CtrlK
BlogDocsLog inGet started
Tessl Logo

running-sbx-sandboxes

Run and operate Docker Sandboxes — choosing an agent, passing it flags, git workspace modes, ports, secrets, network policy, and sharing host skills into a sandbox. Use when starting or re-attaching to a sandbox, picking between the built-in agents, signing in from CI, copying files in or out, or reaching for the right sbx command.

76

Quality

96%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exceptional operating reference: fully executable commands for every common case, explicit error-recovery loops, validation checkpoints before risky operations, and clean delegation of deeper detail to two real reference files and sibling skills. The only knock is minor over-explanation in a couple of rationale passages that could be tightened without losing information.

Suggestions

Trim the rationale sentences for pre-loosened agents and the shared-skills trust-boundary discussion down to one line each — the facts (microVM is the boundary; store is read-write and cross-sandbox) stand on their own.

The 'Last verified' section's caveats about dropped command blocks could be folded into the Known Discrepancies reference file to keep the main body purely operational.

DimensionReasoningScore

Conciseness

The body is dense with sbx-specific, non-inferable facts (deny-by-default egress, the `--` argument merge rule, create-time-only flags) and never explains concepts Claude already knows, so it is well above the 'mostly efficient' anchor. It falls short of 5 only because a few passages over-explain reasoning that could be trimmed — e.g. the rationale for pre-loosened agents ('The reasoning is that the microVM *is* the boundary, so the prompts guard nothing…') and the multi-sentence trust-boundary discussion of the shared skills store.

4 / 5

Actionability

Nearly every section is copy-paste-ready shell commands with inline comments, covering the common cases concretely: lifecycle (`sbx run claude --name my-sandbox ~/my-project`), CI login (`echo "$DOCKER_PAT" | sbx login --username <docker-id> --password-stdin`), SSH commit signing, policy, ports, and the YAML kit fork example. This matches 'Fully executable; copy-paste ready code or commands; specific examples cover the common cases'.

5 / 5

Workflow Clarity

Multi-step processes are clearly sequenced with explicit validation checkpoints and feedback loops: SSH signing is split into 'Load the key on the **host**, then configure Git **inside**'; 'The loop' section is literally a validate-fix-retry cycle (`sbx policy log` → `sbx policy allow network <host>` → retry); and `sbx kit validate`, `sbx policy check`, `sbx skills import --dry-run`, and reading back OS-assigned ports from `sbx ports` serve as pre-flight checks. Diagnose commands are ordered ('Try them in that order').

5 / 5

Progressive Disclosure

The body is a clear 80%-case overview with well-signaled, one-level-deep references that exist on disk ([references/credentials.md](references/credentials.md), [references/discrepancies.md](references/discrepancies.md)), a 'Where the detail lives' routing table delegating deeper topics to named sibling skills, and no nested-reference chains. This matches 'Clear overview with well-signaled one-level-deep references; content appropriately split; easy navigation'.

5 / 5

Total

19

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: it states a concrete, comprehensive action list in third-person imperative voice, follows it with an explicit 'Use when…' clause full of natural trigger phrases, and stays tightly scoped to this skill's operating surface versus its siblings. Both what and when are answered with no fluff.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete capabilities — 'choosing an agent, passing it flags, git workspace modes, ports, secrets, network policy, and sharing host skills into a sandbox' — which comprehensively covers the skill's operating surface, matching the top anchor ('Lists multiple specific concrete actions; comprehensive coverage'). It is not a 4 because there are no noticeable coverage gaps in the action list.

5 / 5

Completeness

It explicitly answers both questions: the 'what' is 'Run and operate Docker Sandboxes' with a concrete capability list, and the 'when' is an explicit 'Use when starting or re-attaching to a sandbox, picking between the built-in agents, signing in from CI, copying files in or out, or reaching for the right sbx command' with concrete trigger phrases. This is the anchor-5 example pattern verbatim in structure.

5 / 5

Trigger Term Quality

Natural trigger phrases users would actually say are comprehensively covered: 'starting or re-attaching to a sandbox', 'picking between the built-in agents', 'signing in from CI', 'copying files in or out', plus product synonyms ('Docker Sandboxes', 'sandbox', 'sbx'). This matches the top anchor's comprehensive synonym coverage; nothing common is missing.

5 / 5

Distinctiveness Conflict Risk

'Run and operate Docker Sandboxes' carves a clear niche (operating sandboxes) distinct from the sibling skills it implies (building templates/kits, diagnosing, governing), and the 'sbx' product terms are unambiguous, so minimal conflict risk. Not a 4: no meaningful overlap with closely related skills is introduced by the wording.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
slurpyb/sbx-agent
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.