Opp Repl Sandbox

Run opp_repl, simulations, and its MCP server under bubblewrap (bwrap) filesystem isolation with opp_sandbox. Sources are mounted read-only, the working directory read-write; a /.opp_sandbox sentinel lets the MCP server skip bearer-token auth inside the jail. Linux only. Load when running untrusted models, exposing execute_python to an agent more safely, or reproducing clean-environment builds.

tabgab 2fc413b 3.1 KB Updated

File contents

tabgab/opp_repl-skill/tree/main/opp-repl-sandbox commit 2fc413b71c

Frequently asked questions

npx skillmds@latest add tabgab/opp-repl-sandbox