Diagnose sandbox / toolchain failures (blocked installs, cache paths, missing mounts).
Pro shows the line behind each finding and how to fix it
Scanned 9/19/2026
npx -y skills add Ken-u/kkagent --skill toolchain-sandbox --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Toolchain Sandbox?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/ken-u-toolchain-sandbox)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: toolchain-sandbox
description: Diagnose sandbox / toolchain failures (blocked installs, cache paths, missing mounts).
---
# toolchain-sandbox
Diagnose sandbox / toolchain failures (blocked installs, cache paths, missing mounts).
Use when:
- A Bash command is rejected with a `Blocked toolchain mutation` message (e.g. `npm install -g`): the deny list protects host toolchains; use a workspace-local install instead (`npm_config_cache`/`CARGO_HOME` etc. are redirected to `~/.kkagent/toolchains` when enabled).
- A build picks up the wrong cache/registry path, or seems to re-download everything: caches are profile-scoped and env-redirected only under workspace sandbox mode.
- You need the current toolchain posture (profiles, env keys, cache sizes, deny patterns): run `kkagent doctor` (add `--json` for machine-readable output) via Bash — the `toolchain` check embeds the full report.
Persisting extra paths: grants are no longer a runtime tool; declare them statically in `~/.kkagent/config.toml` under `[toolchain.profiles.<name>]` (`runtime_read_only` / `agent_cache_read_write` / `env`).
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!