOME': '/tmp',
                'PYTHONDONTWRITEBYTECODE': '1'
            }
        )
        return {
            'stdout': result.stdout,
            'stderr': result.stderr,
            'returncode': result.returncode,
            'timed_out': False
        }
    except subprocess.TimeoutExpired:
        return {
            'stdout': '',
            'stderr': f'Execution timed out after {timeout}s',
            'returncode': -1,
            'timed_out': True
        }
    finally:
        os.unlink(script_path)

# Example usage
result = run_sandboxed("""
import numpy as np
data = np.random.randn(1000)
print(f"Mean: {data.mean():.4f}")
print(f"Std:  {data.std():.4f}")
""", timeout=30, max_memory_mb=256)
print(result['stdout'])

Nix-Based Reproducible Environments

For maximum reproducibility, use Nix to pin every dependency including system libraries:

nix
# shell.nix for a research project
{ pkgs ? import (fetchTarball {
    url = "https://github.com/NixOS/nixpkgs/archive/nixos-23.11.tar.gz";
  }) {} }:

pkgs.mkShell {
  buildInputs = with pkgs; [
    python311
    python311Packages.numpy
    python311Packages.scipy
    python311Packages.pandas
    python311Packages.matplotlib
    python311Packages.scikit-learn
    R
    rPackages.ggplot2
    rPackages.dplyr
  ];

  shellHook = ''
    echo "Research sandbox activated"
    echo "Python: $(python --version)"
    echo "R: $(R --version | head -1)"
  '';
}
bash
# Enter the reproducible environment
nix-shell shell.nix

# Or use flakes for even better reproducibility
nix develop

Security Best Practices

When running untrusted or third-party code:

  1. Network isolation: Use --network=none in Docker to prevent data exfiltration
  2. Filesystem restrictions: Mount data as read-only, limit writable paths
  3. Resource caps: Always set CPU, memory, and time limits
  4. User isolation: Run as non-root user inside the container
  5. Syscall filtering: Use seccomp profiles to restrict system calls
  6. Output sanitization: Validate and sanitize all output before processing

Integration with CI/CD

Automate research pipeline execution with GitHub Actions:

yaml
name: Research Pipeline
on:
  push:
    paths: ['src/**', 'data/**']

jobs:
  run-analysis:
    runs-on: ubuntu-latest
    container:
      image: research-sandbox:latest
      options: --cpus 4 --memory 8g
    steps:
      - uses: actions/checkout@v4
      - run: python src/01_preprocess.py
      - run: python src/02_analyze.py
      - run: python src/03_visualize.py
      - uses: actions/upload-artifact@v4
        with:
          name: results
          path: output/

This ensures every commit triggers a fresh, sandboxed execution of the full pipeline, catching environment-dependent bugs and ensuring reproducibility.

© wentorai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/tools/code-exec/sandbox-execution-guide of wentorai/research-plugins.

Open the folder on GitHubat commit bf44b3c

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in wentorai/research-plugins, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Sandbox Execution Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sandbox Execution Guide compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sandbox Execution Guide this skillwentorai/research-plugins2981 repos~1.5kAutomated safety check: PassMIT
Bio Workflow Management Nf Core PipelinesGPTomics/bioSkills1.2k1 repos~4.1kAutomated safety check: PassMIT
Peer ReviewK-Dense-AI/claude-scientific-writer2.4k2 repos~3.1kAutomated safety check: NotesMIT
Compute Environment Setupaipoch/open-science5.5k1 repos~2.6kAutomated safety check: PassApache-2.0
CHARLS Paper Reproduction Guidexjtulyc/MedgeClaw6171 repos~1.8kAutomated safety check: PassNone
Figure Styleaipoch/open-science5.5k—~5.1kAutomated safety check: PassApache-2.0

Similar skills

  • Runs and configures curated nf-core community Nextflow pipelines (rnaseq, sarek, atacseq, methylseq, ampliseq, taxprofiler, fetchngs) reproducibly, pinning the pipeline revision with -r and…

    1.2k GitHub starsUsed in 1 repo~4.1k tokens
    Research & ScienceAuto-check passed
  • Peer Review

    K-Dense-AI/claude-scientific-writer

    Prepare evidence-bounded, constructive peer-review drafts and structured manuscript assessments.

    2.4k GitHub starsUsed in 2 repos~3.1k tokens
    Research & ScienceAuto-check: notes
  • Compute Environment Setup

    aipoch/open-science

    Prepares setup instructions and a named activation file for a user-managed software environment on an Open-Science SSH or Slurm compute host.

    5.5k GitHub starsUsed in 1 repo~2.6k tokens
    Research & ScienceAuto-check passed
  • Guides an agent through reproducing papers built on the CHARLS health and retirement survey, from variable mapping to cognition, depression and isolation scores.

    617 GitHub starsUsed in 1 repo~1.8k tokens
    Research & ScienceAuto-check passed
  • Figure Style

    aipoch/open-science

    Publication-grade correctness and legibility rules for final-deliverable scientific figures, not exploratory plots.

    5.5k GitHub stars~5.1k tokensUpdated today
    Research & ScienceAuto-check passed
  • Add Bactopia Tool

    bactopia/bactopia

    Scaffold a complete Bactopia Tool across all three tiers -- module, subworkflow, and workflow entry point under workflows/bactopia-tools/.

    522 GitHub stars~4.1k tokensUpdated 2 mo ago
    Research & ScienceAuto-check passed

More from wentorai/research-plugins

All 405 skills in this repo
  • Abstract Writing Guide

    wentorai/research-plugins

    Craft structured research abstracts that maximize clarity and journal acceptance

    298 GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • Academic Citation Manager

    wentorai/research-plugins

    Manage academic citations across BibTeX, APA, MLA, and Chicago formats

    298 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Academic Paper Summarizer

    wentorai/research-plugins

    Summarize academic papers with structured extraction of key elements

    298 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Academic Study Methods

    wentorai/research-plugins

    Evidence-based study techniques for academic learning and retention

    298 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Academic Tone Guide

    wentorai/research-plugins

    Adjust writing tone and register for academic audiences and venues

    298 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Academic Translation Guide

    wentorai/research-plugins

    Academic translation, post-editing, and Chinglish correction guide

    298 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed

Questions about Sandbox Execution Guide

What does Sandbox Execution Guide do?

Secure sandboxed code execution environments for reproducible research computing. Sandbox Execution Guide is an agent skill from wentorai/research-plugins.

When should I use Sandbox Execution Guide?

Sandbox Execution Guide fits situations like: tasks that involve Reproducible research.

How do I install Sandbox Execution Guide in Claude Code?

Run `npx skills add wentorai/research-plugins --skill sandbox-execution-guide -a claude-code`. Or copy the skill folder (skills/tools/code-exec/sandbox-execution-guide in wentorai/research-plugins) into .claude/skills/sandbox-execution-guide in your project. Claude Code loads it when a task matches its description.

How do I install Sandbox Execution Guide in Codex?

Run `npx skills add wentorai/research-plugins --skill sandbox-execution-guide -a codex`. Or copy the skill folder (skills/tools/code-exec/sandbox-execution-guide in wentorai/research-plugins) into .agents/skills/sandbox-execution-guide in your project. Codex loads it when a task matches its description.

Can I use Sandbox Execution Guide in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wentorai/research-plugins --skill sandbox-execution-guide -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sandbox-execution-guide, .gemini/skills/sandbox-execution-guide, .github/skills/sandbox-execution-guide and .opencode/skills/sandbox-execution-guide in your project.

What does Sandbox Execution Guide need to run?

Going by SKILL.md and its folder, Sandbox Execution Guide needs the command-line tools its instructions call (docker and nix). Our summary lists: Python 3; Docker.

Does Sandbox Execution Guide access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Sandbox Execution Guide safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sandbox Execution Guide use?

Sandbox Execution Guide is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sandbox Execution Guide use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sandbox Execution Guide?

Skills that share tags, products or a category with Sandbox Execution Guide: Bio Workflow Management Nf Core Pipelines (GPTomics/bioSkills, 1.2k stars), Peer Review (K-Dense-AI/claude-scientific-writer, 2.4k stars), Compute Environment Setup (aipoch/open-science, 5.5k stars) and CHARLS Paper Reproduction Guide (xjtulyc/MedgeClaw, 617 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sandbox Execution Guide?

wentorai (a GitHub user) maintains it in wentorai/research-plugins, which has 298 GitHub stars. The repository holds 405 skills in this directory. The repository was last updated on June 19, 2026.

Source: wentorai/research-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.