Skip to content
Back to skills

Security Sandbox

FSecurity

Secure command execution with allowlists and validation hooks. Use when validating bash commands, configuring security policies, implementing pre-tool-use hooks, or sandboxing autonomous agent operations.

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added February 8, 2026
developmentpythongobashnodeexpressdockergitsecuritydocumentation

Security analysis

F39/100
  • criticalPipes output to a shell interpreter
  • highPerforms destructive filesystem operations
  • criticalDownloads and executes remote scripts — classic supply chain attack
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 8 files and shows the line behind each finding

Scanned February 12, 2026

npx -y skills add adaptationio/Skrillz --skill security-sandbox --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Sandbox?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Sandbox
[![Security: F — Skills Directory](https://www.skillsdirectory.com/api/skills/adaptationio-security-sandbox/badge)](https://www.skillsdirectory.com/skills/adaptationio-security-sandbox)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-sandbox
description: Secure command execution with allowlists and validation hooks. Use when validating bash commands, configuring security policies, implementing pre-tool-use hooks, or sandboxing autonomous agent operations.
version: 1.0.0
category: autonomous-coding
layer: foundation
---

# Security Sandbox

Provides defense-in-depth security for autonomous coding operations through command validation, allowlists, and execution hooks.

## Quick Start

### Validate a Command
```python
from scripts.command_validator import validate_command

result = validate_command("npm install express")
if result.allowed:
    # Safe to execute
    pass
else:
    print(f"Blocked: {result.reason}")
```

### Use Security Hook
```python
from scripts.security_manager import create_bash_security_hook

hook = create_bash_security_hook()

# Hook returns decision for Claude SDK
decision = await hook({
    "tool_input": {"command": "rm -rf /"}
})
# decision = {"decision": "block", "reason": "Command 'rm' requires approval"}
```

### Configure Allowlist
```python
from scripts.allowlist import Allowlist

allowlist = Allowlist()
allowlist.add("docker")
allowlist.add("kubectl")
allowlist.remove("rm")  # Disallow rm
```

## Security Model

```
┌─────────────────────────────────────────────────────────────┐
│                   DEFENSE IN DEPTH                           │
├─────────────────────────────────────────────────────────────┤
│                                                              │
│  LAYER 1: SANDBOX                                           │
│  ├─ OS-level isolation                                      │
│  ├─ Filesystem restrictions                                 │
│  └─ Network limitations                                     │
│                                                              │
│  LAYER 2: PERMISSIONS                                       │
│  ├─ Tool allowlist (Read, Write, Bash...)                  │
│  ├─ Path restrictions (./**)                               │
│  └─ Operation limits                                        │
│                                                              │
│  LAYER 3: COMMAND VALIDATION                                │
│  ├─ Command extraction & parsing                            │
│  ├─ Allowlist checking                                      │
│  └─ Dangerous pattern detection                             │
│                                                              │
│  LAYER 4: HOOKS                                             │
│  ├─ PreToolUse validation                                   │
│  ├─ Real-time blocking                                      │
│  └─ Audit logging                                           │
│                                                              │
└─────────────────────────────────────────────────────────────┘
```

## Default Allowlist

```python
ALLOWED_COMMANDS = {
    # File inspection
    "ls", "cat", "head", "tail", "wc", "grep", "find",
    # File operations
    "cp", "mkdir", "chmod", "touch",
    # Node.js
    "npm", "node", "npx", "yarn", "pnpm",
    # Python
    "python", "python3", "pip", "pip3", "poetry",
    # Version control
    "git",
    # Process management
    "ps", "lsof", "sleep", "pkill", "kill",
    # System info
    "pwd", "whoami", "uname", "which", "env",
    # Network (limited)
    "curl", "wget",
}
```

## Dangerous Patterns

These patterns are always blocked:

| Pattern | Risk | Example |
|---------|------|---------|
| `rm -rf /` | System destruction | Wipes filesystem |
| `> /dev/sda` | Disk corruption | Overwrites disk |
| `chmod 777` | Security hole | World-writable |
| `curl \| bash` | Code injection | Remote execution |
| `:(){ :\|:& };:` | Fork bomb | DoS attack |
| `dd if=/dev/zero` | Disk fill | Resource exhaustion |

## Hook Integration

```python
# For Claude SDK integration
from scripts.security_manager import SecurityManager

manager = SecurityManager()

# Configure SDK with hooks
sdk_options = {
    "hooks": {
        "PreToolUse": [manager.pre_tool_hook]
    }
}
```

## Integration Points

- **autonomous-session-manager**: Provides security during sessions
- **coding-agent**: Uses hooks for safe command execution
- **autonomous-loop**: Ensures safety in continuous operation

## References

- `references/ALLOWED-COMMANDS.md` - Full allowlist documentation
- `references/SECURITY-MODEL.md` - Security architecture
- `references/CUSTOM-RULES.md` - Custom rule configuration

## Scripts

- `scripts/security_manager.py` - Core security manager
- `scripts/command_validator.py` - Command validation
- `scripts/allowlist.py` - Allowlist management
- `scripts/sandbox_config.py` - Sandbox configuration

Files in this skill

  • SKILL.md5.1 KB
  • references/ALLOWED-COMMANDS.md4.4 KB
  • references/CUSTOM-RULES.md3.6 KB
  • references/SECURITY-MODEL.md6.1 KB
  • scripts/allowlist.py5.5 KB
  • scripts/command_validator.py5.1 KB
  • scripts/sandbox_config.py6.7 KB
  • scripts/security_manager.py5.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…