LangBot Deployment Guide
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
Step-by-step guide for adding a new sandbox provider to Agent Kernel.
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yaalalabs/agent-kernel ak-dev-new-sandbox-provider --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ak-dev-new-sandbox-provider .claude/skills/ak-dev-new-sandbox-provider && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ak-dev-new-sandbox-provider" agent skill from https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-sandbox-provider into .claude/skills/ak-dev-new-sandbox-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ak-dev-new-sandbox-provider", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-sandbox-providerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yaalalabs/agent-kernel ak-dev-new-sandbox-provider --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/ak-dev-new-sandbox-provider .agents/skills/ak-dev-new-sandbox-provider && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ak-dev-new-sandbox-provider" agent skill from https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-sandbox-provider into .agents/skills/ak-dev-new-sandbox-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ak-dev-new-sandbox-provider", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yaalalabs/agent-kernel ak-dev-new-sandbox-provider --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/ak-dev-new-sandbox-provider .cursor/skills/ak-dev-new-sandbox-provider && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ak-dev-new-sandbox-provider" agent skill from https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-sandbox-provider into .cursor/skills/ak-dev-new-sandbox-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ak-dev-new-sandbox-provider", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yaalalabs/agent-kernel.git --path .agents/skills/ak-dev-new-sandbox-provider--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yaalalabs/agent-kernel ak-dev-new-sandbox-provider --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/ak-dev-new-sandbox-provider .gemini/skills/ak-dev-new-sandbox-provider && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ak-dev-new-sandbox-provider" agent skill from https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-sandbox-provider into .gemini/skills/ak-dev-new-sandbox-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ak-dev-new-sandbox-provider", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yaalalabs/agent-kernel ak-dev-new-sandbox-providerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/ak-dev-new-sandbox-provider .github/skills/ak-dev-new-sandbox-provider && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ak-dev-new-sandbox-provider" agent skill from https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-sandbox-provider into .github/skills/ak-dev-new-sandbox-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ak-dev-new-sandbox-provider", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yaalalabs/agent-kernel ak-dev-new-sandbox-provider --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/ak-dev-new-sandbox-provider .opencode/skills/ak-dev-new-sandbox-provider && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ak-dev-new-sandbox-provider" agent skill from https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-sandbox-provider into .opencode/skills/ak-dev-new-sandbox-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ak-dev-new-sandbox-provider", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ak-dev-new-sandbox-providerStep-by-step guide for adding a new sandbox provider to Agent Kernel.
Ak Dev New Sandbox Provider is an agent skill from yaalalabs/agent-kernel. Step-by-step guide for adding a new sandbox provider to Agent Kernel. Use this skill when you need to integrate a new code-execution backend for the sandbox capability (beyond localsubprocess, docker, kubernetes, e2b, daytona, and ec2ssm). Covers implementing the Sandbox / SandboxProvider ABCs, declaring capabilities honestly, factory registration, configuration, the contract test suite, and examples.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Container orchestration, Integration testing and Containers. It works with Docker and Kubernetes. The repository describes itself as: The Operating System for Scalable Enterprise AI Agents - Run, orchestrate, and deploy Compliant Enterprise AI Agents at scale across frameworks, without lock-in, rewrites or… The licence is Apache-2.0.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 97fa8d9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ak Dev New Sandbox Provider loads about 3.7k tokens when it runs. Until then it costs about 109 tokens; SKILL.md has 1,114 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yaalalabs/agent-kernel at commit 97fa8d9, republished under its Apache-2.0 licence (© yaalalabs). 1,114 words, ~3,711 tokens.
.claude/skills/ak-dev-new-sandbox-provider/SKILL.md (or your agent's skills folder).This guide walks through adding a new sandbox provider to Agent Kernel. Use the shipped
local_subprocess (ak-py/src/agentkernel/sandbox/providers/local_subprocess.py) and
docker (ak-py/src/agentkernel/sandbox/providers/docker.py) implementations as reference.
| Provider | type value | Isolation | Extra |
|---|---|---|---|
| Local subprocess | local_subprocess | none (no isolation; dev/test) | — (stdlib) |
| Docker | docker | container | agentkernel[sandbox-docker] |
| E2B | e2b | micro_vm | agentkernel[e2b] |
| Daytona | daytona | container | agentkernel[daytona] |
| EC2 via SSM | ec2_ssm | none (attach-only to an existing instance) | agentkernel[aws] |
| Kubernetes | kubernetes | container | agentkernel[kubernetes] |
Planned in later iterations: bedrock_agentcore.
Reference implementations by pattern: docker.py (sync SDK via to_thread), e2b.py
(native async SDK + native idle timeout passthrough), daytona.py (sync SDK + native
auto-stop + configurable base image/snapshot/env_vars + resource mapping), ec2_ssm.py
(attach-only provider with user-identity
mapping: sts:AssumeRole + run_as), kubernetes.py (sync SDK via to_thread with plain
dict manifests, exec over the WebSocket stream API (the caller's RBAC needs BOTH create
and get on pods/exec), user identity via cached per-subject RBAC-impersonation clients,
and the instance-level capability override, below). Providers with a native auto-stop take
the profile's idle_timeout as a second constructor argument, passed by their factory
branch; kubernetes takes it too, sizing the pod's activeDeadlineSeconds orphan ceiling.
Attach-only backends (environments the framework connects to but never owns) subclass
AttachedEnvironmentProvider instead of SandboxProvider: it fixes create (binds to the
config's attach_to, never provisions) and destroy (no-op) once, so only attach is
implemented. The handle subclasses AttachedEnvironment (not Sandbox directly), which fixes
close() as a no-op and keeps the class name honest (e.g. EC2SSMEnvironment). Declare
provisions=False, attaches_external=True — the factory validates the profile's
environment: managed | attached mode against these flags at startup (attach-only providers
are rejected under managed, and attached requires attaches_external plus an attach_to
target), and the worker never self-heal-provisions or disposes an attached environment.
The sandbox capability (ak-py/src/agentkernel/sandbox/) is config-driven and pluggable:
SandboxProvider (base.py) — one long-lived instance per configured profile backend.
Implements create()/destroy() (abstract), attach() when capabilities.attach is declared
(the base default raises SandboxCapabilityError), and declares a capabilities class attribute.Sandbox (base.py) — a handle to one live sandbox. Implements the two abstract methods
execute_code() (language="python") and close(), and optionally execute_command(),
upload_file(), download_file(), install_packages() (each raises SandboxCapabilityError
in the base until overridden).SandboxCapabilities (model.py) — the honest declaration of what the provider supports
(isolation tier, shell, languages, files, package_install, stateful, attach, principal_user,
policy_network/filesystem/resources). The manager/worker consult it before routing an operation;
an operation a provider didn't declare raises SandboxCapabilityError.SandboxProviderFactory (factory.py) — resolves a profile's type to a provider. Built-in
short names are if/elif branches with real lazy imports; anything with a dot is treated as a
dotted path to a SandboxProvider subclass (bring-your-own, no code change needed).BrokerWorkerCore (broker/worker.py) — enforces principal and policy fail-closed against
the declared capabilities, then calls the provider.Key principle — declare capabilities honestly. Only claim what the backend truly enforces.
If you declare policy_network=True but can't actually restrict egress, you've created a false
security guarantee. Under-declaring is safe (the operation raises a clear capability error);
over-declaring is a security bug.
Instance-level capability override (#503): when a capability's enforcement depends on
operator-asserted infrastructure the provider cannot detect, keep the class declaration honest
(False) and flip it per instance in __init__ via
self.capabilities = type(self).capabilities.model_copy(update=...) behind an explicit config
flag. The reference is the kubernetes provider's network_policy: true, which asserts the
cluster CNI actually enforces NetworkPolicy; consumers read provider.capabilities on the
instance, so attribute shadowing is sufficient.
Create ak-py/src/agentkernel/sandbox/providers/<provider>.py with a Sandbox subclass and a
SandboxProvider subclass.
from agentkernel.sandbox import Sandbox
from agentkernel.sandbox.errors import SandboxCapabilityError
from agentkernel.sandbox.model import SandboxResult
class <Provider>Sandbox(Sandbox):
def __init__(self, sandbox_id: str, ...) -> None:
self.id = sandbox_id # provider-scoped id, stable across attach/reconnect
async def execute_code(self, code: str, language: str = "python", timeout: float | None = None) -> SandboxResult:
# language="python" is MANDATORY. A failing program (non-zero exit) is a RESULT
# (SandboxResult with exit_code != 0), NOT an exception. Raise only on machinery failure.
if language not in <declared languages>:
raise SandboxCapabilityError(self.__class__.__name__, f"language:{language}")
...
return SandboxResult(stdout=..., stderr=..., exit_code=...)
# Override ONLY the optional operations your capabilities declare. The base ABC raises
# SandboxCapabilityError for execute_command / upload_file / download_file / install_packages
# when not overridden — that is capability honesty in action.
async def close(self) -> None:
# Idempotent. For per_session scope this must NOT destroy state needed for a later
# attach() — only destroy() permanently disposes backend state.
...Sync SDKs must be wrapped in asyncio.to_thread (see docker.py), since the sandbox runs on an
event loop. Enforce timeout with asyncio.wait_for when the backend has no native timeout.
from agentkernel.sandbox import Sandbox, SandboxProvider
from agentkernel.sandbox.errors import SandboxGoneError
from agentkernel.sandbox.model import IsolationTier, SandboxCapabilities, SandboxPolicy, SandboxPrincipal
class <Provider>SandboxProvider(SandboxProvider):
capabilities = SandboxCapabilities(
isolation=IsolationTier.CONTAINER, # declare the REAL boundary
shell=True,
languages=["python"],
files=True,
package_install=False,
stateful=False,
attach=True,
provisions=True, # False for attach-only backends (never create)
attaches_external=False, # True only if attach_to can bind to something you didn't create
principal_user=False, # True only if you enforce a user identity
policy_network=False, # True only if you actually restrict egress
policy_filesystem=False,
policy_resources=False,
)
def __init__(self, config) -> None:
super().__init__(config) # config is the provider's Pydantic config block
# Create SDK clients lazily (first use), not here — keep import/constructor cheap.
async def create(self, *, principal: SandboxPrincipal, policy: SandboxPolicy) -> Sandbox:
# Provision a new sandbox. Map `policy` onto the backend's real controls here; if a
# declared-enforceable dimension can't be honored for this request, raise SandboxPolicyError.
...
async def attach(self, sandbox_id: str, *, principal: SandboxPrincipal, policy: SandboxPolicy) -> Sandbox:
# Reconnect to an existing sandbox. Raise SandboxGoneError when the target is gone —
# that is the self-heal signal the worker uses to recreate under the same session id.
...
async def destroy(self, sandbox_id: str) -> None:
# Permanently dispose. Idempotent; unknown ids are a no-op.
...Policy mapping and principal mapping (for principal_user=True) belong in create/attach.
See docker.py for the policy mapping pattern (network_egress: deny → network_mode: none,
cpu/memory → container limits, filesystem → read-only rootfs + writable workdir).
Add an if/elif branch to SandboxProviderFactory._build in
ak-py/src/agentkernel/sandbox/factory.py, and append the short name to
_BUILTIN_PROVIDER_NAMES (this is the #541 house pattern: real lazy imports, no registry map):
if type_name == "<provider>":
config_block = cls._require_block(profile_name, profile, type_name)
with require_extra("<extra>", "sandbox provider '<provider>'"): # skip the wrap if stdlib-only
from .providers.<provider> import <Provider>SandboxProvider
return <Provider>SandboxProvider(config_block)_BUILTIN_PROVIDER_NAMES = ["local_subprocess", "docker", "<provider>"] # add your namerequire_extra produces the friendly pip install "agentkernel[<extra>]" message when the SDK
is missing. A bring-your-own provider needs none of this — a dotted-path type resolves via
resolve_dotted automatically.
In ak-py/src/agentkernel/core/config.py, add a _Sandbox<Provider>Config Pydantic model and
wire it as an Optional field on both _SandboxProfileConfig and _SandboxConfig (the
latter for single-backend sugar), mirroring _SandboxDockerConfig:
class _Sandbox<Provider>Config(BaseModel):
# provider-specific fields, e.g. image, region, api_key_env, attach_to
...
# on _SandboxProfileConfig AND _SandboxConfig:
<provider>: Optional[_Sandbox<Provider>Config] = Field(default=None, description="Configuration for the '<provider>' provider")The factory's _require_block raises SandboxConfigError when a built-in's config block is
missing, so the block must exist even if all fields have defaults (<provider>: {}).
If the provider needs an SDK, add an extra to ak-py/pyproject.toml (or reuse aws for boto3):
[project.optional-dependencies]
<extra> = ["provider-sdk>=x.y.z"]Add to ak-py/tests/test_sandbox_providers.py:
SandboxProviderContract (from
agentkernel.sandbox.testing) with a provider fixture returning your provider against a
mocked SDK. It asserts the ABC semantics (mandatory execute_code, capability honesty,
idempotent close/destroy, result-vs-exception discipline, attach honesty).to_thread usage for sync SDKs, timeout behavior.Mock the SDK (no real network/daemon). Add a factory test in ak-py/tests/test_sandbox.py
asserting the real-import branch resolves and the missing-extra path raises the friendly error.
Add a profile to an examples/sandbox/ example (or a new subfolder) showing the provider in
a config.yaml, and note any required services (daemon, API key, cloud creds) in the README.
examples/sandbox/docker/ is the reference: a full subfolder for an isolating provider,
including a profile that demonstrates enforced policy and sentinel-based deterministic tests.
docs/docs/advanced/sandbox.md (with the honest isolation
tier and the extra), and to the "Installation" extras in ak-py/README.md.principal_user, document its identity mapping (how agent/user
mode resolves to backend credentials).docs/src/components/*/data.tsx): a tile in the Cloud &
infrastructure row of IntegrationsMarquee/data.tsx (role Sandbox, href to the
provider's setup anchor in docs/docs/advanced/sandbox.md, logo or react-icons/si glyph),
and the provider in the Sandboxed Execution card's tags and description under the
Scale tab in FeatureExplorer/data.tsx. Logo sourcing and the build check are in
ak-dev-sync-docs-from-branch, Docs-Site Landing and Features Pages.docs/src/pages/features.tsx): the provider-name highlight on the Sandboxed
Code Execution card and the provider count in the sandbox entry of FEATURE_PAGE_MAP. Grep
docs/src/pages/*.tsx, docs/docs/intro.md, and docs/src/components/SandboxFlowDiagram
for the provider roll call and the count.ak-py/src/agentkernel/sandbox/providers/<provider>.py with Sandbox + SandboxProvider subclassescapabilities declared honestly (only what the backend truly enforces)if/elif real-import branch + name in _BUILTIN_PROVIDER_NAMES (factory.py)_Sandbox<Provider>Config block on _SandboxProfileConfig and _SandboxConfig (config.py)pyproject.toml (if the SDK isn't stdlib/boto3)SandboxProviderContract subclass + provider-specific tests in tests/test_sandbox_providers.pytests/test_sandbox.pyexamples/sandbox/docs/docs/advanced/sandbox.md + extra in ak-py/README.mdIntegrationsMarquee/data.tsx), Sandboxed Execution card tags (FeatureExplorer/data.tsx)docs/src/pages/features.tsx (sandbox card highlight and FEATURE_PAGE_MAP count) and SandboxFlowDiagram© yaalalabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/ak-dev-new-sandbox-provider of yaalalabs/agent-kernel.
Open the folder on GitHubat commit 97fa8d9
Ak Dev New Sandbox Provider next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ak Dev New Sandbox Provider this skillyaalalabs/agent-kernel | 192 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | |
| LangBot Deployment Guidelangbot-app/LangBot | 18k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | |
| Build Openshell Mxc WindowsNVIDIA/OpenShell | 16k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | |
| Devopsnicepkg/auto-company | 195 | 2 repos | ~814 | Automated safety check: Pass | MIT | |
| Debug Openshell ClusterNVIDIA/OpenShell | 16k | — | ~20k | Automated safety check: Notes | Apache-2.0 | |
| Deepseek Harness Dockerrunzhliu/deepseek-harness-docker | 110 | — | ~2.7k | Automated safety check: Notes | MIT |
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
NVIDIA/OpenShell
Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.
nicepkg/auto-company
Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).
NVIDIA/OpenShell
Debug why an OpenShell gateway deployment is unhealthy, unreachable, or unable to create sandboxes.
runzhliu/deepseek-harness-docker
Deploy, configure, verify, upgrade, and troubleshoot DeepSeek Harness with the community Docker, Docker Compose, rootless Podman, and Helm runtime, including the built-in Chromium/noVNC browser…
ericboy0224/learn-docker-and-k8s
Clean up Docker resources created by the Learn Docker & K8s game.
yaalalabs/agent-kernel
Code quality standards, formatting, Python style rules (classes over script-style functions, configuration-field rules), commit conventions, and PR workflow for Agent Kernel development.
yaalalabs/agent-kernel
Step-by-step guide for adding a new built-in test evaluator provider to Agent Kernel (beyond DeepEval, Opik and JEV).
yaalalabs/agent-kernel
Step-by-step guide for adding a new guardrail provider to Agent Kernel.
yaalalabs/agent-kernel
Step-by-step guide for adding a new knowledge base backend to Agent Kernel.
yaalalabs/agent-kernel
Step-by-step guide for adding a new messaging platform integration to Agent Kernel.
yaalalabs/agent-kernel
Step-by-step guide for adding a new multimodal attachment storage backend to Agent Kernel.
Works with
Categories
Step-by-step guide for adding a new sandbox provider to Agent Kernel. Ak Dev New Sandbox Provider is an agent skill from yaalalabs/agent-kernel. Step-by-step guide for adding a new sandbox provider to Agent Kernel.
Ak Dev New Sandbox Provider fits situations like: you need to integrate a new code-execution backend for the sandbox capability (beyond localsubprocess; tasks that involve Container orchestration; tasks that involve Integration testing.
Run `npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a claude-code`. Or copy the skill folder (.agents/skills/ak-dev-new-sandbox-provider in yaalalabs/agent-kernel) into .claude/skills/ak-dev-new-sandbox-provider in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a codex`. Or copy the skill folder (.agents/skills/ak-dev-new-sandbox-provider in yaalalabs/agent-kernel) into .agents/skills/ak-dev-new-sandbox-provider in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ak-dev-new-sandbox-provider, .gemini/skills/ak-dev-new-sandbox-provider, .github/skills/ak-dev-new-sandbox-provider and .opencode/skills/ak-dev-new-sandbox-provider in your project.
Going by SKILL.md and its folder, Ak Dev New Sandbox Provider needs the command-line tools its instructions call (pip). Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Ak Dev New Sandbox Provider is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ak Dev New Sandbox Provider: LangBot Deployment Guide (langbot-app/LangBot, 18k stars), Build Openshell Mxc Windows (NVIDIA/OpenShell, 16k stars), Devops (nicepkg/auto-company, 195 stars) and Debug Openshell Cluster (NVIDIA/OpenShell, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yaalalabs (a GitHub organization) maintains it in yaalalabs/agent-kernel, which has 192 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 9, 2026.
Source: yaalalabs/agent-kernel on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.