Load when a member asks to run or repair a supplied script, inspect or change files in /workspace, build or diagnose a project, execute a workspace command, or use `ufo llm` or `ufo tool`. Do not load for an unexecuted snippet.
Scanned 9/28/2026
Install to Claude Code
npx -y skills add ufo-ai/ufo-core --skill sandbox --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Sandbox?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/ufo-ai-sandbox)More formats (shields.io, HTML) on the badges page.
---
name: sandbox
description: Load when a member asks to run or repair a supplied script, inspect or change files in /workspace, build or diagnose a project, execute a workspace command, or use `ufo llm` or `ufo tool`. Do not load for an unexecuted snippet.
metadata:
tools:
- bash
- read
- write
- edit
- share_file
---
# Working in the sandbox
Every command and file operation runs in a disposable container that belongs to a conversation — a
subagent turn runs in the container of the turn that spawned it. The one writable tree is
`/workspace`; it is the durable truth — it survives across turns while the container itself is cache
that may be rebuilt between turns. Anything outside `/workspace` is off limits.
## Building up work
- Keep intermediate artifacts as files under `/workspace` with descriptive names, not in your head.
A later turn (and a subagent sharing this workspace) reads them back.
- Use `bash` for anything a shell does — installing a package, running a script, inspecting output.
Long pipelines belong in a saved script you run, not one giant command.
- Read a file before you `edit` it: an edit replaces one unique occurrence, so if the old string
is not unique, read more context and widen it until it is.
## Calling tools from programs
A program or shell pipeline cannot call your model tools directly. Use these installed CLIs at that
boundary. When the request names this interface, invoke it; never fabricate its output or replace a
bridge call with the corresponding direct tool.
- One prompt-to-text Anthropic model call: `ufo llm [--model MODEL] [--max-tokens N] 'PROMPT'`.
stdout is the response text. This is turn-time generation, not a website runtime API.
- Object or connector tool: run `ufo tool --list` for the names and descriptions available to this
agent, then run `ufo tool TOOL --describe` for the chosen input schema. Pipe one JSON object to
the call, including every schema-required field: `printf '%s' '{"kind":"agent"}' | ufo tool object_list`. Every response is one JSON stdout envelope:
`{"ok":true,"result":...}` or `{"ok":false,"error":"..."}`; failure exits nonzero. Only listed
tools are callable.
## Handing a result back
A file reaches the user through a Markdown link in the closing message or through `share_file`,
which returns a time-limited download link. A plain `/workspace` path does not deliver it. Save the
finished artifact, then share the exact path only when the ask carries a
share trigger from the delivery register: the user asked for a file, a document, or a format, or for
a copy of the write-up or a new revision of a file you already shared.
A verb alone is not a trigger — "send", "give me", and "write up" name the delivery, so answer inline
and link the file as `[name](/workspace/name)` in the closing message. Without `share_file` in your
tool set, the workspace is the handoff: name the path in your result, and the parent carries it.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!