Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add The-Biomechanist/Windows-Dev-Agent --skill sandbox-rungit clone --depth 1 https://github.com/The-Biomechanist/Windows-Dev-AgentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/the-biomechanist/windows-dev-agent/sandbox-run)<a href="https://agentmods.dev/skills/the-biomechanist/windows-dev-agent/sandbox-run"><img src="https://agentmods.dev/badge/skills/the-biomechanist/windows-dev-agent/sandbox-run/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/the-biomechanist/windows-dev-agent/sandbox-run"><img src="https://agentmods.dev/badge/skills/the-biomechanist/windows-dev-agent/sandbox-run.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00035 | $0.00784 |
| Opus 5 | $0.00017 | $0.00392 |
| Sonnet 5 | $0.00007 | $0.00157 |
| Haiku 4.5 | $0.00003 | $0.00078 |
Grade A, and why
sandbox-run scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 38 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Sandbox Run
Choose the boundary from the task's required property, not from whichever backend happens to be installed first.
Routing
| Requirement | isolation_requirement |
Auto route | Boundary |
|---|---|---|---|
| Linux-native compatibility or a low-risk Linux execution surface | linux_compatibility |
WSL | Interoperable Linux environment; not hostile-code containment from the Windows host. |
| Reproduce the project's declared devcontainer environment | project_reproducibility |
Dev Container | Requires the devcontainer CLI and project devcontainer configuration. |
| Run an untrusted Windows artifact away from the host | untrusted_windows |
Windows Sandbox | Disposable Windows VM with networking and clipboard disabled; the selected workload must be staged explicitly. |
environment: auto is legal only when isolation_requirement is supplied. For untrusted_windows, also supply one or more workspace-relative payload_paths; the runtime refuses an auto-routed hostile-workload plan that would launch a sandbox without the workload inside it.
Procedure
- Establish the property the boundary must provide. Do not silently substitute Linux compatibility for hostile-Windows containment.
- Inspect relevant backend availability with
env_inspectwhen it is not already established. Treatnull/unknown availability as unresolved rather than missing. - For WSL or Dev Container work, use the active project as
workspace_folder. WSL execution enters that Windows project directory through WSL's--cdboundary and usessh -lc; a task requiring Bash-specific semantics should request Bash explicitly. - For Windows Sandbox, identify exactly which project files/directories the isolated command needs and pass them as workspace-relative
payload_paths. Every selected path component and every traversed child must remain an ordinary workspace path: symbolic links and NTFS reparse points such as junctions are rejected before traversal crosses them, and failure to establish that metadata blocks staging rather than being treated as safe. Overlapping selections are rejected, and staged input is limited to 10,000 filesystem entries and 1 GiB total file bytes. Write the inner command relative to the staged payload root (C:\WDAShare\payload). - Call
sandbox_runwithexecute: falseand inspect the selected route, payload list, and launch plan. Planning must not create the temporary bundle or launch the workload. In Codex, a trustedPermissionRequesthook may auto-allow this plan-only request; without trusted hooks, the host may prompt for the plan. - To launch, call the same reviewed tool with
execute: true. The active host decides whether that exact call proceeds; do not invent a second approval token. - For WSL and Dev Container runs, use captured return code/stdout/stderr only for what they establish. For Windows Sandbox, report only that the interactive sandbox launched; the inner command remains
unknownuntil an observation from inside the sandbox establishes its outcome. - An executed Windows Sandbox launch returns
cleanup_path. Remove the temporary bundle only after the sandbox no longer needs it. If staging or process launch fails before the Sandbox starts, the runtime removes the partial bundle itself.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 38 lines · 35 tokens per session scan A de8b258f145b
sandbox-run is a skill published in the GitHub repository The-Biomechanist/Windows-Dev-Agent (0 stars, last pushed 10d ago), licensed MIT. It adds 35 tokens to every session and 784 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
cost-efficiency-analyzer
Analyzes cost structure, cost efficiency, and expense management from P&L data. Use when the user asks about costs, expenses, COGS, operating expenses, cost ratios, cost control, spending efficiency, margin compression from cost side, or wants to understand where money is going. Also use for "are we spending too…
multi-quarter-trend-analysis
Analyzes financial trends across multiple quarters by comparing P&L metrics over time. Use when the user wants to see trends, patterns, trajectories, or directional movement across 3 or more quarters. Also use for "how are we trending", "show me the trend", "track performance over time", "quarter over quarter…
executive-financial-briefing
Generates a concise executive-level financial briefing or summary suitable for a CEO, CFO, or board presentation. Use when the user asks for a summary, briefing, executive summary, board update, financial overview, financial health check, or "how is the business doing". Covers the full P&L picture in one page. Also…
babysit
Same-session monitoring loop for PRs, CI runs, tickets, and deployments using the monitorstart / monitorupdate / autonudgestop MCP tools. The loop re-injects your check instructions into THIS session on an idle interval — same context, same tools — and works from dashboard chat, Slack threads, and Discord DMs. Use…
sector-rotation
Identify which market sectors to overweight or underweight based on current macro conditions and sector performance data.
trend-analysis
Analyze price and volume trends for one or more stocks to determine momentum direction and key technical levels.