Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Sandbox

ASecurity

Load when a member asks to run or repair a supplied script, inspect or change files in /workspace, build or diagnose a project, execute a workspace command, or use `ufo llm` or `ufo tool`. Do not load for an unexecuted snippet.

60 stars
0 votes
0 copies
0 views
Added 9/28/2026
ai-agentsshellbashapi

Works with

cliapi

Security Analysis

A100/100

Scanned 9/28/2026

Install to Claude Code

$npx -y skills add ufo-ai/ufo-core --skill sandbox --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Sandbox?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Sandbox
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ufo-ai-sandbox/badge)](https://www.skillsdirectory.com/skills/ufo-ai-sandbox)

More formats (shields.io, HTML) on the badges page.

Files
SKILL.md
---
name: sandbox
description: Load when a member asks to run or repair a supplied script, inspect or change files in /workspace, build or diagnose a project, execute a workspace command, or use `ufo llm` or `ufo tool`. Do not load for an unexecuted snippet.
metadata:
  tools:
  - bash
  - read
  - write
  - edit
  - share_file
---
# Working in the sandbox

Every command and file operation runs in a disposable container that belongs to a conversation — a
subagent turn runs in the container of the turn that spawned it. The one writable tree is
`/workspace`; it is the durable truth — it survives across turns while the container itself is cache
that may be rebuilt between turns. Anything outside `/workspace` is off limits.

## Building up work

- Keep intermediate artifacts as files under `/workspace` with descriptive names, not in your head.
  A later turn (and a subagent sharing this workspace) reads them back.
- Use `bash` for anything a shell does — installing a package, running a script, inspecting output.
  Long pipelines belong in a saved script you run, not one giant command.
- Read a file before you `edit` it: an edit replaces one unique occurrence, so if the old string
  is not unique, read more context and widen it until it is.

## Calling tools from programs

A program or shell pipeline cannot call your model tools directly. Use these installed CLIs at that
boundary. When the request names this interface, invoke it; never fabricate its output or replace a
bridge call with the corresponding direct tool.

- One prompt-to-text Anthropic model call: `ufo llm [--model MODEL] [--max-tokens N] 'PROMPT'`.
  stdout is the response text. This is turn-time generation, not a website runtime API.
- Object or connector tool: run `ufo tool --list` for the names and descriptions available to this
  agent, then run `ufo tool TOOL --describe` for the chosen input schema. Pipe one JSON object to
  the call, including every schema-required field: `printf '%s' '{"kind":"agent"}' | ufo tool object_list`. Every response is one JSON stdout envelope:
  `{"ok":true,"result":...}` or `{"ok":false,"error":"..."}`; failure exits nonzero. Only listed
  tools are callable.

## Handing a result back

A file reaches the user through a Markdown link in the closing message or through `share_file`,
which returns a time-limited download link. A plain `/workspace` path does not deliver it. Save the
finished artifact, then share the exact path only when the ask carries a
share trigger from the delivery register: the user asked for a file, a document, or a format, or for
a copy of the write-up or a new revision of a file you already shared.
A verb alone is not a trigger — "send", "give me", and "write up" name the delivery, so answer inline
and link the file as `[name](/workspace/name)` in the closing message. Without `share_file` in your
tool set, the workspace is the handoff: name the path in your result, and the parent carries it.

Attribution

ufo-aiufo-ai
View sourceMore from ufo-ai →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

695601 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →