cloudflare/skills · Official

sandbox-next

Build or maintain Cloudflare Sandbox apps on @cloudflare/sandbox@next (SDK 1.0 preview). Use sandbox-migrate-to-next when porting a stable app.

All-time #811 Trending #325 Hot #6564 First seen Aug 7, 2026
8-week activity · all time api

Installation

$ npx skills add cloudflare/skills --skill sandbox-next

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Security audits

Partner security reviews for this skill.

agent-trust-hub Reviewed

Analyzed Sep 6, 2026

snyk Reviewed

Analyzed Sep 6, 2026

socket Score 0.9000 · 0 alerts

Analyzed Sep 6, 2026

  • license 1
  • maintenance 1
  • quality 0.9
  • supply chain 1
  • vulnerability 1

0 alerts

Also in this package

Other skills from cloudflare/skills · top by installs.

npx skills add cloudflare/skills

Browse all from cloudflare/skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 2.8K
License LICENSE
Default branch main
Open issues 8
Status Active

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 6,816 B
  • docs SUMMARY.md 3,985 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 27,709 installs

SKILL.md

Sandbox SDK — @next (1.0 preview)

Isolated Linux environments on Cloudflare Containers, driven from Workers.

Prefer preview docs and installed @next types over memory. APIs change; this skill is a gate, a contract, and a retrieval map—not a full manual.

We recommend new projects on this line. Apps still on the default package use sandbox-stable. Port only when asked, via sandbox-migrate-to-next.

1. Gate — confirm the package line

Before writing code, inspect the app:

Check Must match
npm dependency @cloudflare/sandbox@next (or another preview tag)
Container image Same line (e.g. cloudflare/sandbox:next, next-python)
If you find… Action
Default @cloudflare/sandbox (no @next) Stop. Load sandbox-stable. Do not apply this skill’s APIs.
User wants to port stable → @next Stop. Load sandbox-migrate-to-next.
Self-deployed bridge only Bridge is not on the 1.0 preview line yet. Keep bridge on stable package + image. Bridge (stable)

Never mix an @next Worker package with a stable container image (or the reverse).

Skills install: Agent setup · cloudflare/skills

2. Contract — non-negotiables

  • sandbox.exec(argv) takes an argv list and resolves when the process starts. It returns a handle, not a finished command result.
  • Collect results with handle methods: output(), logs(), waitForExit(), waitForPort(), waitForLog(), kill(signal?).
  • No implicit shell. Shell syntax needs an explicit shell, e.g. ["/bin/bash", "-lc", script].
  • Each launch is independent. A cd / export in one exec is not visible to the next. Pass cwd and env per launch, or one shell script.
  • Process handles have no stdin. Interactive use → terminals (createTerminal + connect).
  • Local wait timeout / AbortSignal cancel the wait only. They do not kill the process. Use kill or exec’s remote timeout.
  • getProcess / listProcesses / getTerminal / listTerminals do not start a container; they return null / [] when none is up.
  • Process and terminal IDs belong to the current container, not forever to a sandbox ID. For work that must survive replace, store the full job (argv, cwd, env, app state)—not only an id.
  • Non-secret config only in setEnvVars / launch env. Live credentials stay in the Worker; use outbound handlers when the sandbox calls external APIs.
  • Do not invent removed stable APIs (gitCheckout on core, string-exec completion, session execution, sandbox.terminal(request)).
  • Do not use one retry loop for every error (see Errors docs).

Minimal shape:

import { getSandbox, proxyToSandbox, Sandbox } from "@cloudflare/sandbox";

export { Sandbox };

const sandbox = getSandbox(env.Sandbox, "user-123");
const process = await sandbox.exec(["python3", "-c", "print(2 + 2)"]);
const result = await process.output({ encoding: "utf8" });
// result.stdout, result.exitCode

Task-specific API documentation: [references/api-quick-ref.md](references/api-quick-ref.md)

Examples index (next branch): [references/examples.md](references/examples.md)

3. Retrieve — open the doc for the task

Fetch the page before implementing. Installed @next types win over guesses.

You need to… Open
Orient / choose preview 1.0 preview overview
First Worker, wrangler, Dockerfile Get started
exec, handles, readiness, durability Process execution
Process API signatures Processes API
Sandbox ID vs container vs sleep/destroy Lifecycle
cwd / env / setEnvVars Environment
Interactive PTY / browser terminal Terminals · Terminals API
Python/JS code interpreter Interpreter · Interpreter API
Extensions model Extensions
Error classes and recovery Errors · Errors API
Common failures Troubleshooting
API hub API reference
Files, mounts, backups, ports, tunnels, proxyToSandbox Main docs for shared surfaces (ignore stable-only session/transport/sandbox.terminal): Files · Storage / mounts · Ports · Tunnels · Backups · Outbound traffic · Expose services · Production
Example apps examples on next
Still on stable package sandbox-stable · Main Sandbox docs
Porting an existing stable app sandbox-migrate-to-next · Migrate

4. Before you ship

  • Lockfile and Dockerfile on the same @next line
  • Typecheck against installed @next types
  • No live secrets in sandbox env
  • Production preview hostnames need wildcard DNS on a custom domain when using those URL patterns