Imported from woodybriggs/luasbox (
SKILL.md). Install upstream withnpx skills add woodybriggs/luasbox. Copyright stays with the author.
SKILL: Running luasbox
Overview
luasbox is a sandboxed Lua script runner. You (the agent) act as the approval layer — luasbox sends you requests when a script tries to access modules, functions, or call sandboxed APIs. You decide whether to approve or deny each request.
How It Works
- Start luasbox with a script and socket path:
luasbox -c config.ini --socket /tmp/luasbox.sock script.lua - Use
luasbox-clientto read requests and send approvals. - Repeat until the script finishes.
Protocol
Two sockets are created:
<path>.req— agent connects to read the pending request<path>.approve— agent connects to send approval/denial
Each connection is short-lived: connect, send one message, disconnect.
Messages (luasbox → agent):
REQUEST module <name>— Script wants to require a moduleREQUEST function <name>— Script wants to access a functionREQUEST call <name> [[arg]]...— Script wants to call a function with argsDONE— Script completed successfullyERROR <msg>— Script error
Messages (agent → luasbox):
APPROVED— Allow the requestDENIED— Block the request
Using luasbox-client
# Read the pending request
luasbox-client /tmp/luasbox.sock read
# → REQUEST module io
# Approve the request
luasbox-client /tmp/luasbox.sock approve
# Read + approve in one step
luasbox-client /tmp/luasbox.sock auto
# → REQUEST module io
# (sends APPROVED automatically)
# Deny a request
luasbox-client /tmp/luasbox.sock deny
Bash Example
# Start luasbox
luasbox -c sandbox.ini --socket /tmp/luasbox.sock script.lua &
# Read and approve each request
luasbox-client /tmp/luasbox.sock auto # REQUEST module io
luasbox-client /tmp/luasbox.sock auto # REQUEST module math
luasbox-client /tmp/luasbox.sock auto # REQUEST call io.open [[/tmp/f.txt]] [[w]]
Decision Strategy
| Request | Auto-approve? | Notes |
|---|---|---|
REQUEST module io |
Yes | Core I/O module |
REQUEST module math |
Yes | Pure computation |
REQUEST module string |
Yes | Pure computation |
REQUEST function io.open |
Depends | Check the path argument |
REQUEST call io.open [[/tmp/...]] |
Yes | Writing to temp is safe |
REQUEST call io.open [[/etc/...]] |
No | Sensitive system paths |
REQUEST function os.execute |
No | Always blocked by sandbox |
When in doubt, ask the human.
Notes
- Each approval is per-operation. Once
io.openis approved, future calls still go through the protocol. - If no response is sent within30 seconds, the request is denied automatically.
os.executeis always blocked even if approved — the sandbox enforces this.- Scripts must use
local io = require("io")(assign to variable) since standard lib globals are sandboxed.
