sandbox

sandbox is a command for Claude Code from an8079/take-skills. It costs 16 tokens per session (1,678 once invoked), scanned A, original, MIT.

A command that runs commands or coding-agent tasks inside an isolated Docker container. Docker containers are separated environments that can limit network access, file changes, users, and computer resources.

In plain words
What is it for?
Use it to run risky commands, inspect a codebase with limited tools, or manage temporary isolated containers.
Why use it?
It helps contain sensitive, dangerous, or untrusted operations so they are less likely to affect the main system.

Command for Claude Code

Written for Claude Code: shipped in a Claude Code plugin. Also seen: mentions Claude Code.

Part of the claude-dev-assistant plugin — 21 skills, 39 commands shipped together

Good fit Use it to run risky commands, inspect a codebase with limited tools, or manage temporary isolated containers.

Compare 6 commands from other repositories ↓
Install with agentmods
npx agentmods add commands/an8079/take-skills/takes-sandbox
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/an8079/take-skills

Made for: Claude Code.

Or install claude-dev-assistant, the plugin that ships this one along with the rest of its 21 skills, 39 commands.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for sandbox

README.md
[![agentmods](https://agentmods.dev/badge/commands/an8079/take-skills/takes-sandbox/github.svg)](https://agentmods.dev/commands/an8079/take-skills/takes-sandbox)
Your own site
<a href="https://agentmods.dev/commands/an8079/take-skills/takes-sandbox"><img src="https://agentmods.dev/badge/commands/an8079/take-skills/takes-sandbox/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for sandbox

Your own site · 80×15
<a href="https://agentmods.dev/commands/an8079/take-skills/takes-sandbox"><img src="https://agentmods.dev/badge/commands/an8079/take-skills/takes-sandbox.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 16 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,678 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. ✓ AI security review Sonnet 5 · 7 Sept 2026 📄 Read the review
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00016 $0.01678
Opus 5 $0.00008 $0.00839
Sonnet 5 $0.00003 $0.00336
Haiku 4.5 $0.00002 $0.00168

Measured 10d ago against content hash f5790cf6d85b, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

sandbox scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

commands/takes-sandbox.md · 224 lines

How it starts

The opening of the file, as written. The whole thing — 224 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/sandbox - 沙箱隔离执行

为敏感、危险或不可信操作提供隔离的 Docker 容器执行环境。

使用方式

/sandbox "命令或任务描述"

沙箱执行
隔离运行
安全模式

核心能力

容器隔离

特性 说明
网络隔离 --network none,完全禁用网络访问
文件系统只读 根文件系统只读,白名单路径可写
资源限制 CPU、内存限制
临时文件系统 /tmp/var/run 使用 tmpfs
非 root 运行 在隔离的用户下执行

沙箱执行场景

import { sandboxExec, sandboxClaudeExec, containerCreate, containerRemove } from './scripts/docker-utils.ts';

// 1. 在沙箱中执行任意命令
const result = await sandboxExec('rm -rf / --no-preserve-root', {
  timeout: 5000,
  networkIsolation: true,
});
// 实际不会执行危险操作,因为网络和文件系统都被隔离

// 2. 在沙箱中执行 Claude Code
const claudeResult = await sandboxClaudeExec('Analyze this codebase', {
  apiKey: process.env.ANTHROPIC_API_KEY,
  allowedTools: ['Read', 'Grep', 'Glob'],
  memoryLimit: '1g',
});

// 3. 手动管理容器
const containerId = containerCreate({
  image: 'alpine:latest',
  name: 'my-sandbox',
  networkMode: 'none',
  memoryLimit: '512m',
  mounts: [
    { source: '/safe/path', target: '/workspace', readonly: true }
  ]
});

containerStart(containerId);
// ... 执行操作
containerStop(containerId);
containerRemove(containerId);

生命周期管理

函数 说明
containerCreate() 创建容器
containerStart() 启动容器
containerStop() 停止容器
containerRemove() 删除容器
containerStats() 获取资源使用统计
containerInspect() 获取容器详细信息
containerList() 列出所有容器

安全特性

  1. 网络隔离

    • 可选 networkIsolation: true 完全禁用网络
    • 使用 init-firewall.sh 配置白名单域名
  2. 文件系统隔离

    • 根文件系统只读
    • 临时目录使用 tmpfs(内存文件系统)
    • 白名单路径可写
  3. 资源限制

    • CPU 限制:--cpus
    • 内存限制:--memory
    • 超时控制:防止无限运行
  4. 工具限制

    const result = await sandboxExec('rm -rf /', {
      allowedTools: ['Read'], // 只允许读取
      allowedPaths: ['/safe/path'],
      deniedPaths: ['/etc/shadow', '/root/.ssh'],
    });
    

与 claude-hub 的集成

参考 F:/AI项目/claude-hub-main/ 的实现:

claude-hub/
├── Dockerfile.claudecode     # 容器镜像定义
└── scripts/
    ├── runtime/
    │   └── claudecode-entrypoint.sh  # 入口脚本
    └── security/
        └── init-firewall.sh          # 防火墙配置

Read the full file on GitHub · 224 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 224 lines · 16 tokens per session scan E f5790cf6d85b

Subscribe to this mod's changes

sandbox is a command published in the GitHub repository an8079/take-skills (4 stars, last pushed 5mo ago), licensed MIT. It adds 16 tokens to every session and 1,678 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.