benchmark-agents
Advanced AI agent benchmark scenarios that push Vercel's cutting-edge platform features —…
Vercel Sandbox guidance — ephemeral Firecracker microVMs for running untrusted code safely. Supports AI agents, code generation, and experimentation. Use when executing user-generated or AI-generated code in isolation.
$ npx -y skills add vercel/vercel-plugin --skill vercel-sandbox --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/vercel-sandboxContext preview
The summary Claude sees to decide when to auto-load this skill.
Vercel Sandbox guidance — ephemeral Firecracker microVMs for running untrusted code safely. Supports AI agents, code generation, and experimentation. Use when executing user-generated or AI-generated code in isolation.
name: vercel-sandbox
description: Vercel Sandbox guidance — ephemeral Firecracker microVMs for running untrusted code safely. Supports AI agents, code generation, and experimentation. Use when executing user-generated or AI-generated code in isolation.
summary: "Run untrusted/AI-generated code in ephemeral Firecracker microVMs via @vercel/sandbox. Core loop: `const s = await Sandbox.create(); try { const r = await s.runCommand('python3', ['-c', code]); } finally { await s.stop(); }`. runCommand has no shell (wrap pipes/redirects in `bash -c`) and does not throw on non-zero exit (check r.exitCode). Default image is Ubuntu (`apt-get update` before install). Persistence is on by default (auto-snapshot on stop, resume by name; only the filesystem survives). For untrusted code use `networkPolicy: 'deny-all'`, a short `timeout`, and `persistent: false`. Credential brokering: a firewall `transform` injects a secret header on egress so the VM never holds it. AI agents reach models with no API key via the AI Gateway (`https://ai-gateway.vercel.sh`, `Authorization: Bearer $VERCEL_OIDC_TOKEN`) — the token is not auto-injected, so pass it via `env` or broker it. Full docs: https://vercel.com/docs/sandbox"
metadata:
priority: 4
docs:
- "https://vercel.com/docs/sandbox"
sitemap: "https://vercel.com/sitemap.xml"
pathPatterns: []
importPatterns:
- '@vercel/sandbox'
bashPatterns:
- '\bnpm\s+(install|i|add)\s+[^\n]*@vercel/sandbox\b'
- '\bpnpm\s+(install|i|add)\s+[^\n]*@vercel/sandbox\b'
- '\bbun\s+(install|i|add)\s+[^\n]*@vercel/sandbox\b'
- '\byarn\s+add\s+[^\n]*@vercel/sandbox\b'
promptSignals:
phrases:
- "@vercel/sandbox"
- "sandbox"
- "code sandbox"
- "vercel sandbox"
- "isolated environment"
- "sandboxed execution"
allOf:
- [sandbox, code]
- [sandbox, execute]
- [sandbox, run]
- [sandbox, isolated]
- [sandbox, safe]
- [sandbox, environment]
- [isolated, execute]
- [isolated, code]
- [isolated, environment]
- [isolated, run]
- [safe, execute]
- [safe, code]
- [untrusted, code]
- [untrusted, execute]
- [code, runner]
- [code, playground]
- [execute, safely]
- [run, safely]
- [run, isolation]
- [execute, isolation]
- [ffmpeg, process]
- [ffmpeg, convert]
- [ffmpeg, compress]
- [student, code]
- [student, execute]
- [student, run]
anyOf:
- "sandbox"
- "isolated"
- "isolation"
- "untrusted"
- "safely"
- "microvm"
- "ffmpeg"
- "playground"
noneOf:
- "iframe sandbox"
- "sandbox attribute"
- "codesandbox.io"
- "stackblitz"
minScore: 4
retrieval:
aliases:
- code sandbox
- microvm
- isolated execution
- safe code runner
intents:
- run untrusted code
- execute code safely
- create sandbox
- isolate code execution
entities:
- Vercel Sandbox
- Firecracker
- microVM
- isolated execution
chainTo:
-
pattern: 'from\s+[''""]vm2[''""]|require\s*\(\s*[''""]vm2[''""\)]|new\s+VM\('
targetSkill: vercel-sandbox
message: 'vm2 detected — it has known security vulnerabilities. Reloading Vercel Sandbox guidance for Firecracker microVM-based safe execution.'
-
pattern: 'child_process.*exec\(|execSync\(|spawn\(.*\{.*shell:\s*true'
targetSkill: ai-sdk
message: 'Shell exec for code execution detected — loading AI SDK guidance for tool-calling patterns that pair with Vercel Sandbox for safe agent execution.'Vercel Sandbox runs untrusted or AI-generated code inside an ephemeral Firecracker microVM. You get a real Linux VM with a filesystem and network — created on demand over an API, and stopped (or snapshotted) when you're done. Reach for it when code you don't fully trust needs to run: AI agent tool calls, code generation, user submissions, builds, or experiments.
Do **not** use in-process sandboxes like `vm2` (known escapes) or `child_process`/`eval` for untrusted code. Those share your process; a Sandbox is a separate VM.
pnpm add @vercel/sandbox # or npm i / yarn add / bun add
There is also a Python SDK (`vercel` package, `vercel.sandbox`) and a `sandbox` CLI. This skill shows the JS SDK unless noted.
The core loop is create → run → stop. For one-off work, stop in a `finally` so a thrown error can't leak a running VM (you're billed while it runs). `stop()` is safe to call more than once.
import { Sandbox } from "@vercel/sandbox";
const sandbox = await Sandbox.create();
try {
const result = await sandbox.runCommand("python3", ["-c", "print(2 + 2)"]);
console.log(await result.stdout()); // "4\n"
console.log(result.exitCode); // 0
} finally {
await sandbox.stop();
}`Sandbox.create()` with no arguments boots the default image (`vercel/sandbox/universal`, Ubuntu with Node.js 24, Python 3.14 as `python3`, and common tools), 2 vCPUs, and a 5-minute timeout.
This is auth for the process **calling** the SDK. It is separate from any credential you want available **inside** the VM — the sandbox does not automatically carry your `VERCEL_OIDC_TOKEN` (see [Running AI agents](#running-ai-agents-in-a-sandbox)).
Common `Sandbox.create()` options (all optional):
| Option | Default | Notes | |---|---|---| | `image` | `vercel/sandbox/universal` | Managed image, or a custom/public VCR image. See [Images](#i
Comprehensive Vercel ecosystem plugin — relational knowledge graph, skills for every major product, specialized agents, and Vercel conventions. Turns any AI agent into a Vercel expert.
Repo: vercel-labs/vercel-plugin
Advanced AI agent benchmark scenarios that push Vercel's cutting-edge platform features —…
End-to-end benchmark suite for vercel-plugin. Runs realistic projects through skill…
Run vercel-plugin eval scenarios in Vercel Sandboxes instead of local WezTerm panels.…
Create and launch benchmark test projects to exercise vercel-plugin skill injection across…
Audit vercel-plugin performance on real-world projects. Extracts tool calls from Claude Code…
Release vercel-plugin — run gates, bump version, generate artifacts, commit, and push. Use…