devbox
Persistent Linux container per user with dev tools and network access pre-installed. Escape hatch for tasks the bwrap sandbox can't handle.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Persistent Linux container per user with dev tools and network access pre-installed. Escape hatch for tasks the bwrap sandbox can't handle.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
Calendar operations with CalDAV
Git repository management, GitLab merge requests, and GitHub pull requests
Location tracking, place recognition, visit history, and calendar attendance
Persistent memory writes — USER.md (behavioral) and the knowledge graph (facts).
Accounting operations (ledger, invoicing, transactions, work log, investment portfolio) — runs in-process via the vendored money package
Send a push notification to the user's configured ntfy device(s). One-way (bot to phone), no reply channel.
| name | devbox |
| triggers | ["devbox","install package","pip install","apt install","npm install","cargo install","go install","compile","build","dig","nslookup","traceroute","whois","ping","nmap","tcpdump","openssl","mtr","network diagnostic","port scan","certificate","DNS lookup","reverse DNS"] |
| description | Persistent Linux container per user with dev tools and network access pre-installed. Escape hatch for tasks the bwrap sandbox can't handle. |
| cli | true |
| requires_capability | ["devbox"] |
A persistent Linux container — your personal workbench. Use it for tasks the main sandbox can't handle: installing packages, compiling code, running arbitrary binaries, or anything needing real network access (DNS, ICMP, raw sockets).
The devbox is isolated from {BOT_NAME}'s secrets, your workspace, and internal services. Files cross the boundary only via explicit cp-in / cp-out.
pip install, broken traceroute)?The most common case today: network diagnostics. The main sandbox has dig, ping, curl, etc. but no network. The devbox has them all with a working network and CAP_NET_RAW.
# Run any command
istota-skill devbox exec "dig MX example.com +short"
istota-skill devbox exec "pip install --user pandas && python -c 'import pandas; print(pandas.__version__)'"
# Run a local script file (copies it into /workspace, runs it, returns output)
istota-skill devbox exec-file /path/to/local/script.py
# Move a file in / out
istota-skill devbox cp-in /local/file.csv /workspace/file.csv
istota-skill devbox cp-out /workspace/out.json /local/out.json
# State + maintenance
istota-skill devbox status # running? uptime? disk? image?
istota-skill devbox reset # wipe volume, recreate from base image (destructive)
git clone / git push over HTTPS to GitHub / GitLab. The image's /etc/gitconfig wires [credential] helper = istota, which proxies every credential lookup to a host-side daemon over /run/istota-cred/sock. Tokens never enter the container — the daemon injects username=x-access-token + password=<token> only for the duration of the request. Unknown hosts (e.g. bitbucket.org) get a no-token response so git fails cleanly with its standard "authentication failed".gh and glab curated CLI shims. The supported subcommands route through the proxy:
gh: pr create|view|list|close, issue create|view|list, repo view, auth status.glab: mr create|view|list|close, issue create|view|list, repo view, auth status.
Anything else exits 2 with a message pointing at github-api / gitlab-api for raw REST access.github-api / gitlab-api — raw REST wrappers ($GITHUB_API_CMD / $GITLAB_API_CMD env vars point at them). Same shape as the host-side wrappers: --method, --endpoint, optional --body / --body-file / --body-stdin, repeatable --header KEY=VALUE. Calls are validated against the operator-configured allowlist; endpoint mismatches return a not_allowed error, never reach the upstream.git commit works without first running git config user.*. The baked-in /etc/gitconfig carries placeholder Istota Agent <istota@local>; override per-repo if a project needs real identity.The proxy is host-side and per-user — the in-container scripts are thin clients that just frame JSON requests. Stale tokens are fixed by restarting the proxy unit on the host, not by anything inside the container.
{"status": "ok", "stdout": "…", "stderr": "…", "exit_code": 0, "duration_ms": 1234}
exit_code != 0 is reported, not raised — the JSON envelope is the result. Inspect stderr to decide what to do.\n…[truncated: N more bytes] marker.--timeout SECONDS.{"status": "error", "error": "…"}.istota-skill devbox exec "dig MX example.com +short"
istota-skill devbox exec "host -t TXT example.com"
istota-skill devbox exec "whois example.com"
istota-skill devbox exec "ping -c 4 host.example.com"
istota-skill devbox exec "mtr --report --report-cycles 10 example.com"
istota-skill devbox exec "nmap -sT -p 22,80,443 example.com"
istota-skill devbox exec "nc -zv example.com 443 2>&1"
istota-skill devbox exec "curl -sI -w 'time_total: %{time_total}s\\n' https://example.com"
istota-skill devbox exec "echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates -subject -issuer"
cp-in it first. /workspace/ is a tmpfs scratch dir (cleared on container restart); /home/dev/ is the persistent volume (good for clones, builds, caches). Host-side cp-in source and cp-out destination paths must stay under {BOT_NAME}'s deferred-op dir or the user's workspace subtree — copying to/from anywhere else is refused.exec runs commands through bash -c inside the container, so pipes / redirects / && work. Single-quote your argument to keep the host shell from rewriting it.exec runs non-interactively. Commands that wait for stdin will hang and hit the timeout.docker run, docker network, raw socket calls). The docker socket bound into the sandbox is a filtering proxy that only permits exec/cp/inspect/restart on your own container — docker run, container creation, --privileged, and host mounts are refused at the socket. The devbox CLI is the supported surface; anything else is out of contract.Read directly.Bash with curl (works in the main sandbox via the CONNECT proxy).python -c '...' → main sandbox has Python; only reach for the devbox when you need extra packages or freedom.