SandBase Skills Library
Installable open-source Agent Skills for research, social intelligence, marketing and business workflows, working with Claude Code, Codex, Cursor, Gemini CLI and DeepSeek Harness.
- Source repo
- sandbaseai/sandbase-skills
- Stars
- ★ 201
- Last updated
- 2d ago
- License
- Apache-2.0
- Primary language
- Python
- FA score
- 50/100 · Major gaps
At a glance
- How it runs
- Works with
- Universal · cross-platformCodex · Claude CodeChatGPT (Needs adaptation)
- Cost
- Free software; you pay for model usage
- Setup effort
- Low · running in minutes
- You'll need
- Typical use
- A market or intelligence analyst verifying a market claim, using multi-source-search to cross-check independent sources and emit an auditable evidence ledger
- Not a fit if
- Users who want a single chat assistant and won't install instruction files into an AI agent
- Teams that need deep social/market provider capabilities but refuse to register a SandBase account
- Source review
- 50/100 · Major gaps
What does this agent do, and when should you use it?
SandBase Skills (repository sandbaseai/sandbase-skills) is an Apache-2.0 open-source collection of installable Agent Skills — the README states 245 (the repo description says 88) — organized into research, social intelligence, business intelligence, marketing & SEO, media generation, data science, software engineering, and utility catalogs. Each Skill is a SKILL.md instruction file that defines a repeatable workflow, evidence rules, and an output format that a host agent reads and executes. The repository separates hand-written Skill sources (research/, marketing/) from generated catalog metadata (catalog/skills/, skills.) and per-client packaging (agent-plugin/, .claude-plugin/, dsh/), with consistency enforced by npm test, marketplace:check, and scripts/skillpack.py validate. The flagship multi-source-search Skill runs on host-provided search and page-reading tools and produces an evidence ledger that can be validated offline, with no SandBase account required; specialized social, market, and data Skills additionally use SANDBASE_API_KEY to tap SandBase's 2,000+ models and APIs. The deployment boundary is clear: Skills are instructions only — execution, searching, and media generation happen in the host agent and whatever tools it is connected to.
Once installed, the agent reads each Skill's SKILL.md and follows the workflow it defines. For example, multi-source-search cross-checks a claim using the host's existing search tools, builds a source-linked evidence ledger, and can verify report consistency offline:bashpython3 research/multi-source-search/scripts/validate_report.py examples/verifiable-research-report.
` The validator rejects unknown or duplicate sources, inflated confidence, unused evidence, and high-confidence claims with a declared conflict. The 14 social Skills (twitter-intelligence, youtube-research, weibo-research, xiaohongshu-research, …) search posts, track trends, and analyze sentiment across major platforms; market-research and competitor-monitor produce market and competitive intelligence; seo-content-brief generates SERP-backed content briefs. With SANDBASE_API_KEY configured, Skills call SandBase providers via sandbase_discover → sandbase_inspect → sandbase_run (polling async results with sandbase_run_get); the separate SandBase CLI exposes 2,000+ models and APIs to the same agent as six MCP tools.
- A market or intelligence analyst verifying a market claim, using multi-source-search to cross-check independent sources and emit an auditable evidence ledger
- A social media manager comparing this month's sentiment and recurring complaints for two brands on X via twitter-intelligence
- A growth marketer tracking three competitors' pricing, launches, content, and social activity with competitor-monitor's dated competitive-intelligence brief
- An SEO content lead producing a writer-ready brief for a target keyword, with search intent, competing pages, and differentiation angles from seo-content-brief
- A recruiter or investor assessing an engineering team's open-source activity with github-profile-research's repository, language, contribution, and star analysis
- Researchers in the China market monitoring topics and sentiment across WeChat, Weibo, Xiaohongshu, and Douyin using weibo-research, xiaohongshu-research, and china-social-research
How do you install or deploy this agent?
Skills are free and open source (Apache-2.0). Try without installing:
bash
npx skills use sandbaseai/sandbase-skills@multi-source-searchInstall into Codex:
bash
npx skills add sandbaseai/sandbase-skills@multi-source-search --agent codexGitHub CLI 2.90.0+ can preview before installing:
bash
gh skill preview sandbaseai/sandbase-skills research/multi-source-search
gh skill install sandbaseai/sandbase-skills research/multi-source-search --agent codex --scope userPortable Agent Plugin (Copilot CLI and compatible clients):
bash
copilot plugin install sandbaseai/sandbase-skills:agent-pluginDeepSeek Harness (all Skills):
bash
dsh plugin --profile web add github:sandbaseai/sandbase-skills
dsh webClaude Code marketplace (all Skills):
text
/plugin marketplace add sandbaseai/sandbase-skills
/plugin install sandbase-skills@sandbase-agent-skillsThe flagship Skill needs no account when the host already provides search tools; specialized social/market/data Skills require SANDBASE_API_KEY in your environment — never in a prompt or committed file.
How do you use this agent?
Install a Skill, then give your agent a task, e.g. to multi-source-search: "Fact-check this claim with independent sources and validate the evidence ledger." The flow: user question → agent reads SKILL.md → host-compatible search or browser tools are used first → if configured, SandBase providers are called via sandbase_discover/sandbase_inspect/sandbase_run → the agent executes the workflow, validates structured evidence, and delivers the result. Verify research output offline:
bash
python3 research/multi-source-search/scripts/validate_report.py examples/verifiable-research-report.
To add SandBase's 2,000+ models and APIs as MCP tools in the same agent:
bash
npx -y https://github.com/sandbaseai/cli/releases/download/v0.1.17/sandbaseai-cli-0.1.17.tgz connect --client codexInstall other Skills by name:
bash
npx skills add sandbaseai/sandbase-skills@<skill-name> --agent codex --global
npx skills add sandbaseai/sandbase-skills --listWhat are this agent's strengths and limitations?
- The flagship multi-source-search runs entirely on host-provided tools with an offline evidence-ledger validator — zero accounts and no vendor lock-in
- One Skill source ships to many agents: Codex, Claude Code marketplace, Copilot CLI Agent Plugin, DeepSeek Harness bundle, plus npx skills add for Cursor, Gemini CLI and more
- Broad catalog — 245 Skills spanning multi-platform China social research (WeChat, Weibo, Xiaohongshu, Douyin), SEO, competitor monitoring, data science, and software engineering — with catalog metadata and CI consistency checks
- The evidence-ledger validator concretely rejects duplicate sources, inflated confidence, and unused evidence, making research output auditable
- Skills are instruction files only; real-world quality depends heavily on the host agent and its tools, and the repo does not provide per-Skill verifiable evidence for all 245 entries
- Specialized social, market, and data Skills require SANDBASE_API_KEY, and SandBase API calls are usage-based (typical research task $0.05–$0.20), creating partial dependence on the SandBase ecosystem
- The Skill count is inconsistent in the source (88 in the repo description vs. 245 in the README), and many Skill descriptions are templated boilerplate, so depth must be verified per Skill
- The offline validator checks internal consistency only; it does not attest that a source is true — trust remains with the user
How does this agent compare with similar options?
The repository distributes its Skills through multiple directories (skills.sh, AgentSkill.sh, Agentic Awesome Skills, Agent Skill Exchange, askill, and others) and states compliance with the Agent Skills specification and the vendor-neutral Agent Plugins 1.0 specification; its differentiator versus client-specific skill collections is that the same canonical source is packaged for Codex, Claude Code marketplace, Copilot CLI, and DeepSeek Harness. The source does not provide a functional comparison against specific competitor libraries.
Key facts side by side with the most closely related agents.
| Agent | Source review | Form / cost | Stars | Updated | Language | Full support on |
|---|---|---|---|---|---|---|
| SandBase Skills Library This agent | 50 · Major gaps | Agent plugin / skillFree + model costs | ★ 201 | 2d ago | Python | Codex · Claude Code |
| Harness Desktop | 82 · Good | Desktop appFree + model costs | ★ 10 | 4d ago | JavaScript | — |
| DeepChat | 66 · Some gaps | Desktop appFree + model costs | ★ 6.3k | 4d ago | TypeScript | OpenAI API · Claude API |
| Event Planning Multi-Agent System | 62 · Some gaps | CLIFree + model costs | ★ 115 | 5mo ago | Python | — |
How does FollowAgents rate this agent?
Why each dimension lost points
Least privilege, user confirmation, data-flow transparency, sensitive-data handling, external effects and rollback are all asserted only at README level (e.g. --force before overwrite, an evidence log); no SKILL.md or script bodies are in evidence to verify actual permissions or network behavior — deducted for unverifiable skill internals. LICENSE plus THIRD_PARTY_NOTICES.md (listed in package. files) support source attribution, scored 2.
Tests show the validator emits specific errors for duplicate URLs, inflated confidence, and unreferenced sources (scored 2); but self-consistency is in doubt: the review object says 88 skills while README.de.md claims 245, and the evidence cannot adjudicate; dependency availability requires both Node>=20 and Python3 with no lockfile evidence — scored 1.
Targets multiple agents (Claude Code, Codex, Cursor, Gemini CLI, DeepSeek Harness, etc.) with 8 localized READMEs and environment-specific install paths (.dsh/skills), scoring 2 on environment fit; capability boundaries and trigger precision lack any skill-definition evidence and are bare claims, scored 1.
Information architecture, install notes, and naming stability are test-enforced (catalog count matches directories, skills.sh groups deduplicated, every localized README contains install commands); examples include a verifiable report sample. Deducted for: no known-limitations statement, no CHANGELOG (only package. 0.3.5), and an Apache-2.0 file with an unfilled copyright placeholder. SECURITY.md private-vulnerability process and the CI validation workflow support maintenance responsibility at 2.
Output usability is backed by an evidence-report JSON schema and offline validator; multi-source-search works without an account, giving reasonable marginal value and cost/benefit; without execution evidence of output quality, conservatively scored 2 across.
The validator enforces independent-source counts, rejects duplicate URLs (including tracking-parameter normalization), rejects high confidence under conflict, and requires a gaps field — claim traceability and fact/inference separation design is solid (2 each); only the mechanism is statically confirmed, actual retrieval quality is unverifiable, hence not 3.
- The object description says 88 skills while the README claims 245 — the count is inconsistent; verify the actual skill directories before installing.
- Skill sources (SKILL.md, scripts) are not in evidence; actual permissions, network calls, and side effects cannot be statically verified — review each skill after installation.
- Force-install overwrites existing skills; tests cover the guard but no backup/rollback mechanism is documented.
- Tests and runtime require both Node>=20 and Python3; provision the environment accordingly.
- Publisher identity is unverified; base trust on code review, not branding.