Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/wecode-ai/wegent/sandboxnpx skills add wecode-ai/Wegent --skill sandboxgit clone --depth 1 https://github.com/wecode-ai/WegentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/wecode-ai/wegent/sandbox)<a href="https://agentmods.dev/skills/wecode-ai/wegent/sandbox"><img src="https://agentmods.dev/badge/skills/wecode-ai/wegent/sandbox.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00060 | $0.03759 |
| Opus 5 | $0.00030 | $0.01879 |
| Sonnet 5 | $0.00012 | $0.00752 |
| Haiku 4.5 | $0.00006 | $0.00376 |
Grade C, and why
sandbox scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
| Create/delete directories | `exec` | Use `mkdir -p` or `rm -rf` directly | How it starts
The opening of the file, as written. The whole thing — 538 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Sandbox Environment
Execute code, commands, and complex tasks securely in isolated Docker containers running AlmaLinux 9.4.
Core Capabilities
The sandbox environment provides fully isolated execution spaces with:
- Command Execution - Run shell commands, scripts, and programs
- File Operations - Read/write files, browse directories, manage filesystems
- Code Execution - Safely execute and test code
- Claude AI Tasks - Available for advanced use cases when explicitly requested by users
- Attachment Upload/Download - Upload generated files to Wegent for user download, or download user attachments for processing
When to Use
Use this skill when you need to:
- ✅ Execute shell commands or scripts
- ✅ Run and test code
- ✅ Read, write, or manage files
- ✅ Perform multi-step programming tasks
- ✅ Git operations (clone, commit, push, etc.)
- ✅ Require isolated environment for safety
Note: The sub_claude_agent tool should only be used when the user explicitly requests Claude AI assistance (e.g., "use Claude to generate...", "ask Claude to create...").
Available Tools
Command Execution
exec
Execute shell commands in the sandbox environment.
Use Cases:
- Run single commands or scripts
- Directory operations (create, delete, move)
- Install dependencies, run tests
- View system information
Parameters:
command(required): Shell command to executeworking_dir(optional): Working directory pathtimeout(optional): Timeout in seconds
Example:
{
"name": "exec",
"arguments": {
"command": "python script.py --arg value",
"working_dir": "/home/user/project"
}
}
sub_claude_agent
Run Claude AI to execute complex tasks in the sandbox.
⚠️ IMPORTANT: This tool should only be used when the user explicitly requests it. Do not use this tool automatically or as a default option.
Use Cases:
- When user explicitly asks to use Claude (e.g., "use Claude to generate...", "ask Claude to create...")
- Generate presentations and Word documents (when specifically requested)
- Create code projects (when specifically requested)
- Complex multi-step programming tasks (when specifically requested)
What ships with it
10 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- __init__.py 390 B runs code
- _base.py 686 B runs code
- claude_tool.py 13 KB runs code
- command_tool.py 11 KB runs code
- download_attachment_tool.py 14 KB runs code
- list_files_tool.py 7.3 KB runs code
- provider.py 7.1 KB runs code
- read_file_tool.py 9.2 KB runs code
- upload_attachment_tool.py 14 KB runs code
- write_file_tool.py 10 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 538 lines · 60 tokens per session scan C e15708d03a08
sandbox is a skill published in the GitHub repository wecode-ai/Wegent (776 stars, last pushed today), licensed Apache-2.0. It adds 60 tokens to every session and 3,759 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it C with 1 finding (recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
git-github-workflow
处理基于 git 和 GitHub 的真实协作工作流。当任务涉及仓库同步、分支管理、修复 bug、提交代码、创建或更新 PR、处理 review、解决冲突、检查 GitHub 认证与权限、或需要通过 fork 与用户仓库协作时使用,强调安全、干净、可审计的协作流程。必须在需要时使用该 Skill 并严格遵守相关规范!!!
skill-creator
创建新的 Claude Code 技能,修改和优化已有技能。当用户想从头创建技能、将当前工作流封装为技能、优化已有技能的内容或触发描述时使用此技能。即使用户没有明确说"技能",当他们想把某个重复工作流程固定下来时也应使用。.
agent-browser
使用此技能进行浏览器自动化操作,包括网页抓取、表单填写、UI 测试和任何 Web 交互任务。.
contribute-to-eliza
Finish and prove a scoped elizaOS GitHub issue, or independently review and repair an open elizaOS pull request. Use when contributing compute to elizaOS by selecting unclaimed work, implementing or reviewing changes, adding real tests and evidence, validating artifacts, or preparing a contribution for maintainer…
build-monetized-app
Use when the task is building a new app on Eliza Cloud that earns money — chat apps, agent apps, MCP-backed tools, anything that calls the cloud's chat/messages/inference endpoints on behalf of users. Covers app registration, container deploy, markup configuration, affiliate header, app charge requests, x402 payment…
discord
Use when you need to control Discord from Otto via the discord tool: send messages, react, post or upload stickers, upload emojis, run polls, manage threads/pins/search, create/edit/delete channels and categories, fetch permissions or member/role/channel info, set bot presence/activity, or handle moderation actions in…