Best for
- ✅ Execute shell commands or scripts
- ✅ Run and test code
- ✅ Read, write, or manage files
wecode-ai/Wegent/backend/init_data/skills/sandbox/SKILL.md
Provides read_file/write_file/exec/list_files/read_file/write_file for running process and managing filesystems in the sandbox. Ideal for code testing, file management, and command execution. The sub_claude_agent tool is available for advanced use cases. You MUST load this skill BEFORE use sandbox tools.
Decision brief
Execute code, commands, and complex tasks securely in isolated Docker containers running AlmaLinux 9.4.
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/wecode-ai/Wegent --skill "backend/init_data/skills/sandbox"Inspect the Agent Skill "sandbox" from https://github.com/wecode-ai/Wegent/blob/aa89ef88ea199e10f364827eaedf8cd7c9bd1157/backend/init_data/skills/sandbox/SKILL.md at commit aa89ef88ea199e10f364827eaedf8cd7c9bd1157. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
⚠️ zip is not pre-installed. Always run dnf install -y zip before using it.
The sandbox environment provides fully isolated execution spaces with:
Use this skill when you need to:
Execute shell commands in the sandbox environment.
Execute shell commands in the sandbox environment.
Permission review
The documentation asks the agent to run terminal commands or scripts.
**Command Execution** - Run shell commands, scripts, and programsThe documentation asks the agent to run terminal commands or scripts.
✅ Execute shell commands or scriptsThe documentation asks the agent to read local files, directories, or repositories.
Read file contents.The documentation asks the agent to create, modify, or delete local files.
Write content to a file.The documentation includes network, browsing, or remote request actions.
Upload a file from sandbox to Wegent and get a download URL for users.The documentation asks the agent to read local files, directories, or repositories.
User can not access file directly, you MUST use upload_attachment tool for sending file to user.The documentation includes network, browsing, or remote request actions.
[Click to Download](/api/attachments/123/download)The documentation asks the agent to create, modify, or delete local files.
| Write files | `write_file` | Auto directory creation, size validation |Evidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 91/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 713 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Execute code, commands, and complex tasks securely in isolated Docker containers running AlmaLinux 9.4.
The sandbox environment provides fully isolated execution spaces with:
Use this skill when you need to:
Note: The sub_claude_agent tool should only be used when the user explicitly requests Claude AI assistance (e.g., "use Claude to generate...", "ask Claude to create...").
execExecute shell commands in the sandbox environment.
Use Cases:
Parameters:
command (required): Shell command to executeworking_dir (optional): Working directory pathtimeout (optional): Timeout in secondsExample:
{
"name": "exec",
"arguments": {
"command": "python script.py --arg value",
"working_dir": "/home/user/project"
}
}
sub_claude_agentRun Claude AI to execute complex tasks in the sandbox.
⚠️ IMPORTANT: This tool should only be used when the user explicitly requests it. Do not use this tool automatically or as a default option.
Use Cases:
Parameters:
prompt (required): Task description for Claudeallowed_tools (optional): List of tools Claude can useappend_system_prompt (optional): Additional system prompttimeout (optional): Timeout in seconds (minimum: 600 seconds / 10 minutes, default: 1800 seconds / 30 minutes)Features:
Example:
{
"name": "sub_claude_agent",
"arguments": {
"prompt": "Create a 5-page presentation about the history of artificial intelligence",
"allowed_tools": "Edit,Write,Bash(*),skills,Read"
}
}
list_filesList files and subdirectories in a directory.
Parameters:
path (required): Directory pathdepth (optional): Recursion depth, default 1Returns:
Example:
{
"name": "list_files",
"arguments": {
"path": "/home/user/project",
"depth": 2
}
}
read_fileRead file contents.
Parameters:
file_path (required): File path to readLimits:
Example:
{
"name": "read_file",
"arguments": {
"file_path": "/home/user/config.json"
}
}
write_fileWrite content to a file.
⚠️ IMPORTANT: Both file_path AND content are REQUIRED parameters. You must always provide the content to write.
Parameters:
file_path (REQUIRED): File path to writecontent (REQUIRED): Content to write (MUST be provided, cannot be omitted)format (optional): Content format - 'text' (default) or 'bytes' (base64-encoded)create_dirs (optional): Auto-create parent directories (default: True)Features:
Example - Text file:
{
"name": "write_file",
"arguments": {
"file_path": "/home/user/output.txt",
"content": "Hello, Sandbox!"
}
}
Example - HTML file:
{
"name": "write_file",
"arguments": {
"file_path": "/home/user/index.html",
"content": "<!DOCTYPE html><html><head><title>Test</title></head><body><h1>Hello</h1></body></html>"
}
}
upload_attachmentUpload a file from sandbox to Wegent and get a download URL for users.
Use Cases:
Parameters:
file_path (required): Path to the file in sandbox to uploadtimeout_seconds (optional): Upload timeout in seconds (default: 300)Returns:
success: Whether the upload succeededattachment_id: ID of the uploaded attachmentfilename: Name of the uploaded filefile_size: Size of the file in bytesmime_type: MIME type of the filedownload_url: Relative URL for downloading (e.g., /api/attachments/123/download)Limits:
Example:
{
"name": "upload_attachment",
"arguments": {
"file_path": "/home/user/documents/report.pdf"
}
}
After Upload - Presenting to User: After a successful upload, present the download link to the user:
Document generation completed!
📄 **report.pdf**
[Click to Download](/api/attachments/123/download)
download_attachmentDownload a file from Wegent attachment URL to sandbox for processing.
Use Cases:
Parameters:
attachment_url (required): Wegent attachment URL (e.g., /api/attachments/123/download)timeout_seconds (optional): Download timeout in seconds (default: 300)The tool resolves the attachment filename and owning subtask from Wegent, then
saves it to the canonical task attachment directory:
/home/user/{task_id}:executor:attachments/{subtask_id}/{filename}.
Returns:
success: Whether the download succeededfile_path: Full path to the downloaded file in sandboxfile_size: Size of the downloaded file in bytesExample:
{
"name": "download_attachment",
"arguments": {
"attachment_url": "/api/attachments/123/download"
}
}
| Task Type | Recommended Tool | Reason |
|---|---|---|
| Execute commands or scripts | exec | Fast execution, no overhead |
| Create/delete directories | exec | Use mkdir -p or rm -rf directly |
| Read files | read_file | Better error handling and size validation |
| Write files | write_file | Auto directory creation, size validation |
| Browse directories | list_files | Structured output with metadata |
| Upload files for user download | upload_attachment | Get download URL for user-facing files |
| Download attachments | download_attachment | Retrieve Wegent attachments into sandbox |
| Complex tasks with Claude | sub_claude_agent | Only when user explicitly requests |
Important: Always prefer exec for standard operations. Only use sub_claude_agent when the user specifically asks for Claude AI assistance.
{
"name": "exec",
"arguments": {
"command": "cd /home/user && python -m pip install requests && python app.py"
}
}
{
"name": "exec",
"arguments": {
"command": "dnf install -y gcc make && gcc --version"
}
}
// 1. List files
{
"name": "list_files",
"arguments": {
"path": "/home/user"
}
}
// 2. Read file
{
"name": "read_file",
"arguments": {
"file_path": "/home/user/data.json"
}
}
// 3. Write file
{
"name": "write_file",
"arguments": {
"file_path": "/home/user/result.txt",
"content": "Processing complete: Success"
}
}
{
"name": "exec",
"arguments": {
"command": "git clone https://github.com/user/repo.git && cd repo && git checkout -b feature"
}
}
⚠️ zip is not pre-installed. Always run dnf install -y zip before using it.
⚠️ Always use English or pinyin folder names as the ZIP root directory. The zip command does not set the ZIP UTF-8 flag, so Windows decodes Chinese names using CP437, resulting in garbled folders that appear empty.
// Step 1: Install zip
{
"name": "exec",
"arguments": {
"command": "dnf install -y zip"
}
}
// Step 2: Create ZIP with English folder name (recommended)
{
"name": "exec",
"arguments": {
"command": "zip -r 'my-skill.zip' 'my-skill/'"
}
}
If the user explicitly requires a Chinese folder name, use Python's zipfile module instead — it automatically sets the UTF-8 flag so Windows can decode Chinese names correctly:
{
"name": "exec",
"arguments": {
"command": "python3 -c \"\nimport zipfile, os\nfolder = '中文名称'\nwith zipfile.ZipFile(folder + '.zip', 'w', zipfile.ZIP_DEFLATED) as zf:\n for root, dirs, files in os.walk(folder):\n for f in files:\n zf.write(os.path.join(root, f))\n\""
}
}
Example user request: "Please use Claude to generate a presentation about AI"
{
"name": "sub_claude_agent",
"arguments": {
"prompt": "Create a 5-page presentation about the history of artificial intelligence"
}
}
Note: This scenario should only be used when the user explicitly asks for Claude assistance.
Control Claude's available tools via the allowed_tools parameter:
{
"allowed_tools": "Edit,Write,MultiEdit,Bash(*),skills,Read,Glob,Grep,LS"
}
Bash(*): Allow all Bash commandssuccess fieldsub_claude_agent when user explicitly requests Claude assistancezip first with dnf install -y zip; always use English/pinyin folder names for cross-platform compatibility; if Chinese names are required, use Python's zipfile module (it sets the UTF-8 flag correctly, preventing garbled names on Windows)Cause: Executor Manager unavailable Solution: Check service status and configuration
Cause: Incorrect path or file doesn't exist
Solution: Use absolute paths, verify with list_files first
Cause: Task execution takes too long Solution: Increase timeout setting or split into smaller tasks
Cause: Exceeds size limit (1MB read / 10MB write) Solution: Process in chunks or adjust configuration
Cause: Insufficient file permissions Solution: Check file paths and permission settings
Cause: The zip command stores filenames as raw bytes without setting the ZIP UTF-8 flag (bit 11). Windows decodes them using CP437, turning Chinese folder names into garbled text, making contents inaccessible.
Solution: Use English/pinyin folder names with the zip command. If Chinese names are required, use Python's zipfile module — it sets the UTF-8 flag automatically:
python3 -c "
import zipfile, os
folder = '中文名称'
with zipfile.ZipFile(folder + '.zip', 'w', zipfile.ZIP_DEFLATED) as zf:
for root, dirs, files in os.walk(folder):
for f in files:
zf.write(os.path.join(root, f))
"
Frequently asked questions
Execute code, commands, and complex tasks securely in isolated Docker containers running AlmaLinux 9.4.
The source record exposes this install command: npx skills add https://github.com/wecode-ai/Wegent --skill "backend/init_data/skills/sandbox". Inspect the command and pinned source before running it.
Static rules flagged exec-script, read-files, write-files, network in the source; the page lists the matching lines and excerpts.
Alternatives
garrytan/gbrain
End-to-end discipline for turning any large data source (audio libraries, email takeouts, document corpora, chat exports, API dumps) into brain pages at scale. The lifecycle spine: SCHEMA → ACCESS → TRIAL → EVALUATE → IMPROVE → CODIFY → TEST → SKILLIFY → BULK → MONITOR. State is tracked in a durable JSON manifest (see MANIFEST-PATTERN.md) so any crash, session boundary, or subagent fan-out resumes from ground truth instead of memory.
alirezarezvani/claude-skills
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist
dotnet/skills
Migrates .NET test projects from VSTest to Microsoft.Testing.Platform (MTP). Use when user asks to "migrate to MTP", "switch from VSTest", "enable Microsoft.Testing.Platform", "use MTP runner", set OutputType=Exe only for test projects in Directory.Build.props, or mentions EnableMSTestRunner, EnableNUnitRunner, or UseMicrosoftTestingPlatformRunner. USE FOR: MTP behavioral differences vs VSTest (exit code 8, zero tests discovered, --ignore-exit-code, TESTINGPLATFORM_EXITCODE_IGNORE); centralizing
vipshop/cache-dit
High-level guide for integrating a new DiT model into cache-dit: Cache (BlockAdapter/ForwardPattern), Context Parallelism, Tensor Parallelism, Text Encoder Parallelism (TE-P), VAE Parallelism (VAE-P), generate CLI, installation, testing workflow, and detailed references. Use when adding support for a new diffusion transformer model in cache-dit.