sandbox skillB
sandbox is agent-read markdown (skill) from jakeselby/agent-harness: Fence an autonomous or long-running agent loop: the built-in sandbox with network off, or a container with the worktree mounted. Use before any unattended loop, before `execute` autonomy on an unfamiliar repo, and whenever a task pulls untrusted input..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Fence the loop A permission mode decides whether a call runs. A sandbox decides what a command can reach once it is running, and the OS enforces that on every child process. An unattended loop needs the second kind: nobody is at the prompt to answer for the first. ## Runtime scope The configuration and container example below are Claude Code-specific. Do not copy those settings into Codex. For Codex, use its native sandbox and approval controls as documented in [the configuration reference](https://learn.chatgpt.com/docs/config-file/config-reference). A read-only sandbox constrains filesystem writes; approval policy is a separate control. Native hooks are not a replacement for OS confinement. Custom Codex role defaults can be superseded by the parent turn's permissions; see `docs/runtime-controls.md` before delegating work that requires a hard boundary. Client qualification remains in the compatibility catalog. ## The Claude Code sandbox It "runs on macOS, Linux, and WSL2. Native Windows is not supported"; Linux and WSL2 need `bubblewrap` and `socat` installed first. Put this in `~/.claude/settings.json` to cover every …
Read the whole file at its exact version.
How to install
mdr add jakeselby/agent-harness/sandbox@git:20260923.097bdb0mdr add jakeselby/agent-harness/sandbox@sha256:5645a919019a716bPin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_c74gwzohxrdkb7e4)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260923.097bdb0 latest | 2026-09-23 | 097bdb0 | 4,395 B | B | view · diff |
| git:20260919.04aa2b5 | 2026-09-19 | 04aa2b5 | 4,432 B | B | view · diff |
| git:20260919.6cf18f7 | 2026-09-19 | 6cf18f7 | 3,767 B | B | view |
Audit of the latest version
- fail: No instruction to read or print local credentials (matched: Read": ["~/.ssh", "~/.aws)
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (4395 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
jakeselby/agent-harness · 17 stars · license MIT · pushed 2026-09-25 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_c74gwzohxrdkb7e4 GET https://markdownregistry.com/api/v1/resolve?ref=jakeselby/agent-harness/sandbox GET https://markdownregistry.com/api/v1/blob/5645a919019a716b33675f97d55b73e22ae12e36b4cea4c9f1f985d4b970bd69
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
More from jakeselby/agent-harness
Every file in jakeselby/agent-harness