sandbox-agent — security grade SAFE, quality 68/100

Security audit verdict: SAFE · quality 68/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by rivet-dev · Codex Skill · ★ 1.6k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is sandbox-agent safe to install? View the security audit →

About sandbox-agent

Run Coding Agents in Sandboxes. Control Them Over HTTP. A server that runs inside your sandbox. Your app connects remotely to control Claude Code, Codex, OpenCode, Cursor, Amp, or Pi — streaming events, handling permissions, managing sessions. Documentation — API Reference — Discord Experimental: Gigacode — use OpenCode's TUI with any coding agent. Why Sandbox Agent? Running coding agents remotely is hard. Existing SDKs assume local execution, SSH breaks TTY handling and streaming, and every agent has a different API. Building from scratch means reimplementing everything for each coding agent. Sandbox Agent solves three problems: Coding agents need sandboxes — You can't let AI execute arbitrary code on your production servers. Coding agents need isolated environments, but existing SDKs assume local execution. Sandbox Agent is a server that runs inside the sandbox and exposes HTTP/SSE. Every coding agent is different — Claude Code, Codex, OpenCode, Cursor, Amp, and Pi each have proprietary APIs, event formats, and behaviors. Swapping agents means rewriting your integration.

agentaiampclaudeclaude-codecodexdaytonae2bopencodesandbox

Quick Facts

Stars1,569
Forks125
LanguageTypeScript
CategoryCodex Skill
LicenseApache-2.0
Quality Score67.8426050475659/100
Open Issues82
Last Updated2026-06-19
Created2026-01-25
Platformsclaude-code, codex, node
Est. Tokens~16k

Compatible Skills

These tools work well together with sandbox-agent for enhanced workflows:

  • fragments — semantic(0.19)+complementary+rare_topics+same_lang+similar_pop+shared_platform (60%)
  • superset — semantic(0.24)+complementary+same_lang+similar_pop+shared_platform (58%)
  • codex-mcp-server — semantic(0.22)+complementary+same_lang+similar_pop+shared_platform (58%)
  • oh-my-claudecode — semantic(0.20)+complementary+same_lang+similar_pop+shared_platform (57%)
  • vm0 — semantic(0.18)+complementary+rare_topics+same_lang+similar_pop+shared_platform (56%)

sandbox-agent alternative? Top 6 similar tools

Looking for a sandbox-agent alternative? If you're comparing sandbox-agent with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • openpencil by ZSeven-W · ⭐ 6.0k

    The world's first open-source AI-native vector design tool and the first to feature concurrent Agent Teams. De

  • axonhub by looplj · ⭐ 5.3k

    ⚡️ Open-source AI Gateway — Use any SDK to call 100+ LLMs. Built-in failover, load balancing, cost control & e

  • agentsys by agent-sh · ⭐ 984

    AI writes code. This automates everything else · 24 plugins · 49 agents · 44 skills · for Claude Code, OpenCod

  • OpenContext by 0xranx · ⭐ 1.2k

    A personal context store for AI agents and assistants—reuse your existing coding agent CLI (Codex/Claude/OpenC

  • code-on-incus by mensfeld · ⭐ 728

    Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops t

  • agnix by agent-sh · ⭐ 422

    The missing linter and lsp for AI coding assistants. Validate CLAUDE.md, AGENTS.md, SKILL.md, hooks, MCP. Plug

More Codex Skill Tools

Explore other popular codex skill tools:

View all Codex Skill tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is sandbox-agent?

sandbox-agent is Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.. It is categorized as a Codex Skill with 1.6k GitHub stars.

What programming language is sandbox-agent written in?

sandbox-agent is primarily written in TypeScript. It covers topics such as agent, ai, amp.

How do I install or use sandbox-agent?

You can find installation instructions and usage details in the sandbox-agent GitHub repository at github.com/rivet-dev/sandbox-agent. The project has 1.6k stars and 125 forks, indicating an active community.

What license does sandbox-agent use?

sandbox-agent is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to sandbox-agent?

The top alternatives to sandbox-agent on Agent Skills Hub include openpencil, axonhub, agentsys. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Codex Skill tools