sandbox-executor
Runs commands in a read-only Docker container with:
- read-only root filesystem
- no new privileges
- dropped ALL capabilities
- network disabled by default
- 256MB memory limit
Falls back to native execution if Docker unavailable.
Docker-isolated command runner with security constraints
npx skillmds@latest add bobo070314/sandbox-executor Runs commands in a read-only Docker container with:
Falls back to native execution if Docker unavailable.
bobo070314/openclaw-workspace/tree/main/skills/sandbox-executor commit 9a7ceae926