Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
github avatar

Sandbox Npm Install

  • 1.6k installs
  • 37.1k repo stars
  • Updated July 28, 2026
  • github/awesome-copilot

sandbox-npm-install installs npm dependencies in Docker virtiofs sandboxes via ext4 install and workspace symlinks.

About

The sandbox-npm-install skill fixes native binary crashes when installing npm packages in Docker sandboxes with virtiofs-mounted workspaces. Tools like esbuild, lightningcss, and rollup fail with SIGILL or mmap errors on aarch64 virtiofs, so the bundled install script copies package manifests to a container-local ext4 path, runs npm ci or install there, and symlinks node_modules into the workspace. It supports Playwright browser install, verifies known native binaries, and documents post-install test and build checks. Agents re-run after package.json or lockfile changes and must not run npm install directly on the mounted workspace. Troubleshooting covers permission errors, broken host symlinks, and intermittent verification failures. Use on first sandbox session setup, lockfile updates, or when dev servers crash with native module errors.

  • Installs node_modules on local ext4 to avoid virtiofs native binary crashes.
  • Bundles scripts/install.sh with npm ci, symlink, and binary verification.
  • Supports optional Playwright Chromium install for E2E sandboxes.
  • Documents re-run triggers after package.json or lockfile changes.
  • Warns against direct npm install on virtiofs-mounted workspaces.

Sandbox Npm Install by the numbers

  • 1,626 all-time installs (skills.sh)
  • +21 installs in the week ending Jul 28, 2026 (Skillselion tracking)
  • Ranked #126 of 1,453 DevOps & CI/CD skills by installs in the Skillselion catalog
  • Security screen: MEDIUM risk (skills.sh audit)
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

sandbox-npm-install capabilities & compatibility

Capabilities
ext4 npm install · node_modules symlink · native binary verification
Use cases
devops · ci cd
npx skills add https://github.com/github/awesome-copilot --skill sandbox-npm-install

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs1.6k
repo stars37.1k
Security audit2 / 3 scanners passed
Last updatedJuly 28, 2026
Repositorygithub/awesome-copilot

Why do esbuild or vite crash with SIGILL after npm install in a sandbox?

Install npm packages in Docker virtiofs sandboxes by running deps on local ext4 and symlinking node_modules back to the workspace.

Who is it for?

Copilot sandbox sessions on virtiofs with Node native dependencies.

Skip if: Host-native installs without Docker virtiofs constraints.

When should I use this skill?

User hits native binary crashes, missing node_modules, or lockfile changes in sandbox.

What you get

Working node_modules symlink with verified native binaries ready for test and dev commands.

  • symlinked node_modules directory
  • installed npm dependencies on ext4

By the numbers

  • Defaults node_modules install base to /home/agent/project-deps on local ext4
  • Targets native binary crashes from esbuild, lightningcss, and rollup on virtiofs

Files

SKILL.mdMarkdownGitHub ↗

Sandbox npm Install

When to Use This Skill

Use this skill whenever:

  • You need to install npm packages for the first time in a new sandbox session
  • package.json or package-lock.json has changed and you need to reinstall
  • You encounter native binary crashes with errors like SIGILL, SIGSEGV, mmap, or unaligned sysNoHugePageOS
  • The node_modules directory is missing or corrupted

Prerequisites

  • A Docker sandbox environment with a virtiofs-mounted workspace
  • Node.js and npm available in the container
  • A package.json file in the target workspace

Background

Docker sandbox workspaces are typically mounted via virtiofs (file sync between the host and Linux VM). Native Go and Rust binaries (esbuild, lightningcss, rollup, etc.) crash with mmap alignment failures when executed from virtiofs on aarch64. The fix is to install on the container's local ext4 filesystem and symlink back into the workspace.

Step-by-Step Installation

Run the bundled install script from the workspace root:

bash scripts/install.sh

Common Options

OptionDescription
--workspace <path>Path to directory containing package.json (auto-detected if omitted)
--playwrightAlso install Playwright Chromium browser for E2E testing

What the Script Does

1. Copies package.json, package-lock.json, and .npmrc (if present) to a local ext4 directory 2. Runs npm ci (or npm install if no lockfile) on the local filesystem 3. Symlinks node_modules back into the workspace 4. Verifies known native binaries (esbuild, rollup, lightningcss, vite) if present 5. Optionally installs Playwright browsers and system dependencies (uses sudo when available)

If verification fails, run the script again — crashes can be intermittent during initial setup.

Post-Install Verification

After the script completes, verify your toolchain works. For example:

npm test             # Run project tests
npm run build        # Build the project
npm run dev          # Start dev server

Important Notes

  • The local install directory (e.g., /home/agent/project-deps) is container-local and is NOT synced back to the host
  • The node_modules symlink appears as a broken link on the host — this is harmless since node_modules is typically gitignored
  • Running npm ci or npm install on the host naturally replaces the symlink with a real directory
  • After any package.json or package-lock.json change, re-run the install script
  • Do NOT run npm ci or npm install directly in the mounted workspace — native binaries will crash

Troubleshooting

ProblemSolution
SIGILL or SIGSEGV when running dev serverRe-run the install script; ensure you're not running npm install directly in the workspace
node_modules not found after installCheck that the symlink exists: ls -la node_modules
Permission errors during installEnsure the local deps directory is writable by the current user
Verification fails intermittentlyRun the script again — native binary crashes can be non-deterministic on first load

Vite Compatibility

If your project uses Vite, you may need to allow the symlinked path in server.fs.allow. Add the symlink target's parent directory (e.g., /home/agent/project-deps/) to your Vite config so that Vite can serve files through the symlink.

Related skills

How it compares

Use Sandbox npm Install instead of standard npm install when the workspace is virtiofs-mounted in an agent sandbox and native addon binaries crash.

FAQ

Why not run npm ci in the workspace?

Native Go and Rust binaries crash when executed from virtiofs on aarch64 sandboxes.

Will node_modules sync to the host?

The symlink may look broken on the host but is harmless because node_modules is gitignored.

When should I re-run the install script?

After any package.json or package-lock.json change or corrupted node_modules.

Is Sandbox Npm Install safe to install?

skills.sh reports 2 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

DevOps & CI/CDdevopsintegrations

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.