Sandbox Shell — DevOps skill for Claude Code
macOS Seatbelt sandbox CLI for developers.
How to install Sandbox Shell
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open agentic-dev3o/sandbox-shell and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Sandbox Shell does
macOS Seatbelt sandbox CLI for developers. Protect credentials (SSH, AWS, GPG) from malicious npm packages, supply chain attacks, and untrusted build scripts. Deny-by-default filesystem isolation. Perfect for Claude Code agentic workflows with --dangerously-skip-permissions.
Alternatives in DevOps
- Replace And Ensure $github PAT Is Set In Your Shell — echo "${GITHUB_PAT}" docker login ghcr.io -u --password-stdin 225 ★
- Deploy To Docker — Build Docker image and start/redeploy the MCP Task Orchestrator container, reusing the last-used config by def 205 ★
- Cc DevOps Skills — by akin-ozer - Immensely detailed set of skills for DevOps Engineers (or anyone who has to deploy code, really 123 ★
README
sx - macOS Sandbox CLI for Secure Development
[](https://github.com/agentic-dev3o/sandbox-shell/actions/workflows/QA.yaml) [](LICENSE) [](https://developer.apple.com/documentation/security/app_sandbox)
A lightweight Rust CLI that wraps shell commands in macOS Seatbelt sandboxes. That npm package you just installed? It can't read your `~/.ssh` keys or `~/.aws` credentials. Can't steal what you can't see.
Supply chain attacks are everywhere. A single compromised dependency tries to exfiltrate your secrets? It can't—filesystem is deny-by-default. Your credentials aren't readable, even with network enabled. No containers, no VMs, just native macOS sandboxing.
Quick Start
brew tap agentic-dev3o/sx
brew install sx
# That's it. Now run untrusted code:
sx -- npm run build
sx -- cargo test
sx -- ./build.sh
# Or start an interactive sandboxed shell
sx
Your secrets stay secret. Malicious postinstall scripts get nothing.
Profiles
Profiles stack. Combine them: `sx online rust -- cargo build`
| Profile | What it does |
|---|---|
base |
Minimal sandbox (always included) |
online |
Full network access |
localhost |
127.0.0.1 only |
rust |
Cargo/rustup paths |
bun |
~/.bun + parent directory listing for module resolution |
claude |
Claude Code paths (includes online) |
gpg |
GPG signing |
Examples
# Bun
sx bun -- bun install # Offline, from cache
sx bun online -- bun install # Download deps
# Rust
sx rust -- cargo test # Offline tests
sx rust online -- cargo build # Download crates
# Claude Code - the whole point
sx claude -- claude --dangerously-skip-permissions --continue
# Interactive shell with network
sx online
Claude Code Integrati
Related Skills
Lockdown
Per-repo supply-chain hardening — detects the package managers, Dockerfiles, and CI in use, then guides you th
Multi Target Publish
When a single change spans multiple repos / packages / deploy targets with different deploy mechanisms (auto-d
Porta
Sandboxed runtime for AI agents. WASM isolation + OS-level sandbox. Run Claude Code, Python, or any command wi
Deny
Run clawband deny '$ARGUMENTS' to add the pattern to ~/.clawband/deny.patterns, then confirm it was added. If
Guidance For Dynamic Game Npc Dialogue On AWS
This guidance helps game developers automate the process of creating a non-player character (NPC) for their ga
Relay Dev
Native macOS workspace manager for developers: projects, terminal sessions, AI CLI agents, dev services, Docke
Related Agents
Fleet Ops
Use PROACTIVELY and automatically — do not wait to be asked — for macOS + Kali fleet operations: SSH, liveness
Supply Chain Framework Auditor
Audits dependency CVEs, malicious or over-permissioned SDKs, build-pipeline leftovers (debug flags, test endpo
Impl Cross Platform
Reviews implementation plans from a cross-platform compatibility perspective. Use when evaluating Linux vs. ma