Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/2018wzh/windows-sandbox-computer-use/agents-mdgit clone --depth 1 https://github.com/2018wzh/windows-sandbox-computer-useWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/2018wzh/windows-sandbox-computer-use/agents-md)<a href="https://agentmods.dev/instructions/2018wzh/windows-sandbox-computer-use/agents-md"><img src="https://agentmods.dev/badge/instructions/2018wzh/windows-sandbox-computer-use/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00318 | $0.00318 |
| Opus 5 | $0.00159 | $0.00159 |
| Sonnet 5 | $0.00064 | $0.00064 |
| Haiku 4.5 | $0.00032 | $0.00032 |
Grade A, and why
windows-sandbox-computer-use AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Repository instructions
Product boundary
This repository ships one Windows Sandbox-only skill through two distribution surfaces:
- a skills-only Codex plugin and repo Marketplace;
- the open Agent Skills layout discovered by
npx skills.
Both surfaces must consume the single canonical skill tree at:
plugins/windows-sandbox-computer-use/skills/windows-sandbox-computer-use/
Do not create a second skill copy, generic RDP backend, legacy Sandbox window backend, compatibility layer, credential path, or silent fallback.
Runtime architecture
wsb / SandboxCore -> IronRDP NamedPipe -> screenshots and remote input
Use wsb share for scoped directory sharing. Keep read-only as the default. Writable sharing requires explicit authorization for the exact source and destination.
Change requirements
- Fail closed on missing or incompatible dependencies.
- Preserve structured, bounded error output and observable lifecycle state.
- Keep repository paths relative and never commit machine-specific paths, Sandbox IDs, screenshots, logs, or credentials.
- Update
README.md, plugin metadata, Marketplace metadata, tests, and this file when product scope or distribution changes. - Increment the strict semantic version in
.codex-plugin/plugin.jsonfor releases.
Validation
Run focused checks before committing:
python scripts/validate_release.py
python -m unittest discover \
-s plugins/windows-sandbox-computer-use/skills/windows-sandbox-computer-use/tests \
-p 'test_*.py' \
-v
npx skills add . --list
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 46 lines · 318 tokens per session scan A df6f8bfc43d9
windows-sandbox-computer-use AGENTS.md is an instructions file published in the GitHub repository 2018wzh/windows-sandbox-computer-use (2 stars, last pushed 8d ago), licensed MIT. It adds 318 tokens to every session, about $0.0016 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
arcbox CLAUDE.md
Claude Code instructions for arcboxlabs/arcbox, covering repository guidelines for coding agents, project overview, performance targets, platform priority and project structure.
arcbox copilot-instructions.md
Copilot instructions for arcboxlabs/arcbox, covering arcbox ai agent instructions, architecture overview, critical platform differences, development workflows and required once.
Upsonic CLAUDE.md
Claude Code instructions for Upsonic/Upsonic, covering claude.md, project overview, ai operational guides, default pre-work consultation and keep documents/ai/explanation/ in sync with code.
SmolVM AGENTS.md
Instructions for CelestoAI/SmolVM, covering smolvm context, 🚀 project overview, 🧪 development, key commands and release checklist.
open-codex-computer-use AGENTS.md
AGENTS.md instructions for iFurySt/open-codex-computer-use, covering open-codex-computer-use, 每轮开始先读, 代码改完前要读, 按任务需要选读 and 工作规则.
pi AGENTS.md
AGENTS.md instructions for TGYD-helige/pi, covering pi extensions monorepo — agent guidelines, project overview, required agent skills, ponytail — minimal-code discipline and mattpocock/skills — engineering workflow skills.