agentCLAWHUBUnverified

claudebox

Install, configure, or run Claude Code through the claudebox wrapper, or connect to its HTTP, MCP, Telegram, or cron surfaces. Skill: claudebox Owner: psyb0t Summary: Install, configure, or run Claude Code through the claudebox wrapper, or connect to its HTTP, MCP, Telegram, or cron surfaces. Tags: latest:2.5.0 Version history: v2.5.0 | 2026-10-07T17:20:21.602Z | auto cluedebox v2.5.0 changelog: - Updated reference documentation in references/setup.md. - Removed skill-card.md file. - No changes to command-line interface or functionality—docu

OpenClaw

Rank

62

Safety

84

Downloads

1.7k

Updated

Oct 10, 2026

Version

2.5.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.7K downloadsadoption · observed Oct 10, 2026
Latest release
2.5.0release · observed Oct 7, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:claudebox
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-claudebox/snapshot"

Documentation

CLAWHUB

148,317 characters of source documentation, loaded on request.

Extracted files

4 files captured from the source.

SKILL.md

---
name: claudebox
description: "Install, configure, or run Claude Code through the claudebox wrapper, or connect to its HTTP, MCP, Telegram, or cron surfaces."
homepage: https://github.com/psyb0t/docker-claudebox
user-invocable: true
metadata:
  { "openclaw": { "emoji": "📦", "primaryEnv": "CLAUDEBOX_URL", "requires": { "bins": ["docker", "curl"] } } }
---

# claudebox

Claude Code — the agentic coding CLI from Anthropic — running in an isolated Docker container with dev tools, passwordless sudo, docker-in-docker, and `--permission-mode bypassPermissions` on by default. Built as a thin child image of `psyb0t/aicodebox`; every server-mode surface (API / OpenAI adapter / MCP / Telegram / Cron) is inherited from that base.

## Agent execution

Use `claudebox` when it is on `PATH`. Run it from the workspace the user
named. Do not assemble a new `docker run` command for routine interactive or
one-shot work. The wrapper owns the workspace mount, `~/.claude`, SSH state,
image selection, and session lifecycle.

```bash
claudebox                                      # interactive Claude Code
claudebox -p "inspect this workspace"          # one-shot work
claudebox -p "emit events" --output-format stream-json
CLAUDEBOX_FULL=1 claudebox -p "run the full suite"
```

For a wrapper-started server, prefix container variables with
`CLAUDEBOX_ENV_`. For example,
`CLAUDEBOX_ENV_CLAUDEBOX_API_MODE=1 claudebox` passes
`CLAUDEBOX_API_MODE=1` into the container. Bare `CLAUDEBOX_API_MODE` is not
forwarded and does not start the server.

Start a local API and MCP server only when the user asks for one. Authenticate
Claude first, then use distinct bearer tokens for the two surfaces:

```bash
CLAUDEBOX_ENV_CLAUDEBOX_API_MODE=1 \
CLAUDEBOX_ENV_CLAUDEBOX_MCP_MODE=1 \
CLAUDEBOX_ENV_CLAUDEBOX_API_MODE_TOKEN=your-api-token \
CLAUDEBOX_ENV_CLAUDEBOX_MCP_MODE_TOKEN=your-mcp-token \
claudebox
```

Use an HTTP or MCP endpoint only when the user asks for a service or provides
an already-running remote URL. MCP plugins connect to a server. They do not
replace the local wrapper.

If `claudebox`, `codexbox`, and `pibox` were installed in the same command
directory, a box can invoke a sibling command directly. The parent wrapper
passes the real host paths and the sibling wrapper file. Do not set
`AICODEBOX_HOST_*`, copy wrapper files, or manually mount another box's state
directory. If the sibling command is absent, ask the user to install it or to
choose another approach.

## Security & safety

- **No auth when the per-mode token is unset.** `CLAUDEBOX_API_MODE_TOKEN` and `CLAUDEBOX_MCP_MODE_TOKEN` each default to no auth if unset — see [HTTP REST API mode](#http-rest-api-mode) and [MCP server mode](#mcp-server-mode) for details and the exact capability exposed unauthenticated in each case.
- **File operations include removal.** Deleting a workspace file has no undo — only remove files the current task created, and only when the user asked.
- **The standard wrapper mounts `/var/run/d

_meta.json

{
  "ownerId": "kn79dhvmpjng4rp2jjk8k0v5xx80ccbk",
  "slug": "claudebox",
  "version": "2.5.0",
  "publishedAt": 1791393621602
}

references/setup.md

# claudebox setup

## Requirements

- Docker installed and running. That's it — the wrapper handles the rest.
- An Anthropic credential: `CLAUDE_CODE_OAUTH_TOKEN` (via `claudebox setup-token`) or `ANTHROPIC_API_KEY`.

For ordinary agent work, use the installed `claudebox` command from the target
workspace. Do not replace it with a hand-written Docker invocation. The
wrapper handles the workspace, state, SSH, image, and nested launch context.

## Quick Install (CLI wrapper)

Safer path — download, inspect, then run:

```bash
curl -fsSL https://raw.githubusercontent.com/psyb0t/docker-claudebox/master/install.sh -o install.sh
less install.sh   # read it before running anything you downloaded
bash install.sh

# full image variant
export CLAUDEBOX_FULL=1 && bash install.sh

# custom binary name
bash install.sh claude
```

Downloading and reading the script before running it is the recommended flow, especially in an agent-driven or CI context — it runs with your privileges.

The installer pulls the image, generates an ed25519 SSH key at `~/.ssh/claudebox/id_ed25519` for git operations inside the container, creates `~/.claude`, and installs the wrapper to `/usr/local/bin/claudebox` (override with `CLAUDEBOX_INSTALL_DIR` / `CLAUDEBOX_BIN_NAME`). Add the generated public key to GitHub/GitLab for git push/pull to work from inside the container.

```bash
claudebox                                  # interactive
claudebox -p "inspect this workspace"      # one-shot
CLAUDEBOX_FULL=1 claudebox -p "run tests"  # temporary full image
```

For a wrapper-started server, use `CLAUDEBOX_ENV_` before every variable that
must reach the container. For example,
`CLAUDEBOX_ENV_CLAUDEBOX_API_MODE=1 claudebox` starts API mode.

Install `claudebox`, `codexbox`, and `pibox` in the same command directory,
normally `/usr/local/bin`, when one box needs to launch another. The parent
mounts only sibling wrapper files read-only. A sibling wrapper then runs through
the host Docker daemon and mounts its own host data directory.

Manual setup without piping to bash: `mkdir -p ~/.claude`, generate the SSH key yourself, `docker pull psyb0t/claudebox:latest` (or `:latest-full`), then fetch `wrapper.sh` and install it as your `claudebox` binary.

## Image Variants

| | `psyb0t/claudebox:latest` (minimal, default) | `psyb0t/claudebox:latest-full` |
| --- | --- | --- |
| Base | Ubuntu 24.04, git/curl/wget/jq, Node.js 24 LTS, Python 3.14 + uv, Docker CE | same, plus everything below |
| Go | — | 1.26 toolchain (golangci-lint, gopls, delve, staticcheck, gofumpt, gotests, impl, gomodifytags) |
| Python | — | 3.14 via pyenv (flake8, black, isort, pyright, mypy, vulture, pytest, poetry, pipenv) |
| Node dev tools | — | eslint, prettier, typescript, yarn, pnpm, framework CLIs |
| C/C++ | — | gcc, g++, make, cmake, clang-format, valgrind, gdb |
| DevOps | — | terraform, kubectl, helm, gh |
| DB clients | — | sqlite3, psql, mysql, redis-cli |
| Shell utils | — | ripgrep, bat, exa, fd-find, ag, htop

skill-card.md

## Description:

Install and run Claude Code in a Docker-backed workspace, or connect to its HTTP, MCP, Telegram, and scheduled-job interfaces.

This skill is ready for commercial/non-commercial use.

## Publisher:

[psyb0t](https://clawhub.ai/user/psyb0t)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and engineers use Claudebox to run Claude Code locally or from automation, and to configure authenticated services for remote or scheduled agent tasks.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Unauthenticated HTTP or MCP endpoints can expose agent execution and workspace file control.

Mitigation: Set separate API and MCP tokens; bind services to loopback or protect them with an authenticated proxy.

Risk: Agent tasks can access host Docker or mounted credentials when run through the standard wrapper.

Mitigation: Keep untrusted prompts out of privileged runtimes; isolate workspaces and omit the Docker socket when it is unnecessary.

Risk: Installing remote scripts or using mutable images can run unreviewed code.

Mitigation: Inspect the installer and image provenance before use, and prefer pinned images and packages.

Risk: File-control operations can delete workspace files without an undo path.

Mitigation: Confirm target paths and only delete files the current task created when removal was requested.

## Reference(s):

- [Claudebox setup guide](references/setup.md)
- [Claudebox project homepage](https://github.com/psyb0t/docker-claudebox)
- [Claudebox release on ClawHub](https://clawhub.ai/psyb0t/skills/claudebox)

## Skill Output:

**Output Type(s):** [Guidance, Shell commands, Configuration]

**Output Format:** [Markdown with shell commands and configuration examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Agent responses may include text, code, and structured results from the configured runtime.]

## Skill Version(s):

2.5.0 (source: ClawHub release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 12h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/psyb0t/skills/claudebox",
      "sourceUrl": "https://clawhub.ai/psyb0t/skills/claudebox",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T04:35:01.162Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-claudebox/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-claudebox/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T04:35:01.162Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.7K downloads",
      "href": "https://clawhub.ai/psyb0t/claudebox",
      "sourceUrl": "https://clawhub.ai/psyb0t/claudebox",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T04:35:01.162Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "2.5.0",
      "href": "https://clawhub.ai/psyb0t/claudebox",
      "sourceUrl": "https://clawhub.ai/psyb0t/claudebox",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-07T17:20:21.602Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-claudebox/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-claudebox/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 2.5.0",
      "description": "cluedebox v2.5.0 changelog: - Updated reference documentation in references/setup.md. - Removed skill-card.md file. - No changes to command-line interface or functionality—documentation only. - Skill description, usage, and security guidance remain unchanged.",
      "href": "https://clawhub.ai/psyb0t/claudebox",
      "sourceUrl": "https://clawhub.ai/psyb0t/claudebox",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-07T17:20:21.602Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to claudebox and adjacent AI workflows.