Sandbox skills
Free agent skills tagged sandbox, ready to install into any SKILL.md-compatible agent.
13 skills
Cloudflare Sandbox Next
cloudflare
Build and modify Cloudflare Sandbox apps with ease.
Automated Malware Submission Pipeline
mukul975
Streamline malware analysis with automation.
Analyzing Malware Behavior
mukul975
Dynamic analysis of malware using Cuckoo Sandbox.
Sandbox SDK - Stable
cloudflare
Manage Cloudflare Sandbox apps with stability in mind.
Migrate to Sandbox Next
cloudflare
Streamline your Cloudflare Sandbox app upgrade process.
Competition Web Runtime
zhaoxuya520
Specialized tool for web behavior and routing analysis.
Benchmark Sandbox
vercel
Run Vercel plugin evaluations in isolated environments.
Managing Streamlit Apps
posthog
Easily create and deploy Streamlit apps in PostHog.
Vercel Sandbox
vercel
Run untrusted code safely in ephemeral microVMs.
CTF Sandbox Orchestrator
Default entrypoint and master ctf-sandbox-orchestrator workflow for CTF, exploit, reverse engineering, DFIR, pwnable, crypto, stego, mobile, AI-agent, cloud, container, Active Directory, Windows-host, and identity challenges. Use first when the user presents challenge infrastructure, binaries, prompts, hosts, or identities that should be treated as sandbox-internal by default and Codex needs to choose, route, and load the right downstream analysis path with concise evidence.
Vercel Sandbox
Run agent-browser + Chrome inside Vercel Sandbox microVMs for browser automation from any Vercel-deployed app. Use when the user needs browser automation in a Vercel app (Next.js, SvelteKit, Nuxt, Remix, Astro, etc.), wants to run headless Chrome without binary size limits, needs persistent browser sessions across commands, or wants ephemeral isolated browser environments. Triggers include "Vercel Sandbox browser", "microVM Chrome", "agent-browser in sandbox", "browser automation on Vercel", or any task requiring Chrome in a Vercel Sandbox.
Automated Malware Analysis with CAPE
Deploy and operate the CAPEv2 malware sandbox (a Cuckoo derivative) to run samples in a monitored Windows guest VM, capturing behavioral signatures, dropped files, PCAP network traffic, and family-specific configuration extraction (e.g. Emotet, TrickBot, Cobalt Strike) via cape-parsers. Use when a suspicious file or payload needs automated dynamic analysis, anti-evasion debugger tricks, or config/payload extraction.
Investigating Phishing Email Incident
Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.
