Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add modelstudioai/cli --skill bailian-sandboxgit clone --depth 1 https://github.com/modelstudioai/cliWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/modelstudioai/cli/bailian-sandbox)<a href="https://agentmods.dev/skills/modelstudioai/cli/bailian-sandbox"><img src="https://agentmods.dev/badge/skills/modelstudioai/cli/bailian-sandbox/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/modelstudioai/cli/bailian-sandbox"><img src="https://agentmods.dev/badge/skills/modelstudioai/cli/bailian-sandbox.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00177 | $0.01904 |
| Opus 5.5 | $0.00071 | $0.00762 |
| Sonnet 5 | $0.00035 | $0.00381 |
| Haiku 4.5 | $0.00018 | $0.00190 |
Grade A, and why
bailian-sandbox scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 76 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Bailian Sandbox (bl sandbox)
Before running bl, read the shared bailian-protocol for consent, high-risk confirmation, version checks, authentication, and error handling. If it is missing, stop execution and prompt the user to install the full family with bl skill init.
Scope and setup
- Manage Sandbox instances and templates through Bailian's E2B-compatible REST control plane. No E2B SDK or E2B API key is required; authentication uses the Bailian API Key as an Authorization Bearer token.
- Resolve Base URL through the same CLI chain as Managed Agent:
--base-url>DASHSCOPE_BASE_URL> login/profilebase_url. Use an origin such ashttps://workspace.cn-beijing.maas.aliyuncs.com; the CLI strips URL paths/query/fragment and appends/api/v1/agentstudio/sandboxfor lifecycle operations, or/api/v1/agentstudio/filesfor template file uploads. The saved API Key is reused. Profile capability fallback follows the shared protocol for both the key and Base URL. - If no Base URL is configured, resolve the workspace from
--workspace-id, thenBAILIAN_WORKSPACE_ID, then configuredworkspace_id, and usehttps://{workspace_id}.cn-beijing.maas.aliyuncs.com/api/v1/agentstudio/sandbox. With a configured Base URL, the workspace flag is optional. The service currently supportscn-beijingand requires prior Sandbox SLR authorization. - No
agents.yamlor local IaC state is required.get/connectreturn instance connection information; neither opens an interactive shell or browser. For WebShell, CDP, or VNC, use that information with the runtime APIs described below. Do not inventbl sandbox exec,webshell, or browser subcommands.
Choose the operation
| User intent | Command family |
|---|---|
| Discover built-in base image presets | bl sandbox official-images (offline, no authentication) |
| Upload a local file for template mounts | bl sandbox file upload |
| Inspect or create instances | bl sandbox list / get / create |
| Connect, pause, or resume an instance | bl sandbox connect / pause / resume |
| Release an instance | bl sandbox delete |
| Inspect or build templates | bl sandbox template list / get / create / update |
| Check a submitted template build | bl sandbox template build-status |
| Delete a template | bl sandbox template delete |
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed a0e92aafb99d
- 2d ago Changed 0b8d1aa4441d
- 4d ago Changed 507e0f408762
- 5d ago Changed 70de08303d05
- 8d ago Changed 5ed38b87ff42
- 11d ago First seen · 76 lines · 177 tokens per session scan A f3f3b2d03067
bailian-sandbox is a skill published in the GitHub repository modelstudioai/cli (335 stars, last pushed yesterday), licensed Apache-2.0. It adds 177 tokens to every session and 1,904 once invoked, about $0.0007 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-12.
Other skills, from other repositories
zeabur-cluster-scale
A guide for changing the size of dedicated Kubernetes clusters on Zeabur. Kubernetes is software that runs containers across groups of servers.
zeabur-server-ssh
Use when debugging services on a user's dedicated server via SSH. Use when needing to run a command on the server, inspect pods, check container logs, view k8s resources, or run kubectl commands. Use when "service exec" is insufficient and you need server-level access. Use when user says "check my server", "run X on…
zeabur-dockerfile
Use when generating a Dockerfile for deploying a project to Zeabur. Use when the user needs help writing a Dockerfile for Node.js, Python, Go, Rust, PHP, Ruby, Java, .NET, or Elixir projects. Use when troubleshooting Dockerfile build failures on Zeabur.
build-mcpb
This skill should be used when the user wants to "package an MCP server", "bundle an MCP", "make an MCPB", "ship a local MCP server", "distribute a local MCP", discusses ".mcpb files", mentions bundling a Node or Python runtime with their MCP server, or needs an MCP server that interacts with the local filesystem…
obsidian-bases
Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries. Use when working with .base files, creating database-like views of notes, or when the user mentions Bases, table views, card views, filters, or formulas in Obsidian.
officecli
Create, analyze, proofread, and modify Office documents (.docx, .xlsx, .pptx) using the officecli CLI tool. Use when the user wants to create, inspect, check formatting, find issues, add charts, or modify Office documents.