Agent skill

K8e Sandbox

by xiaods in xiaods/k8e

Run a goal end to end inside an isolated K8E sandbox pod (gVisor / Kata / Firecracker) instead of on the host: exec bash / Python / Node / TypeScript, install packages, move files in and out, reuse…

Apache-2.0Auto-check passedBackend & APIs

Install K8e Sandbox

skills CLI
$ npx skills add xiaods/k8e --skill k8e-sandbox -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install xiaods/k8e k8e-sandbox --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/xiaods/k8e.git skills-src && mkdir -p .claude/skills && cp -r skills-src/pkg/sandboxcli/skills/k8e-sandbox .claude/skills/k8e-sandbox && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
k8e-sandbox
GitHub stars
500
Token cost
~6k tokens
SKILL.md length
2,289 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run a goal end to end inside an isolated K8E sandbox pod (gVisor / Kata / Firecracker) instead of on the host: exec bash / Python / Node / TypeScript, install packages, move files in and out, reuse…

  • Works in 4 steps: Pre-flight → Plan → Execute (examples) → …
  • The user invokes /k8e-sandbox <goal
  • SKILL.md covers What this skill can do…, dsh (DeepSeek Harness)…, Binary naming (read this first) and Hard rules, plus 10 more sections
  • Calls curl

What it does

K8e Sandbox is an agent skill from xiaods/k8e. Run a goal end to end inside an isolated K8E sandbox pod (gVisor / Kata / Firecracker) instead of on the host: exec bash / Python / Node / TypeScript, install packages, move files in and out, reuse one session across calls, snapshot and restore the workspace, run background jobs, and publish an in-sandbox service through the k8e API Gateway. Use when the user invokes /k8e-sandbox <goal, $k8e-sandbox <goal or /skill:k8e-sandbox, or when work needs untrusted, disposable or reproducible Linux execution — running or…

Its SKILL.md is about 6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Microservices, Background jobs and Container orchestration. It works with Python, Bash, TypeScript and Linux. The repository describes itself as: k8e.sh - OpenSource Agentic AI Sandbox Matrix. The licence is Apache-2.0.

When your agent uses it

  • The user invokes /k8e-sandbox <goal
  • $k8e-sandbox <goal
  • /skill:k8e-sandbox
  • Work needs untrusted

Example prompts

  • “/k8e-sandbox”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Pre-flight
  2. Plan
  3. Execute (examples)
  4. Report

What it can do on your machine

Read from SKILL.md and the folder at commit d690609. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

K8e Sandbox loads about 6k tokens when it runs. Until then it costs about 195 tokens; SKILL.md has 2,289 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~195
When it runs · the whole SKILL.md, loaded when a task matches
~6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from xiaods/k8e at commit d690609, republished under its Apache-2.0 licence (© xiaods). 2,289 words, ~6,042 tokens.

Download SKILL.mdSave it as .claude/skills/k8e-sandbox/SKILL.md (or your agent's skills folder).
name
k8e-sandbox
description
Run a goal end to end inside an isolated K8E sandbox pod (gVisor / Kata / Firecracker) instead of on the host: exec bash / Python / Node / TypeScript, install packages, move files in and out, reuse one session across calls, snapshot and restore the workspace, run background jobs, and publish an in-sandbox service through the k8e API Gateway. Use when the user invokes /k8e-sandbox <goal>, $k8e-sandbox <goal> or /skill:k8e-sandbox, or when work needs untrusted, disposable or reproducible Linux execution — running or testing code, installing dependencies, processing data or files, reproducing a bug in a clean box, or serving a dev app off the host. Egress is allowlisted, destructive actions are human-gated, and the connection is mTLS with multi-cluster profiles.
argument-hint
<goal>
user-invocable
true

/k8e-sandbox

Treat this as the k8e-sandbox skill command.

Invocation (same skill, different harness prefixes):

  • Claude Code: /k8e-sandbox <goal>
  • Codex: $k8e-sandbox <goal> (or pick from /skills)
  • Pi: /skill:k8e-sandbox <goal> (or /k8e-sandbox when skill commands are enabled)
  • dsh (DeepSeek Harness): the model loads this skill via the skill tool (catalog name k8e-sandbox), or the user names it directly in chat — see dsh execution path below

Goal from invocation arguments:

$ARGUMENTS

If $ARGUMENTS is empty and no goal is otherwise provided, ask the user for a sandbox goal and stop (do not invent work).

What this skill can do (capability map)

Match the goal to a capability, then use the matching command. Exact flags live in the command reference.

Goal shapeCapabilityCommand
Run a command, script or test suiteIsolated exec in the pod — bash (default), python, node, tsrun, run --lang python, run --raw
Install dependenciespip/npm writes land in /workspace, not the image (KIP-13)run 'pip install …'
Move files in / outChunked streaming — constant memory, binary-safe, any sizepush <sid> <local> [remote], pull <sid> <remote> [local]
Keep state across callsAuto session, --tenant for cross-process reuse, sub-agents share one pod + workspacerun …, run --tenant, subagent <parent-sid>
Seed a workspaceDeclarative manifest or a git clone at session creation (KIP-9)create --manifest, create --git-repo
Save / restore a workspaceContent-addressed snapshots (deduped; incremental via --base)snapshot save/list/restore/delete
Serve a web app or APIPublish an in-pod port through the k8e API Gateway — no port-forward, no inbound pod exposure (KIP-24)run --background → expose <port> → exposed / unexpose
Reach the internetSession egress allowlist, updatable live while the pod runsallow-hosts --add/--remove/--clear, or --allowed-hosts at create
Watch or debug a runTranscript replay, NDJSON event stream, process list, background polllog, events, ps, poll
Gate an irreversible stepHuman-in-the-loop approval before the action runsconfirm <sid> <action> → approve <aid>
Measure cold-start latencyWarm-pool benchmarkbenchmark
Drive it from another programMachine-readable command surface; native MCP servercatalog, mcp-serve
Target another clustermTLS client certs + named profiles; API keys with TTL (KIP-14 / KIP-17)--profile, connect, k8e sandbox-apikey create
Diagnose a broken setupSelf-check with auto-fixdoctor, doctor --json, doctor --fix

dsh (DeepSeek Harness) execution path

In dsh, decide your execution mode by checking the current session's tool list first — everything else in this skill branches on it.

A. Plugin mounted — k8e_sandbox_session_status IS in your tool list

The dsh-k8e-sandbox plugin replaced the harness's execution seams:

  • bash (subprocess seam) → runs inside the sandbox pod
  • read / write / edit / dir listings (fs seam) → sandbox /workspace
  • k8e_sandbox_* tools → session lifecycle, expose, egress allowlist

Rules:

  1. Do NOT run k8e-sandbox-cli here: it is not present inside the sandbox, and invoking it from the sandboxed bash would recursively dial the gateway from inside the pod. Use the tools + sandboxed seams instead.
  2. Prefer plain bash for commands — it lands in the sandbox. Use k8e_sandbox_exec when you want structured stdout/stderr/exitCode, and k8e_sandbox_run_background + k8e_sandbox_poll for long/streaming tasks.
  3. First action in a session: k8e_sandbox_session_status — it lazily creates the session shared by fs/subprocess/exec, and reports available, sessionId, tenantId.

Tool reference (exact argument shapes — do not guess):

ToolArgumentsReturns
k8e_sandbox_session_status{}available, sessionId, tenantId, error
k8e_sandbox_session_destroy{} — releases the pod (idempotent)destroyed
k8e_sandbox_exec{code: string (required), lang?: "bash"|"python"|"node"|"ts", timeout?: number} — omit timeout to leave a background run uncappedstdout, stderr, exitCode, durationMs, truncated
k8e_sandbox_run_background{code: string (required), lang?: …}runId, sessionId, status
k8e_sandbox_poll{runId: string (required)}runId, status, stdout, stderr, exitCode, durationMs
k8e_sandbox_expose{port: number (required), host?: string}url, port
k8e_sandbox_unexpose{port: number (required)}ok, port
k8e_sandbox_allow_hosts{hosts: string[] (required)} — full replacement list; [] clears (falls back to cluster defaults)hosts[]

Service exposure in dsh: after starting a long-running service with k8e_sandbox_run_background, call k8e_sandbox_expose {port: 8080} and hand the returned URL to the user — same gateway-proxied URL the CLI's expose prints. Teardown with k8e_sandbox_unexpose {port: 8080}. These runs are not time-capped, so the service stays reachable until the session is destroyed.

Session, connection, and mTLS are owned by the plugin: it resolves the gateway from config → env → ~/.k8e/sandbox/profiles.yaml (KIP-17) and reuses one persistent gRPC connection. If a tool errors with gateway unreachable / mTLS / deadline, tell the user to run k8e-sandbox-cli connect (local) or k8e-sandbox-cli connect --endpoint <host>:50051 --apikey <key> (remote) outside dsh, then restart the dsh session.

B. Plugin NOT mounted — k8e_sandbox_* tools are NOT in your tool list

The plugin bundle is not installed for this dsh profile. dsh's bash still runs on the HOST here (no seam replacement), so the CLI-first flow below works normally: execute everything via k8e-sandbox-cli run ... exactly as the CLI examples describe. Do not pretend the k8e_sandbox_* tools exist — calling a nonexistent tool errors.

To enable the full plugin experience, ask the user to install the bundle once (from a k8e checkout), then restart dsh:

dsh plugin --profile <name> add <k8e>/plugins/deepseek-harness/packages/dsh-k8e-sandbox-bundle
dsh --profile <name>          # restart the session
dsh error quick reference
SymptomCauseFix
Tool call fails "not found" / unknown tool k8e_sandbox_*plugin bundle not mounteduse section B (CLI-first); ask user to install the bundle
Tool errors "gateway unreachable" / mTLS / deadlinegateway down or missing credentialsk8e-sandbox-cli connect (or with --endpoint/--apikey) outside dsh, restart dsh
bash/read error with connection refusedsession pod not readyk8e_sandbox_session_status; wait and retry
k8e_sandbox_expose returns 503 "no pod IP"server build predates the podIP backfillupgrade the k8e server, or inspect the session with k8e-sandbox-cli get <sid> and retry

The CLI-first flow below (k8e-sandbox-cli run ...) is for harnesses where the sandbox is not mounted (Claude Code / Codex / Pi / dsh without the plugin).

Binary naming (read this first)

The downloaded file name carries a platform suffix — pick the one for the user's machine:

PlatformDownload name
Linux amd64k8e-sandbox-cli-linux-amd64
Linux arm64k8e-sandbox-cli-linux-arm64
macOS amd64k8e-sandbox-cli-darwin-amd64
macOS arm64k8e-sandbox-cli-darwin-arm64
Windows amd64k8e-sandbox-cli-windows-amd64.exe

It is the same binary this skill invokes as k8e-sandbox-cli — just under the platform-suffixed name. To make the plain name work without renaming, create a symlink (do not rename the file):

bash
# Example for Linux amd64 — substitute the platform name for other OS/arch
curl -sLO https://github.com/xiaods/k8e/releases/latest/download/k8e-sandbox-cli-linux-amd64
chmod +x k8e-sandbox-cli-linux-amd64
ln -s k8e-sandbox-cli-linux-amd64 k8e-sandbox-cli          # symlink, original file stays
# optionally move both into a PATH dir, e.g. ~/.local/bin/
./k8e-sandbox-cli ... connect                             # connect installs this skill + ensures PATH

(Windows: use mklink k8e-sandbox-cli.exe k8e-sandbox-cli-windows-amd64.exe in cmd.)

From then on, this skill and all examples use the plain name k8e-sandbox-cli — same binary.

If you only see a platform-suffixed name in the user's environment (no symlink yet), use that file directly: ./k8e-sandbox-cli-linux-amd64 status etc. All spellings are interchangeable; never tell the user they are missing a second binary.

Hard rules

  1. All code and shell execution goes through k8e-sandbox-cli — never run python3, node, pip, npm, curl, compilers, or tests on the host for this goal.
  2. Prefer auto session mode: k8e-sandbox-cli run "..." (creates/reuses session).
  3. Parse JSON with jq unless --raw is used.
  4. If the gateway is unreachable, tell the user to run k8e-sandbox-cli connect (local) or k8e-sandbox-cli connect --endpoint <host>:50051 --apikey <key> (remote). Multi-cluster: --profile <name> / ~/.k8e/sandbox/profiles.yaml (KIP-17).

Auth & multi-profile (KIP-14 / KIP-17 / #538)

Do not confuse these files:

PathWhoWhat
/etc/k8e/config.yamlk8e server/agentDaemon flags only
~/.k8e/sandbox/profiles.yamlk8e-sandbox-cliNamed gateways / cert dirs
~/.k8e/sandbox/config.jsonk8e-sandbox-cliLast connect stamp

mTLS bootstrap: first remote connect/login uses an API key once; CLI stores ca.crt + client.crt + client.key (private key never leaves the machine). Client certs last 90 days and auto-renew when <30 days remain. API keys default to 30-day TTL (k8e sandbox-apikey create name, override with --ttl 90d|never).

First authentication verifies the gateway using system trust, a cached CA, or an administrator-provided --ca-file /path/to/sandbox-ca.crt on connect/login. Obtain that CA through a trusted channel. Private-CA gateways require the CA on first use. --insecure-bootstrap explicitly bypasses server verification only when no CA is selected; this exposes the API key to server impersonation and must not be the default recovery step. login always authenticates the supplied API key, even with valid cached credentials. Concurrent CLI processes serialize credential initialization and renewal.

Profiles (~/.k8e/sandbox/profiles.yaml, override with K8E_SANDBOX_CONFIG):

yaml
# ~/.k8e/sandbox/profiles.yaml  — NOT /etc/k8e/config.yaml
version: 1
current_profile: default
profiles:
  default:
    endpoint: 10.0.0.1:50051
  prod:
    endpoint: sandbox.prod.example:50051
    cert_dir: ~/.k8e/sandbox-prod
    device_name: laptop-prod
bash
k8e-sandbox-cli --profile prod connect --apikey <64-hex key>
k8e-sandbox-cli --profile prod run 'echo hi'
# or: export K8E_SANDBOX_PROFILE=prod

Priority: flags → env → profile → last-connect fallback (~/.k8e/sandbox/config.json) → defaults. Flag/env pairs: --endpoint/K8E_SANDBOX_ENDPOINT, --apikey/K8E_SANDBOX_APIKEY, --profile/K8E_SANDBOX_PROFILE. The cert dir has no flag: K8E_SANDBOX_CERT_DIR → profile cert_dir → ~/.k8e/sandbox. Other env: K8E_SANDBOX_SESSION_ID, K8E_SANDBOX_TENANT, K8E_SANDBOX_DEVICE_NAME, K8E_SANDBOX_CONFIG (profile file path).

Procedure (always)

1. Pre-flight
bash
command -v k8e-sandbox-cli >/dev/null || { echo "k8e-sandbox-cli not on PATH; run connect again"; exit 1; }
k8e-sandbox-cli status

Require "available": true. If not available, stop and instruct the user to connect.

2. Plan

Decompose $ARGUMENTS into sandbox-safe steps (install deps → write files → run code → read outputs).

3. Execute (examples)
bash
# Shell / bash (default)
k8e-sandbox-cli run 'echo hello'

# Python
k8e-sandbox-cli run "print(1+1)" --lang python

# Multi-line / files
k8e-sandbox-cli run 'pip install pandas' --lang bash
# write via stdin:
# cat analysis.py | k8e-sandbox-cli write <session_id> /workspace/analysis.py
# k8e-sandbox-cli run 'python3 /workspace/analysis.py' --session-id <session_id>
# push/pull local files (chunked streaming — constant memory, binary-safe,
# works for files of any size; prefer over write/read for real files):
# k8e-sandbox-cli push <session_id> ./analysis.py /workspace/analysis.py
# k8e-sandbox-cli pull <session_id> /workspace/results.csv ./results.csv

# Background exec (returns run_id immediately).
# A background run has NO lifetime cap by default. `--timeout N` caps it and
# the daemon SIGKILLs the run (whole process group) when N expires — only pass
# it for work you want bounded.
k8e-sandbox-cli run 'sleep 30; echo done' --background
k8e-sandbox-cli poll <run-id>            # wait + stream output

# Tenant reuse (share one session across CLI calls)
k8e-sandbox-cli run 'echo hi' --tenant my-project

# Sub-agent: child session sharing parent pod + workspace (no new pod)
k8e-sandbox-cli subagent <parent-sid>

# Expose a long-running service through the k8e API Gateway (KIP-24).
# No --timeout here: a cap would kill the server while you are still testing it.
k8e-sandbox-cli run "python3 -m http.server 8080 --bind 127.0.0.1" --background
k8e-sandbox-cli expose 8080     # -> {"url":"http://<gateway>/k8e/expose/<sid>/8080/",...}

Useful commands: run, write, read, list, push, pull, create, get, sessions, destroy, status, log, events, ps, poll, subagent, confirm, approve, snapshot, benchmark, catalog, expose, unexpose, exposed, allow-hosts, doctor, login, mcp-serve.

4. Report

Show stdout/stderr and exit codes from the CLI JSON. Do not claim host-side execution.

Show full SKILL.md (926 more words)Show less

One-time setup (if not connected)

bash
# Local K8E node
k8e-sandbox-cli connect

# Remote — API key from server (default TTL 30d)
k8e sandbox-apikey create my-agent
# → {"name":"my-agent","key":"<64-hex>","e2b_key":"e2b_<64-hex>",
#    "ttl_days":30,"created_at":"…","expires_at":"…"}
# Pass `key` (bare hex) to `connect --apikey`. Hand `e2b_key` to the official e2b
# SDKs: they require the e2b_ prefix and the server strips it.
# k8e sandbox-apikey create my-agent --ttl never   # optional non-expiring

k8e-sandbox-cli connect --endpoint <server-ip>:50051 --apikey <64-hex key> --ca-file /path/to/sandbox-ca.crt
# Multi-cluster: k8e-sandbox-cli --profile prod connect --apikey <64-hex key>

connect authenticates (mTLS), verifies the gateway, puts k8e-sandbox-cli on PATH when needed (symlink to ~/.local/bin/k8e-sandbox-cli), and installs this skill into Claude / Codex / Pi / dsh discovery paths (--agent dsh or --agent all; dsh reads it from ~/.dsh/skills or ~/.agents/skills).

Command reference

CommandPurpose
k8e-sandbox-cli --profile <name> …Use named profile from ~/.k8e/sandbox/profiles.yaml
k8e-sandbox-cli connectLocal/remote auth + install this skill into agent harnesses (--agent auto/claude/codex/pi/dsh/all, --reset-certs, --skip-verify, --skip-path)
k8e-sandbox-cli connect --skill-onlyRe-install this skill only (no gateway dial)
k8e-sandbox-cli loginRemote mTLS only (no skill install); optional --device-name
k8e-sandbox-cli doctorSelf-check gateway / certs / skill install / PATH (--json, --fix)
k8e-sandbox-cli mcp-serveServe the sandbox MCP endpoint for MCP-capable agents (--listen, --gateway, TLS + API-key flags)
k8e-sandbox-cli statusGateway + session probe
k8e-sandbox-cli run <code>Exec in sandbox (--lang, --timeout seconds — default 30, --raw, --session-id, --tenant, --background, --manifest, --git-repo/--git-ref/--git-path, --allowed-hosts)
k8e-sandbox-cli createManual session (--runtime, --env, --secret, --allowed-hosts, --manifest, --git-repo)
k8e-sandbox-cli get <sid>Session introspection (phase, runtime, env keys)
k8e-sandbox-cli sessionsList sessions
k8e-sandbox-cli write/read/listWorkspace files (write --mode, read --raw); list --since <unix-ts> returns only files modified after that timestamp
k8e-sandbox-cli push <sid> <local> [remote]Stream a local file INTO the sandbox (chunked 4MiB windows — constant memory, binary-safe, any size; --chunk-mb to tune)
k8e-sandbox-cli pull <sid> <remote> [local]Stream a sandbox file OUT to a local path (same chunked transfer)
k8e-sandbox-cli log <sid>Replay exec transcript (--offset, --limit, --follow)
k8e-sandbox-cli events <sid>Read daemon NDJSON event stream (--limit)
k8e-sandbox-cli ps <sid>List processes in the sandbox pod (pid, comm, state)
k8e-sandbox-cli poll <run-id>Wait for a run --background job and return its result
k8e-sandbox-cli subagent <parent-sid>Spawn child session (shares parent's pod + workspace — no new pod)
k8e-sandbox-cli confirm <sid> <action>Gate destructive action on human approval (--timeout, --no-wait)
k8e-sandbox-cli approve <aid>Approve a pending confirm (--reject, --reason)
k8e-sandbox-cli snapshot save <sid> <name>Save workspace snapshot (content-addressed, dedup'd)
k8e-sandbox-cli snapshot listList saved snapshots
k8e-sandbox-cli snapshot restore <name>New session from a snapshot (--base <snap> for incremental)
k8e-sandbox-cli snapshot delete <name>Delete a snapshot
k8e-sandbox-cli expose <port>Expose an in-sandbox service through the k8e API Gateway; returns the public URL (--host, --session-id)
k8e-sandbox-cli unexpose <port>Tear down an exposed port (idempotent; --session-id)
k8e-sandbox-cli exposedList live exposures for the session (--session-id)
k8e-sandbox-cli allow-hosts <hosts...>Freely set the session egress allowlist, live (--hosts replace, --add, --remove, --clear; --session-id)
k8e-sandbox-cli benchmarkWarm-pool latency metrics (--pool-size, --iterations)
k8e-sandbox-cli catalogEmit machine-readable command surface (SDK generation)
k8e-sandbox-cli destroy <sid>Tear down session

Default run output is JSON: stdout, stderr, exit_code, session_id, status, duration_ms, truncated, language; run --background returns run_id, status, session_id. Use --raw to stream plain text instead.

Service exposure (KIP-24)

When the agent builds a long-running service inside the sandbox (web app, API server), expose it through the k8e API Gateway so the gateway/other hosts can reach it — no port-forward, no inbound pod exposure:

k8e-sandbox-cli run "python3 -m http.server 8080 --bind 127.0.0.1" --background
k8e-sandbox-cli expose 8080            # -> {"url":"http://<gateway>/k8e/expose/<sid>/8080/",...}
curl http://<gateway>/k8e/expose/<sid>/8080/   # reachable via the gateway (VPC/LB)
k8e-sandbox-cli exposed                # list live exposures
k8e-sandbox-cli unexpose 8080          # tear down

The exposed URL routes: Cilium Gateway API (:80/:443) -> embedded e2b HTTP server -> reverse proxy to http://<podIP>:<port>. The gateway base is configured server-side (--sandbox-expose-base-url, default http://<advertise-hostname>). The CNP is re-applied automatically so only the gateway/e2b-server can reach the exposed port.

Keep the service alive. Start it with run --background and no --timeout: the run then lives until the process exits or the session is destroyed. Passing --timeout N makes sandboxd SIGKILL the run's whole process group after N seconds — the URL keeps working until then and returns 502 afterwards with nothing listening on the port.

A 502 on an exposed URL means nothing is listening on that port inside the sandbox (the service died, never started, or crashed). The 502 body names the unreachable <podIP>:<port>. Diagnose with ps <session_id> (is the process still there?) and poll <run_id> (timed_out = the lifetime cap expired).

Egress allowlist is freely configurable — when the sandbox needs outbound access to domains (package registries, tunnel endpoints), update it live:

k8e-sandbox-cli allow-hosts --add pypi.org,registry.npmjs.org
k8e-sandbox-cli allow-hosts --remove pypi.org
k8e-sandbox-cli allow-hosts --clear          # fall back to cluster defaults

Session modes

ModeHowState
Auto (default)run without session id~/.k8e/sandbox/default/state.json
Tenant--tenant my-project~/.k8e/sandbox/{tenant}/state.json
Manualcreate → run --session-id → destroynone

Egress

Default allowed hosts (cluster SandboxMatrix.spec.defaultAllowedHosts): pypi.org, files.pythonhosted.org, registry.npmjs.org, github.com, raw.githubusercontent.com.

  • At session creation: create --allowed-hosts a.com,b.com (or run --allowed-hosts for auto-created sessions).
  • Live, any time (KIP-24): allow-hosts --add a.com,b.com / --remove a.com / --clear (fall back to cluster defaults). Applies immediately via CNP re-apply; in dsh use k8e_sandbox_allow_hosts {hosts: [...]}.

Security red lines

  • --env is for non-sensitive config only (stored on CRD). Use --secret ENV=secret:key for secrets.
  • Never pass host secrets into sandbox flags in chat logs if avoidable.
  • Never sudo via sandbox CLI.
  • Destructive sandbox actions require confirm → approve (human in the loop); don't skip it.

Error quick reference

ExitMeaningAction
2TLS / cert / unreachableServer reinstalled or CA rotated? Re-run connect --reset-certs --apikey <key> --ca-file /path/to/trusted-new-ca.crt (validates new credentials before replacing cached files); otherwise check profile cert_dir
1Command/session errorRead JSON error; recreate session if gone; re-create API key if TTL expired
8ResourceExhaustedWait or free warm pool capacity

Your role when this skill is active

Do:

  • dsh + plugin mounted (section A): run everything through the sandboxed bash/read/write seams and the k8e_sandbox_* tools; start long-running services with k8e_sandbox_run_background, hand the user a reachable URL via k8e_sandbox_expose.
  • Everywhere else (CLI-first flow): execute $ARGUMENTS entirely via k8e-sandbox-cli; prefer run; use --lang python for Python; use --raw for long streams; show real CLI output. When the goal builds a long-running service (web app, API), start it with run --background and hand the user a reachable URL via expose <port>.

Don't: run the goal on the host; skip pre-flight; invent successful output without actually running a tool/CLI; call k8e_sandbox_* tools that are not in your current tool list (plugin not mounted — use section B instead).

© xiaods, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in pkg/sandboxcli/skills/k8e-sandbox of xiaods/k8e.

Open the folder on GitHubat commit d690609

Compare with similar skills

K8e Sandbox next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

K8e Sandbox compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
K8e Sandbox this skillxiaods/k8e500—~6kAutomated safety check: PassApache-2.0
Temporal Developerlatitude-dev/latitude-llm4.7k—~1.5kAutomated safety check: PassMIT
Temporal Developertemporalio/skill-temporal-developer230—~2.5kAutomated safety check: PassMIT
Intrinsic Core Service Authoringintrinsic-ai/intrinsic-core557—~2.2kAutomated safety check: PassApache-2.0
Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.0
Grix Pre Push Checksaskie/grix153—~831Automated safety check: PassCustom licence

Similar skills

  • Temporal Developer

    latitude-dev/latitude-llm

    This skill should be used when the user asks to "create a Temporal workflow", "write a Temporal activity", "debug stuck workflow", "fix non-determinism error", "Temporal Python", "Temporal…

    4.7k GitHub stars~1.5k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Temporal Developer

    temporalio/skill-temporal-developer

    Official

    Develop, debug, and manage Temporal applications across Python, TypeScript, Go, Java, .NET, Ruby, and Rust.

    230 GitHub stars~2.5k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Intrinsic Core Service Authoring

    intrinsic-ai/intrinsic-core

    Intrinsic Core microservice authoring, ServiceManifest definitions (realspec vs simspec), RuntimeContext port bindings (gRPC port 1 vs HTTP port 7), SIGTERM lifecycle handling, and .binpb sideloading.

    557 GitHub stars~2.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Select and run the smallest sufficient validation set for Grix changes before push, review handoff, or completion.

    153 GitHub stars~831 tokensUpdated yesterday
    MobileAuto-check passed
  • Asdf

    jjmartres/opencode

    A skill your agent uses whenever the user wants to install, configure, or use asdf (asdf-vm), the universal version manager.

    133 GitHub stars~2.1k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check: notes

Categories

Questions about K8e Sandbox

What does K8e Sandbox do?

Run a goal end to end inside an isolated K8E sandbox pod (gVisor / Kata / Firecracker) instead of on the host: exec bash / Python / Node / TypeScript, install packages, move files in and out, reuse…. K8e Sandbox is an agent skill from xiaods/k8e. Run a goal end to end inside an isolated K8E sandbox pod (gVisor / Kata / Firecracker) instead of on the host: exec bash / Python / Node / TypeScript, install packages, move files in and out, reuse one session across calls, snapshot and restore the workspace, run background jobs, and publish an in-sandbox service through the k8e API Gateway.

When should I use K8e Sandbox?

K8e Sandbox fits situations like: the user invokes /k8e-sandbox <goal; $k8e-sandbox <goal; /skill:k8e-sandbox; work needs untrusted.

How do I install K8e Sandbox in Claude Code?

Run `npx skills add xiaods/k8e --skill k8e-sandbox -a claude-code`. Or copy the skill folder (pkg/sandboxcli/skills/k8e-sandbox in xiaods/k8e) into .claude/skills/k8e-sandbox in your project. Claude Code loads it when a task matches its description.

How do I install K8e Sandbox in Codex?

Run `npx skills add xiaods/k8e --skill k8e-sandbox -a codex`. Or copy the skill folder (pkg/sandboxcli/skills/k8e-sandbox in xiaods/k8e) into .agents/skills/k8e-sandbox in your project. Codex loads it when a task matches its description.

Can I use K8e Sandbox in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xiaods/k8e --skill k8e-sandbox -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/k8e-sandbox, .gemini/skills/k8e-sandbox, .github/skills/k8e-sandbox and .opencode/skills/k8e-sandbox in your project.

What does K8e Sandbox need to run?

Going by SKILL.md and its folder, K8e Sandbox needs the command-line tools its instructions call (curl). Our summary lists: Python 3.

Does K8e Sandbox access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is K8e Sandbox safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does K8e Sandbox use?

K8e Sandbox is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does K8e Sandbox use?

About 6k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to K8e Sandbox?

Skills that share tags, products or a category with K8e Sandbox: Temporal Developer (latitude-dev/latitude-llm, 4.7k stars), Temporal Developer (temporalio/skill-temporal-developer, 230 stars), Intrinsic Core Service Authoring (intrinsic-ai/intrinsic-core, 557 stars) and Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains K8e Sandbox?

xiaods (a GitHub user) maintains it in xiaods/k8e, which has 500 GitHub stars. The repository was last updated on September 28, 2026.

Source: xiaods/k8e on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.