Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Quickstart

FSecurity

zerobox is a lightweight, cross-platform process sandboxing tool with file, network, and credential controls. Run commands safely with granular permissions.

54 stars
0 votes
0 copies
1 views
Added 9/6/2026
toolsgobashnodegitapi

Works with

cliapi

Security Analysis

F30/100
criticalPipes output to a shell interpreter
mediumUses curl or wget to download content
criticalDownloads and executes remote scripts — classic supply chain attack
mediumInstalls packages at runtime which could introduce malicious dependencies
mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned 9/6/2026

$npx -y skills add javimosch/supercli --skill quickstart --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Quickstart?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Quickstart
[![Security: F — Skills Directory](https://www.skillsdirectory.com/api/skills/javimosch-quickstart-826ecfef/badge)](https://www.skillsdirectory.com/skills/javimosch-quickstart-826ecfef)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
# zerobox - Process Sandbox

## Overview
zerobox is a lightweight, cross-platform process sandboxing tool with file, network, and credential controls. Run commands safely with granular permissions.

## Quick Start

### Run command with no writes or network
```bash
sc zerobox run command "node -e \"console.log('hello')\""
```

### Allow writes to specific directory
```bash
sc zerobox run command --allow-write=. "npm install"
```

### List filesystem snapshots
```bash
sc zerobox snapshot list
```

### Passthrough to zerobox CLI
```bash
sc zerobox _ <zerobox-args>
```

## Key Features

- **File Controls**: Allow/deny file and directory writes
- **Network Controls**: Restrict network access to specific domains
- **Credential Management**: Pass secrets securely without exposing them to the sandbox
- **Snapshot & Restore**: Record filesystem changes and undo them
- **Environment Control**: Control which environment variables are passed
- **Cross-Platform**: Works on Linux, macOS, and Windows

## Installation

```bash
cargo install zerobox
```

Or via package managers:
- npm: `npm install -g zerobox`
- pip: `pip install zerobox`
- curl: `curl -fsSL https://raw.githubusercontent.com/afshinm/zerobox/main/install.sh | sh`

## Usage Examples

### Basic sandboxing
```bash
zerobox -- node script.js
```

### Allow specific directory writes
```bash
zerobox --allow-write=./build -- npm run build
```

### Allow network to specific domain
```bash
zerobox --allow-net=api.openai.com -- node agent.js
```

### Pass secrets securely
```bash
zerobox --secret OPENAI_API_KEY=sk-proj-123 --secret-host OPENAI_API_KEY=api.openai.com -- node app.js
```

### Record and restore filesystem changes
```bash
zerobox --snapshot --allow-write=. -- npm install
zerobox snapshot restore <session-id>
```

## Notes

- Secrets are passed as placeholders and substituted at the network proxy level
- Use `--allow-env` to pass all parent environment variables
- Use `--deny-env` to block specific environment variables
- Snapshots can be inspected and restored later

Attribution

javimoschjavimosch
View sourceSee grades on GitHubMore from javimosch →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

ucoz-landing-skill

Create and edit uCoz homepage landing pages via MCP: custom templates, hero sections, lead forms, navigation menus, SEO, and responsive layout. Includes a visual design system (style selection, layout/grid, section recipes, typography/spacing, color tokens, component states, icons, modern CSS/JS, motion, imagery, social proof, copy/voice, accessibility). Uses ucoz-mcp tools for templates, site file uploads, and site modules.

107 votes

Paperclip

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

953191 votes

Pptx

Presentation toolkit (.pptx). Create/edit slides, layouts, content, speaker notes, comments, for programmatic presentation creation and modification.

471861 votes

Daw Music

Digital Audio Workstation usage, music composition, interactive music systems, and game audio implementation for immersive soundscapes.

761 votes

Instantly Rdsthomas Mission Control

Instantly.ai cold email outreach API - manage campaigns, leads, accounts, and analytics. Use for cold email automation, lead management, campaign creation/monitoring, and email account warmup.

761 votes
View all in tools →