Borrowing it
Nothing to install: this file belongs to mtarcure/claude-vibe-squad. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/mtarcure/claude-vibe-squad/main/.agents/skills/sandbox-provision-discipline/SKILL.mdgit clone --depth 1 https://github.com/mtarcure/claude-vibe-squadWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mtarcure/claude-vibe-squad/sandbox-provision-discipline)<a href="https://agentmods.dev/skills/mtarcure/claude-vibe-squad/sandbox-provision-discipline"><img src="https://agentmods.dev/badge/skills/mtarcure/claude-vibe-squad/sandbox-provision-discipline/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/mtarcure/claude-vibe-squad/sandbox-provision-discipline"><img src="https://agentmods.dev/badge/skills/mtarcure/claude-vibe-squad/sandbox-provision-discipline.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00045 | $0.00439 |
| Opus 5 | $0.00023 | $0.00219 |
| Sonnet 5 | $0.00009 | $0.00088 |
| Haiku 4.5 | $0.00005 | $0.00044 |
Grade A, and why
sandbox-provision-discipline scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Sandbox Provision Discipline
Use this skill before provisioning or using Docker, a VM, Kubernetes, or any other environment for exploit PoCs, untrusted binaries, fuzzing, or tests that could reach systems beyond the authorized target.
Preflight gate
Record all of the following before execution:
- The task's explicit authorization and exact target scope.
- The isolation boundary and whether it is dedicated or shared.
- Network policy: deny egress by default; enumerate any approved destination.
- Credential policy: inject no production or unrelated credentials.
- Filesystem policy: expose only required inputs; keep outputs in the packet's write scope; declare persistence and retention in advance.
- Resource limits for CPU, memory, process count, time, and storage.
- A harmless containment check showing the sandbox cannot reach an unapproved host, credential source, or host path.
If any item is unknown or cannot be verified, stop before payload execution
and report needs_human plus the missing guarantee. Do not weaken isolation to
make a test pass.
Execution discipline
- Use disposable, uniquely labeled resources tied to the task ID.
- Keep host mounts read-only unless a specific write is required and approved.
- Capture the sandbox definition, tool versions, limits, containment-check result, and test timestamps without logging secret values.
- Never redirect a failed local test to a live target or another tenant.
- Treat unexpected egress, host access, or cross-tenant data as a hard stop.
Cleanup and handoff
State the cleanup procedure and rollback before execution. Perform deletion or destructive cleanup only when the governing task explicitly authorizes it. Otherwise leave resources stopped, identify them precisely, and request operator action. Report residual processes, mounts, volumes, network rules, artifacts, and secrets even when the test succeeds.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago Changed · +1 lines d1ce631441de
- 8d ago First seen · 46 lines · 45 tokens per session scan A 54e7e82ce3f0
sandbox-provision-discipline is a skill published in the GitHub repository mtarcure/claude-vibe-squad (148 stars, last pushed 2d ago), licensed MIT. It adds 45 tokens to every session and 439 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
gh-find-prs
Survey open Codewhale PRs and triage each for mergeability and disposition against the real landing branch.
contributor-onboarding
Help a new contributor get productive on this checkout - inspect sync state against main, build, run the repository's exact verification gate, and produce a local what's-new digest. Never fetches, pulls, or modifies a dirty tree on its own. Explicit-only.
codew-release-qa-sweep
Use before claiming Codewhale release work is done: run the full gate sweep and list the manual QA targets.
gh-file-issue
Use when filing a new Codewhale GitHub issue: turn a bug or idea into a well-formed, actionable issue with repro, acceptance criteria, labels, and milestone.
gh-treasure-hunt
Hunt the issue/PR queue for highest value-over-risk wins: clean focused community PRs, already-implemented issues to close, safe quick-fixes.
recording
Capture screenshots on registered computers, record on macOS or HarmonyOS, and manage saved captures. Probe capabilities before recording.