From ralph-town
Daytona sandbox security. Use for token handling, credential security, full paths in SSH.
How this skill is triggered — by the user, by Claude, or both
Slash command
/ralph-town:sandbox-securityThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
SSH sessions have broken PATH. ALWAYS use full paths:
SSH sessions have broken PATH. ALWAYS use full paths:
| Tool | Path |
|---|---|
| git | /usr/bin/git |
| gh | /usr/bin/gh |
| bun | /root/.bun/bin/bun |
| ls/cat/echo | /bin/ls, /bin/cat, /bin/echo |
NEVER embed tokens in URLs - they leak to process list, logs, errors.
# BAD - token visible in ps, logs, error messages
/usr/bin/git clone https://[email protected]/owner/repo.git
# GOOD - use credential helper
/usr/bin/git config --global credential.helper store
/bin/echo "https://oauth2:[email protected]" > ~/.git-credentials
/bin/chmod 600 ~/.git-credentials
/usr/bin/git clone https://github.com/owner/repo.git
Env vars via --env are visible to ALL processes in sandbox:
env command lists everything/proc/*/environ exposes all process env vars$GH_TOKENMitigations:
Team-lead configures credentials BEFORE spawning teammate:
# $GH_TOKEN expands LOCALLY (double quotes!)
ssh <token>@ssh.app.daytona.io "
/usr/bin/git config --global credential.helper store &&
/bin/echo 'https://oauth2:[email protected]' > ~/.git-credentials &&
/bin/chmod 600 ~/.git-credentials
"
npx claudepluginhub spences10/ralph-town --plugin ralph-townExecutes untrusted Python/Node.js code in isolated Linux containers at the edge via Cloudflare Sandboxes SDK. Useful for AI code interpreters, git operations, and ephemeral workspaces.
Manages environment variables securely to prevent secret exposure in Claude sessions, terminals, logs, and git commits.
Creates, edits, and verifies skills using a test-driven development approach with pressure scenarios and subagents.