Agent skill

Ak Dev New Sandbox Provider

by yaalalabs in yaalalabs/agent-kernel

Step-by-step guide for adding a new sandbox provider to Agent Kernel.

Apache-2.0Auto-check passedDevOps & Cloud

Install Ak Dev New Sandbox Provider

skills CLI
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yaalalabs/agent-kernel ak-dev-new-sandbox-provider --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ak-dev-new-sandbox-provider .claude/skills/ak-dev-new-sandbox-provider && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ak-dev-new-sandbox-provider
GitHub stars
192
Token cost
~3.7k tokens
SKILL.md length
1,114 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
Apache-2.0

At a glance

Step-by-step guide for adding a new sandbox provider to Agent Kernel.

  • Works in 9 steps: Create the Provider File → Implement the Sandbox Handle → Implement the Provider → …
  • You need to integrate a new code-execution backend for the sandbox capability (beyond localsubprocess
  • SKILL.md covers Existing Providers, Architecture Overview, Step-by-Step and Checklist
  • Calls pip

What it does

Ak Dev New Sandbox Provider is an agent skill from yaalalabs/agent-kernel. Step-by-step guide for adding a new sandbox provider to Agent Kernel. Use this skill when you need to integrate a new code-execution backend for the sandbox capability (beyond localsubprocess, docker, kubernetes, e2b, daytona, and ec2ssm). Covers implementing the Sandbox / SandboxProvider ABCs, declaring capabilities honestly, factory registration, configuration, the contract test suite, and examples.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Container orchestration, Integration testing and Containers. It works with Docker and Kubernetes. The repository describes itself as: The Operating System for Scalable Enterprise AI Agents - Run, orchestrate, and deploy Compliant Enterprise AI Agents at scale across frameworks, without lock-in, rewrites or… The licence is Apache-2.0.

When your agent uses it

  • You need to integrate a new code-execution backend for the sandbox capability (beyond localsubprocess
  • Tasks that involve Container orchestration
  • Tasks that involve Integration testing

Example prompts

  • “/ak-dev-new-sandbox-provider”

Requirements

  • Python 3
  • Docker

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Create the Provider File
  2. Implement the Sandbox Handle
  3. Implement the Provider
  4. Register with the Factory
  5. Add the Config Block
  6. Add the Optional Dependency Extra
  7. Add Tests
  8. Add an Example
  9. Add Documentation

What it can do on your machine

Read from SKILL.md and the folder at commit 97fa8d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ak Dev New Sandbox Provider loads about 3.7k tokens when it runs. Until then it costs about 109 tokens; SKILL.md has 1,114 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yaalalabs/agent-kernel at commit 97fa8d9, republished under its Apache-2.0 licence (© yaalalabs). 1,114 words, ~3,711 tokens.

Download SKILL.mdSave it as .claude/skills/ak-dev-new-sandbox-provider/SKILL.md (or your agent's skills folder).
name
ak-dev-new-sandbox-provider
description
Step-by-step guide for adding a new sandbox provider to Agent Kernel. Use this skill when you need to integrate a new code-execution backend for the sandbox capability (beyond local_subprocess, docker, kubernetes, e2b, daytona, and ec2_ssm). Covers implementing the Sandbox / SandboxProvider ABCs, declaring capabilities honestly, factory registration, configuration, the contract test suite, and examples.
license
Apache-2.0
metadata.author
yaalalabs
metadata.category
developer

Adding a New Sandbox Provider

This guide walks through adding a new sandbox provider to Agent Kernel. Use the shipped local_subprocess (ak-py/src/agentkernel/sandbox/providers/local_subprocess.py) and docker (ak-py/src/agentkernel/sandbox/providers/docker.py) implementations as reference.

Existing Providers

Providertype valueIsolationExtra
Local subprocesslocal_subprocessnone (no isolation; dev/test)— (stdlib)
Dockerdockercontaineragentkernel[sandbox-docker]
E2Be2bmicro_vmagentkernel[e2b]
Daytonadaytonacontaineragentkernel[daytona]
EC2 via SSMec2_ssmnone (attach-only to an existing instance)agentkernel[aws]
Kuberneteskubernetescontaineragentkernel[kubernetes]

Planned in later iterations: bedrock_agentcore.

Reference implementations by pattern: docker.py (sync SDK via to_thread), e2b.py (native async SDK + native idle timeout passthrough), daytona.py (sync SDK + native auto-stop + configurable base image/snapshot/env_vars + resource mapping), ec2_ssm.py (attach-only provider with user-identity mapping: sts:AssumeRole + run_as), kubernetes.py (sync SDK via to_thread with plain dict manifests, exec over the WebSocket stream API (the caller's RBAC needs BOTH create and get on pods/exec), user identity via cached per-subject RBAC-impersonation clients, and the instance-level capability override, below). Providers with a native auto-stop take the profile's idle_timeout as a second constructor argument, passed by their factory branch; kubernetes takes it too, sizing the pod's activeDeadlineSeconds orphan ceiling.

Attach-only backends (environments the framework connects to but never owns) subclass AttachedEnvironmentProvider instead of SandboxProvider: it fixes create (binds to the config's attach_to, never provisions) and destroy (no-op) once, so only attach is implemented. The handle subclasses AttachedEnvironment (not Sandbox directly), which fixes close() as a no-op and keeps the class name honest (e.g. EC2SSMEnvironment). Declare provisions=False, attaches_external=True — the factory validates the profile's environment: managed | attached mode against these flags at startup (attach-only providers are rejected under managed, and attached requires attaches_external plus an attach_to target), and the worker never self-heal-provisions or disposes an attached environment.

Architecture Overview

The sandbox capability (ak-py/src/agentkernel/sandbox/) is config-driven and pluggable:

  • SandboxProvider (base.py) — one long-lived instance per configured profile backend. Implements create()/destroy() (abstract), attach() when capabilities.attach is declared (the base default raises SandboxCapabilityError), and declares a capabilities class attribute.
  • Sandbox (base.py) — a handle to one live sandbox. Implements the two abstract methods execute_code() (language="python") and close(), and optionally execute_command(), upload_file(), download_file(), install_packages() (each raises SandboxCapabilityError in the base until overridden).
  • SandboxCapabilities (model.py) — the honest declaration of what the provider supports (isolation tier, shell, languages, files, package_install, stateful, attach, principal_user, policy_network/filesystem/resources). The manager/worker consult it before routing an operation; an operation a provider didn't declare raises SandboxCapabilityError.
  • SandboxProviderFactory (factory.py) — resolves a profile's type to a provider. Built-in short names are if/elif branches with real lazy imports; anything with a dot is treated as a dotted path to a SandboxProvider subclass (bring-your-own, no code change needed).
  • BrokerWorkerCore (broker/worker.py) — enforces principal and policy fail-closed against the declared capabilities, then calls the provider.

Key principle — declare capabilities honestly. Only claim what the backend truly enforces. If you declare policy_network=True but can't actually restrict egress, you've created a false security guarantee. Under-declaring is safe (the operation raises a clear capability error); over-declaring is a security bug.

Instance-level capability override (#503): when a capability's enforcement depends on operator-asserted infrastructure the provider cannot detect, keep the class declaration honest (False) and flip it per instance in __init__ via self.capabilities = type(self).capabilities.model_copy(update=...) behind an explicit config flag. The reference is the kubernetes provider's network_policy: true, which asserts the cluster CNI actually enforces NetworkPolicy; consumers read provider.capabilities on the instance, so attribute shadowing is sufficient.

Step-by-Step

1. Create the Provider File

Create ak-py/src/agentkernel/sandbox/providers/<provider>.py with a Sandbox subclass and a SandboxProvider subclass.

2. Implement the Sandbox Handle
python
from agentkernel.sandbox import Sandbox
from agentkernel.sandbox.errors import SandboxCapabilityError
from agentkernel.sandbox.model import SandboxResult


class <Provider>Sandbox(Sandbox):
    def __init__(self, sandbox_id: str, ...) -> None:
        self.id = sandbox_id            # provider-scoped id, stable across attach/reconnect

    async def execute_code(self, code: str, language: str = "python", timeout: float | None = None) -> SandboxResult:
        # language="python" is MANDATORY. A failing program (non-zero exit) is a RESULT
        # (SandboxResult with exit_code != 0), NOT an exception. Raise only on machinery failure.
        if language not in <declared languages>:
            raise SandboxCapabilityError(self.__class__.__name__, f"language:{language}")
        ...
        return SandboxResult(stdout=..., stderr=..., exit_code=...)

    # Override ONLY the optional operations your capabilities declare. The base ABC raises
    # SandboxCapabilityError for execute_command / upload_file / download_file / install_packages
    # when not overridden — that is capability honesty in action.

    async def close(self) -> None:
        # Idempotent. For per_session scope this must NOT destroy state needed for a later
        # attach() — only destroy() permanently disposes backend state.
        ...

Sync SDKs must be wrapped in asyncio.to_thread (see docker.py), since the sandbox runs on an event loop. Enforce timeout with asyncio.wait_for when the backend has no native timeout.

3. Implement the Provider
python
from agentkernel.sandbox import Sandbox, SandboxProvider
from agentkernel.sandbox.errors import SandboxGoneError
from agentkernel.sandbox.model import IsolationTier, SandboxCapabilities, SandboxPolicy, SandboxPrincipal


class <Provider>SandboxProvider(SandboxProvider):
    capabilities = SandboxCapabilities(
        isolation=IsolationTier.CONTAINER,   # declare the REAL boundary
        shell=True,
        languages=["python"],
        files=True,
        package_install=False,
        stateful=False,
        attach=True,
        provisions=True,                     # False for attach-only backends (never create)
        attaches_external=False,             # True only if attach_to can bind to something you didn't create
        principal_user=False,                # True only if you enforce a user identity
        policy_network=False,                # True only if you actually restrict egress
        policy_filesystem=False,
        policy_resources=False,
    )

    def __init__(self, config) -> None:
        super().__init__(config)             # config is the provider's Pydantic config block
        # Create SDK clients lazily (first use), not here — keep import/constructor cheap.

    async def create(self, *, principal: SandboxPrincipal, policy: SandboxPolicy) -> Sandbox:
        # Provision a new sandbox. Map `policy` onto the backend's real controls here; if a
        # declared-enforceable dimension can't be honored for this request, raise SandboxPolicyError.
        ...

    async def attach(self, sandbox_id: str, *, principal: SandboxPrincipal, policy: SandboxPolicy) -> Sandbox:
        # Reconnect to an existing sandbox. Raise SandboxGoneError when the target is gone —
        # that is the self-heal signal the worker uses to recreate under the same session id.
        ...

    async def destroy(self, sandbox_id: str) -> None:
        # Permanently dispose. Idempotent; unknown ids are a no-op.
        ...

Policy mapping and principal mapping (for principal_user=True) belong in create/attach. See docker.py for the policy mapping pattern (network_egress: deny → network_mode: none, cpu/memory → container limits, filesystem → read-only rootfs + writable workdir).

4. Register with the Factory

Add an if/elif branch to SandboxProviderFactory._build in ak-py/src/agentkernel/sandbox/factory.py, and append the short name to _BUILTIN_PROVIDER_NAMES (this is the #541 house pattern: real lazy imports, no registry map):

python
if type_name == "<provider>":
    config_block = cls._require_block(profile_name, profile, type_name)
    with require_extra("<extra>", "sandbox provider '<provider>'"):   # skip the wrap if stdlib-only
        from .providers.<provider> import <Provider>SandboxProvider
    return <Provider>SandboxProvider(config_block)
python
_BUILTIN_PROVIDER_NAMES = ["local_subprocess", "docker", "<provider>"]   # add your name

require_extra produces the friendly pip install "agentkernel[<extra>]" message when the SDK is missing. A bring-your-own provider needs none of this — a dotted-path type resolves via resolve_dotted automatically.

Show full SKILL.md (436 more words)Show less
5. Add the Config Block

In ak-py/src/agentkernel/core/config.py, add a _Sandbox<Provider>Config Pydantic model and wire it as an Optional field on both _SandboxProfileConfig and _SandboxConfig (the latter for single-backend sugar), mirroring _SandboxDockerConfig:

python
class _Sandbox<Provider>Config(BaseModel):
    # provider-specific fields, e.g. image, region, api_key_env, attach_to
    ...

# on _SandboxProfileConfig AND _SandboxConfig:
<provider>: Optional[_Sandbox<Provider>Config] = Field(default=None, description="Configuration for the '<provider>' provider")

The factory's _require_block raises SandboxConfigError when a built-in's config block is missing, so the block must exist even if all fields have defaults (<provider>: {}).

6. Add the Optional Dependency Extra

If the provider needs an SDK, add an extra to ak-py/pyproject.toml (or reuse aws for boto3):

toml
[project.optional-dependencies]
<extra> = ["provider-sdk>=x.y.z"]
7. Add Tests

Add to ak-py/tests/test_sandbox_providers.py:

  • Contract suite — subclass the public SandboxProviderContract (from agentkernel.sandbox.testing) with a provider fixture returning your provider against a mocked SDK. It asserts the ABC semantics (mandatory execute_code, capability honesty, idempotent close/destroy, result-vs-exception discipline, attach honesty).
  • Provider specifics — create/attach/execute/destroy call shapes, policy/principal mapping arguments, to_thread usage for sync SDKs, timeout behavior.

Mock the SDK (no real network/daemon). Add a factory test in ak-py/tests/test_sandbox.py asserting the real-import branch resolves and the missing-extra path raises the friendly error.

8. Add an Example

Add a profile to an examples/sandbox/ example (or a new subfolder) showing the provider in a config.yaml, and note any required services (daemon, API key, cloud creds) in the README. examples/sandbox/docker/ is the reference: a full subfolder for an isolating provider, including a profile that demonstrates enforced policy and sentinel-based deterministic tests.

9. Add Documentation
  • Add a row to the provider table in docs/docs/advanced/sandbox.md (with the honest isolation tier and the extra), and to the "Installation" extras in ak-py/README.md.
  • If the provider supports principal_user, document its identity mapping (how agent/user mode resolves to backend credentials).
  • Landing page inventories (docs/src/components/*/data.tsx): a tile in the Cloud & infrastructure row of IntegrationsMarquee/data.tsx (role Sandbox, href to the provider's setup anchor in docs/docs/advanced/sandbox.md, logo or react-icons/si glyph), and the provider in the Sandboxed Execution card's tags and description under the Scale tab in FeatureExplorer/data.tsx. Logo sourcing and the build check are in ak-dev-sync-docs-from-branch, Docs-Site Landing and Features Pages.
  • Features page (docs/src/pages/features.tsx): the provider-name highlight on the Sandboxed Code Execution card and the provider count in the sandbox entry of FEATURE_PAGE_MAP. Grep docs/src/pages/*.tsx, docs/docs/intro.md, and docs/src/components/SandboxFlowDiagram for the provider roll call and the count.

Checklist

  • ak-py/src/agentkernel/sandbox/providers/<provider>.py with Sandbox + SandboxProvider subclasses
  • capabilities declared honestly (only what the backend truly enforces)
  • Factory if/elif real-import branch + name in _BUILTIN_PROVIDER_NAMES (factory.py)
  • _Sandbox<Provider>Config block on _SandboxProfileConfig and _SandboxConfig (config.py)
  • Optional dependency extra in pyproject.toml (if the SDK isn't stdlib/boto3)
  • SandboxProviderContract subclass + provider-specific tests in tests/test_sandbox_providers.py
  • Factory resolution test in tests/test_sandbox.py
  • Example profile in examples/sandbox/
  • Documentation: provider table row in docs/docs/advanced/sandbox.md + extra in ak-py/README.md
  • Landing page inventories: marquee tile (IntegrationsMarquee/data.tsx), Sandboxed Execution card tags (FeatureExplorer/data.tsx)
  • Provider inventories on docs/src/pages/features.tsx (sandbox card highlight and FEATURE_PAGE_MAP count) and SandboxFlowDiagram

© yaalalabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/ak-dev-new-sandbox-provider of yaalalabs/agent-kernel.

Open the folder on GitHubat commit 97fa8d9

Compare with similar skills

Ak Dev New Sandbox Provider next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ak Dev New Sandbox Provider compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ak Dev New Sandbox Provider this skillyaalalabs/agent-kernel192—~3.7kAutomated safety check: PassApache-2.0
LangBot Deployment Guidelangbot-app/LangBot18k—~1.5kAutomated safety check: NotesApache-2.0
Build Openshell Mxc WindowsNVIDIA/OpenShell16k—~4.9kAutomated safety check: PassApache-2.0
Devopsnicepkg/auto-company1952 repos~814Automated safety check: PassMIT
Debug Openshell ClusterNVIDIA/OpenShell16k—~20kAutomated safety check: NotesApache-2.0
Deepseek Harness Dockerrunzhliu/deepseek-harness-docker110—~2.7kAutomated safety check: NotesMIT

Similar skills

  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    16k GitHub stars~4.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    195 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed
  • Debug Openshell Cluster

    NVIDIA/OpenShell

    Official

    Debug why an OpenShell gateway deployment is unhealthy, unreachable, or unable to create sandboxes.

    16k GitHub stars~20k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Deepseek Harness Docker

    runzhliu/deepseek-harness-docker

    Deploy, configure, verify, upgrade, and troubleshoot DeepSeek Harness with the community Docker, Docker Compose, rootless Podman, and Helm runtime, including the built-in Chromium/noVNC browser…

    110 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Cleanup

    ericboy0224/learn-docker-and-k8s

    Clean up Docker resources created by the Learn Docker & K8s game.

    491 GitHub stars~454 tokensUpdated 6 mo ago
    DevOps & CloudAuto-check passed

More from yaalalabs/agent-kernel

All 23 skills in this repo
  • Ak Dev Code Quality

    yaalalabs/agent-kernel

    Code quality standards, formatting, Python style rules (classes over script-style functions, configuration-field rules), commit conventions, and PR workflow for Agent Kernel development.

    192 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Ak Dev New Evaluator Provider

    yaalalabs/agent-kernel

    Step-by-step guide for adding a new built-in test evaluator provider to Agent Kernel (beyond DeepEval, Opik and JEV).

    192 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ak Dev New Guardrail Provider

    yaalalabs/agent-kernel

    Step-by-step guide for adding a new guardrail provider to Agent Kernel.

    192 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed
  • Step-by-step guide for adding a new knowledge base backend to Agent Kernel.

    192 GitHub stars~5.1k tokensUpdated yesterday
    Auto-check passed
  • Ak Dev New Messaging Integration

    yaalalabs/agent-kernel

    Step-by-step guide for adding a new messaging platform integration to Agent Kernel.

    192 GitHub stars~4.6k tokensUpdated yesterday
    Auto-check passed
  • Ak Dev New Multimodal Storage

    yaalalabs/agent-kernel

    Step-by-step guide for adding a new multimodal attachment storage backend to Agent Kernel.

    192 GitHub stars~4.3k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Ak Dev New Sandbox Provider

What does Ak Dev New Sandbox Provider do?

Step-by-step guide for adding a new sandbox provider to Agent Kernel. Ak Dev New Sandbox Provider is an agent skill from yaalalabs/agent-kernel. Step-by-step guide for adding a new sandbox provider to Agent Kernel.

When should I use Ak Dev New Sandbox Provider?

Ak Dev New Sandbox Provider fits situations like: you need to integrate a new code-execution backend for the sandbox capability (beyond localsubprocess; tasks that involve Container orchestration; tasks that involve Integration testing.

How do I install Ak Dev New Sandbox Provider in Claude Code?

Run `npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a claude-code`. Or copy the skill folder (.agents/skills/ak-dev-new-sandbox-provider in yaalalabs/agent-kernel) into .claude/skills/ak-dev-new-sandbox-provider in your project. Claude Code loads it when a task matches its description.

How do I install Ak Dev New Sandbox Provider in Codex?

Run `npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a codex`. Or copy the skill folder (.agents/skills/ak-dev-new-sandbox-provider in yaalalabs/agent-kernel) into .agents/skills/ak-dev-new-sandbox-provider in your project. Codex loads it when a task matches its description.

Can I use Ak Dev New Sandbox Provider in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaalalabs/agent-kernel --skill ak-dev-new-sandbox-provider -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ak-dev-new-sandbox-provider, .gemini/skills/ak-dev-new-sandbox-provider, .github/skills/ak-dev-new-sandbox-provider and .opencode/skills/ak-dev-new-sandbox-provider in your project.

What does Ak Dev New Sandbox Provider need to run?

Going by SKILL.md and its folder, Ak Dev New Sandbox Provider needs the command-line tools its instructions call (pip). Our summary lists: Python 3; Docker.

Does Ak Dev New Sandbox Provider access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ak Dev New Sandbox Provider safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ak Dev New Sandbox Provider use?

Ak Dev New Sandbox Provider is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ak Dev New Sandbox Provider use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ak Dev New Sandbox Provider?

Skills that share tags, products or a category with Ak Dev New Sandbox Provider: LangBot Deployment Guide (langbot-app/LangBot, 18k stars), Build Openshell Mxc Windows (NVIDIA/OpenShell, 16k stars), Devops (nicepkg/auto-company, 195 stars) and Debug Openshell Cluster (NVIDIA/OpenShell, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ak Dev New Sandbox Provider?

yaalalabs (a GitHub organization) maintains it in yaalalabs/agent-kernel, which has 192 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 9, 2026.

Source: yaalalabs/agent-kernel on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.