Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/an8079/take-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/an8079/take-skills/takes-sandbox)<a href="https://agentmods.dev/commands/an8079/take-skills/takes-sandbox"><img src="https://agentmods.dev/badge/commands/an8079/take-skills/takes-sandbox/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/an8079/take-skills/takes-sandbox"><img src="https://agentmods.dev/badge/commands/an8079/take-skills/takes-sandbox.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00016 | $0.01678 |
| Opus 5 | $0.00008 | $0.00839 |
| Sonnet 5 | $0.00003 | $0.00336 |
| Haiku 4.5 | $0.00002 | $0.00168 |
Grade A, and why
sandbox scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 224 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/sandbox - 沙箱隔离执行
为敏感、危险或不可信操作提供隔离的 Docker 容器执行环境。
使用方式
/sandbox "命令或任务描述"
或
沙箱执行
隔离运行
安全模式
核心能力
容器隔离
| 特性 | 说明 |
|---|---|
| 网络隔离 | --network none,完全禁用网络访问 |
| 文件系统只读 | 根文件系统只读,白名单路径可写 |
| 资源限制 | CPU、内存限制 |
| 临时文件系统 | /tmp、/var/run 使用 tmpfs |
| 非 root 运行 | 在隔离的用户下执行 |
沙箱执行场景
import { sandboxExec, sandboxClaudeExec, containerCreate, containerRemove } from './scripts/docker-utils.ts';
// 1. 在沙箱中执行任意命令
const result = await sandboxExec('rm -rf / --no-preserve-root', {
timeout: 5000,
networkIsolation: true,
});
// 实际不会执行危险操作,因为网络和文件系统都被隔离
// 2. 在沙箱中执行 Claude Code
const claudeResult = await sandboxClaudeExec('Analyze this codebase', {
apiKey: process.env.ANTHROPIC_API_KEY,
allowedTools: ['Read', 'Grep', 'Glob'],
memoryLimit: '1g',
});
// 3. 手动管理容器
const containerId = containerCreate({
image: 'alpine:latest',
name: 'my-sandbox',
networkMode: 'none',
memoryLimit: '512m',
mounts: [
{ source: '/safe/path', target: '/workspace', readonly: true }
]
});
containerStart(containerId);
// ... 执行操作
containerStop(containerId);
containerRemove(containerId);
生命周期管理
| 函数 | 说明 |
|---|---|
containerCreate() |
创建容器 |
containerStart() |
启动容器 |
containerStop() |
停止容器 |
containerRemove() |
删除容器 |
containerStats() |
获取资源使用统计 |
containerInspect() |
获取容器详细信息 |
containerList() |
列出所有容器 |
安全特性
-
网络隔离
- 可选
networkIsolation: true完全禁用网络 - 使用
init-firewall.sh配置白名单域名
- 可选
-
文件系统隔离
- 根文件系统只读
- 临时目录使用 tmpfs(内存文件系统)
- 白名单路径可写
-
资源限制
- CPU 限制:
--cpus - 内存限制:
--memory - 超时控制:防止无限运行
- CPU 限制:
-
工具限制
const result = await sandboxExec('rm -rf /', { allowedTools: ['Read'], // 只允许读取 allowedPaths: ['/safe/path'], deniedPaths: ['/etc/shadow', '/root/.ssh'], });
与 claude-hub 的集成
参考 F:/AI项目/claude-hub-main/ 的实现:
claude-hub/
├── Dockerfile.claudecode # 容器镜像定义
└── scripts/
├── runtime/
│ └── claudecode-entrypoint.sh # 入口脚本
└── security/
└── init-firewall.sh # 防火墙配置
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 224 lines · 16 tokens per session scan E f5790cf6d85b
sandbox is a command published in the GitHub repository an8079/take-skills (4 stars, last pushed 5mo ago), licensed MIT. It adds 16 tokens to every session and 1,678 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.
specify
Create or update the feature specification from a natural language feature description.
analyze
Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.
converge
Assess the current codebase against the feature's spec, plan, and tasks, then append any remaining unbuilt work as new tasks to tasks.md so implement can complete it.
implement
Execute the implementation plan by processing and executing all tasks defined in tasks.md.