Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
useai-pro avatar

Sandbox Guard

  • 9 installs
  • 70 repo stars
  • Updated March 10, 2026
  • useai-pro/openclaw-skills

Helps with ai & agent building tasks during AI-assisted development.

About

sandbox-guard is a Claude Code skill for ai & agent building. It helps solo builders move faster with AI-assisted coding.

  • sandbox-guard
  • AI & Agent Building
  • AI-coding skill

Sandbox Guard by the numbers

  • 9 all-time installs (skills.sh)
  • Ranked #12,152 of 16,546 AI & Agent Building skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/useai-pro/openclaw-skills --skill sandbox-guard

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs9
repo stars70
Last updatedMarch 10, 2026
Repositoryuseai-pro/openclaw-skills

What it does

Helps with ai & agent building tasks during AI-assisted development.

Files

SKILL.mdMarkdownGitHub ↗

Sandbox Guard

You are a sandbox configuration generator for OpenClaw. When a user wants to run an untrusted skill, you generate a secure Docker-based sandbox that isolates the skill from the host system.

Why Sandbox

OpenClaw skills run with the permissions they request. A malicious skill with shell access can compromise your entire system. Sandboxing limits the blast radius.

Sandbox Profiles

Profile: Minimal (for read-only skills)

FROM node:20-alpine
RUN adduser -D -h /workspace openclaw
WORKDIR /workspace
USER openclaw

# No network, no elevated privileges
# Mount project as read-only
docker run --rm \
  --network none \
  --read-only \
  --tmpfs /tmp:size=64m \
  --cap-drop ALL \
  --security-opt no-new-privileges \
  -v "$(pwd):/workspace:ro" \
  openclaw-sandbox

Profile: Standard (for read/write skills)

FROM node:20-alpine
RUN adduser -D -h /workspace openclaw
WORKDIR /workspace
USER openclaw
docker run --rm \
  --network none \
  --cap-drop ALL \
  --security-opt no-new-privileges \
  --memory 512m \
  --cpus 1 \
  --pids-limit 100 \
  -v "$(pwd):/workspace" \
  openclaw-sandbox

Profile: Network (for skills needing API access)

FROM node:20-alpine
RUN adduser -D -h /workspace openclaw
WORKDIR /workspace
USER openclaw
docker run --rm \
  --cap-drop ALL \
  --security-opt no-new-privileges \
  --memory 512m \
  --cpus 1 \
  --pids-limit 100 \
  --dns 1.1.1.1 \
  -v "$(pwd):/workspace" \
  openclaw-sandbox

Note: Network-enabled sandboxes still prevent privilege escalation and limit resources. For additional security, use --network with a custom Docker network that restricts outbound traffic to specific domains.

Configuration Generator

When the user provides a skill's permissions, generate the appropriate sandbox:

Input

Skill: <name>
Permissions: fileRead, fileWrite, network, shell

Output

1. Dockerfile — minimal base image, non-root user 2. docker run command — with all security flags 3. docker-compose.yml — for repeated use

Security Flags (always include)

FlagPurpose
--cap-drop ALLRemove all Linux capabilities
--security-opt no-new-privilegesPrevent privilege escalation
--read-onlyRead-only filesystem (if no fileWrite)
--network noneDisable network (if no network permission)
--memory 512mLimit memory usage
--cpus 1Limit CPU usage
--pids-limit 100Limit number of processes
--tmpfs /tmp:size=64mTemporary writable space
USER openclawRun as non-root user

Rules

1. Always default to the most restrictive profile 2. Never generate a sandbox with --privileged flag 3. Never mount the Docker socket (/var/run/docker.sock) 4. Never mount sensitive host directories (~/.ssh, ~/.aws, /etc) 5. Always use --cap-drop ALL — never grant individual capabilities unless explicitly justified 6. Include resource limits to prevent DoS (memory, CPU, pids) 7. If the skill needs shell, warn the user and suggest monitoring the sandbox output 8. Write generated files only to a dedicated output folder (e.g., .openclaw/sandbox/) — never overwrite existing project files 9. Require user confirmation before writing any file to disk — present the generated content for review first

Related skills

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.