Agent skill

Cosa Dev

by coreos in coreos/coreos-assembler

Develop and test changes to coreos-assembler itself -- build mantle Go binaries (kola, ore, plume), iterate on Python/shell scripts, or do full container rebuilds

Apache-2.0Auto-check passedDevelopment

Install Cosa Dev

skills CLI
$ npx skills add coreos/coreos-assembler --skill cosa-dev -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install coreos/coreos-assembler cosa-dev --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/coreos/coreos-assembler.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cosa-dev .claude/skills/cosa-dev && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cosa-dev
GitHub stars
395
Token cost
~2k tokens
SKILL.md length
814 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Develop and test changes to coreos-assembler itself -- build mantle Go binaries (kola, ore, plume), iterate on Python/shell scripts, or do full container rebuilds

  • Works in 5 steps: Create output and cache directories → Build the binary → Quick compilation check (no binary output) → …
  • Tasks that involve Shell scripting
  • SKILL.md covers Related skills, Key documentation references, Choosing an approach and Approach 1: Modifying mantle…, plus 3 more sections
  • Calls go, podman and make; reaches github.com

What it does

Cosa Dev is an agent skill from coreos/coreos-assembler. Develop and test changes to coreos-assembler itself -- build mantle Go binaries (kola, ore, plume), iterate on Python/shell scripts, or do full container rebuilds

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Shell scripting and Containers. It works with Python. The repository describes itself as: Tooling container to assemble CoreOS-like systems. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Shell scripting
  • Tasks that involve Containers

Example prompts

  • “/cosa-dev”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Create output and cache directories
  2. Build the binary
  3. Quick compilation check (no binary output)
  4. Test with the modified binary
  5. Iterate

What it can do on your machine

Read from SKILL.md and the folder at commit 4ab8b08. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • podman
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cosa Dev loads about 2k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 814 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from coreos/coreos-assembler at commit 4ab8b08, republished under its Apache-2.0 licence (© coreos). 814 words, ~1,976 tokens.

Download SKILL.mdSave it as .claude/skills/cosa-dev/SKILL.md (or your agent's skills folder).
name
cosa-dev
description
Develop and test changes to coreos-assembler itself -- build mantle Go binaries (kola, ore, plume), iterate on Python/shell scripts, or do full container rebuilds

Developing coreos-assembler

This skill covers workflows for making and testing changes to coreos-assembler (COSA) itself, including the Go binaries in mantle/, the Python/shell scripts in src/, and the container image.

  • Load the cosa-basics skill for the cosa() bash alias, workdir setup, and general build workflow.
  • Load the cosa-kola skill for running kola tests.
  • Load the cosa-platforms skill for cloud platform testing.

Key documentation references

Do NOT duplicate these docs. Read them at runtime for command details:

FileWhat it covers
docs/devel.mdDeveloper workflows: hacking scripts, building Go binaries, container rebuilds
docs/building-fcos.mdThe cosa() bash alias definition
MakefileBuild targets: mantle, kola, ore, plume, kolet, install
mantle/buildMantle build script (called by make kola etc.)
build.shContainer image build steps
DockerfileContainer image definition

Choosing an approach

What changedApproachRebuild time
Go code in mantle/ onlyBuild single binary, mount over container copy~2 min cold, seconds warm
Python/shell in src/ onlySet COREOS_ASSEMBLER_GITInstant (no rebuild)
Both Go and Python/shellCombine both approaches~2 min cold, seconds warm
Dockerfile, RPM deps, or everythingFull podman buildSeveral minutes

Approach 1: Modifying mantle Go binaries (kola, ore, plume)

Use this when changing Go code under mantle/. The idea is to build the binary inside the cosa container (which has the Go toolchain), write it to a host directory, then mount it over the container's installed copy on subsequent runs.

Buildable binaries
Source pathBinary nameInstalled at
mantle/cmd/kolakola/usr/bin/kola
mantle/cmd/oreore/usr/bin/ore
mantle/cmd/plumeplume/usr/bin/plume
mantle/cmd/koletkolet/usr/lib/kola/<arch>/kolet
Step 1: Create output and cache directories
mkdir -p /tmp/cosa-go-cache /tmp/cosa-bin
chmod 777 /tmp/cosa-go-cache /tmp/cosa-bin

The chmod 777 is needed because the cosa container runs as uid 1000 (builder) via --userns=keep-id, and the directories must be writable by that mapped user.

Step 2: Build the binary

Mount the cosa source tree, the output directory, and optionally a persistent Go build cache into the container:

export COREOS_ASSEMBLER_CONTAINER_RUNTIME_ARGS="\
  -v=/path/to/coreos-assembler:/srv/cosa-src:ro \
  -v=/tmp/cosa-bin:/srv/cosa-bin:rw \
  -v=/tmp/cosa-go-cache:/home/builder/.cache/go-build:rw"

cosa shell -- bash -c \
  'cd /srv/cosa-src && go build -buildvcs=false -o /srv/cosa-bin/kola ./mantle/cmd/kola'

Replace kola with ore or plume as needed. To build all mantle binaries at once:

cosa shell -- bash -c \
  'cd /srv/cosa-src && \
   for cmd in kola ore plume; do \
     go build -buildvcs=false -o /srv/cosa-bin/$cmd ./mantle/cmd/$cmd; \
   done'

Key flags:

  • -buildvcs=false -- required to avoid git ownership errors inside the container (the source tree is mounted from the host with a different uid).
  • The persistent Go build cache (/home/builder/.cache/go-build) makes subsequent rebuilds incremental. The first build downloads and compiles all dependencies (~2 minutes); rebuilds after a small code change take only a few seconds.
Step 3: Quick compilation check (no binary output)

To verify that the code compiles without producing a binary:

cosa shell -- bash -c \
  'cd /srv/cosa-src && go build -buildvcs=false ./mantle/...'
Step 4: Test with the modified binary

Mount the built binary over the container's installed copy using COREOS_ASSEMBLER_CONTAINER_RUNTIME_ARGS:

export COREOS_ASSEMBLER_CONTAINER_RUNTIME_ARGS="\
  -v=/tmp/cosa-bin/kola:/usr/bin/kola:ro"

cosa kola run -p qemu basic

This can be combined with other mounts. For example, to also mount AWS credentials:

export COREOS_ASSEMBLER_CONTAINER_RUNTIME_ARGS="\
  -v=/tmp/cosa-bin/kola:/usr/bin/kola:ro \
  -v=/path/to/aws-creds:/srv/aws-creds:ro"

cosa kola run -p aws --aws-credentials-file /srv/aws-creds basic
Step 5: Iterate

After making further code changes, re-run the build command from Step 2. With the persistent Go cache, only the changed packages are recompiled. Then re-run the test from Step 4 -- the mount picks up the new binary automatically.

Show full SKILL.md (346 more words)Show less

Approach 2: Modifying Python/shell scripts (src/)

Use this when changing files under src/ (e.g. src/cmd-build, src/cmd-init, src/cosalib/*.py). No rebuild is needed.

Set the COREOS_ASSEMBLER_GIT environment variable to point at your local coreos-assembler checkout. The cosa() bash alias will automatically mount $COREOS_ASSEMBLER_GIT/src/ over /usr/lib/coreos-assembler/ inside the container:

export COREOS_ASSEMBLER_GIT=/path/to/coreos-assembler
cosa init https://github.com/coreos/fedora-coreos-config
cosa build

Changes to files under src/ take effect immediately on the next cosa invocation. No rebuild or remount is required.

Limitation: This only covers files installed to /usr/lib/coreos-assembler/ (i.e. src/ contents). It does NOT affect Go binaries (kola, ore, plume) or system packages. For Go changes, combine this with Approach 1.

Combining with Go binary changes
export COREOS_ASSEMBLER_GIT=/path/to/coreos-assembler
export COREOS_ASSEMBLER_CONTAINER_RUNTIME_ARGS="\
  -v=/tmp/cosa-bin/kola:/usr/bin/kola:ro"

cosa kola run basic

This uses the modified Python/shell scripts from COREOS_ASSEMBLER_GIT AND the modified kola binary from the mount.

Approach 3: Full container rebuild

Use this when changing the Dockerfile, adding or updating RPM dependencies, or when you want to verify everything works together as a complete image.

Build the container image

From the coreos-assembler repo root:

podman build -t localhost/coreos-assembler .

To speed things up by reusing the official image as a base (useful when only cosa code changed, not dependencies):

podman build -t localhost/coreos-assembler . \
  --from quay.io/coreos-assembler/coreos-assembler:latest
Use the locally-built container

Set COREOS_ASSEMBLER_CONTAINER so the cosa() alias uses your local image instead of the upstream one:

export COREOS_ASSEMBLER_CONTAINER=localhost/coreos-assembler
cosa init https://github.com/coreos/fedora-coreos-config
cosa build

This is the slowest approach but the most complete. It is needed when:

  • The Dockerfile or build.sh changed.
  • System RPM dependencies were added or updated.
  • You want a final integration check before submitting a PR.

Important notes

  • The cosa() bash alias creates a transient container for each invocation. All state persists in the cosa workdir (mounted at /srv/), not inside the container. This is why mounting files in via COREOS_ASSEMBLER_CONTAINER_RUNTIME_ARGS works -- each run gets the latest version of whatever is mounted.
  • Use cosa shell to get a persistent interactive session inside the container. This is useful for running multiple build/test commands without container startup overhead. However, be aware that mounted binaries are fixed at container start time.
  • The Go build cache directory inside the container is /home/builder/.cache/go-build. Persisting it to the host avoids cold rebuilds.
  • When mounting binaries with :ro, the container cannot modify them. This is intentional -- it prevents accidental overwrites.

© coreos, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/cosa-dev of coreos/coreos-assembler.

Open the folder on GitHubat commit 4ab8b08

Compare with similar skills

Cosa Dev next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cosa Dev compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cosa Dev this skillcoreos/coreos-assembler395—~2kAutomated safety check: PassApache-2.0
New Mac Setupswyxio/skills172—~4.3kAutomated safety check: PassMIT
Flowfile Build and Environment SetupEdwardvaneechoud/Flowfile370—~7.3kAutomated safety check: NotesMIT
Code ReviewAzure/sap-automation145—~7kAutomated safety check: PassMIT
Env Doctor Freeaiskillstore/marketplace430—~1.5kAutomated safety check: NotesMIT
Shellpproenca/dot-skills214—~1.9kAutomated safety check: PassMIT

Similar skills

  • New Mac Setup

    swyxio/skills

    Fully automated new Mac setup for fullstack web developers and AI engineers.

    172 GitHub stars~4.3k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Flowfile Build and Environment Setup

    Edwardvaneechoud/Flowfile

    Recreates every Flowfile development and build environment from scratch, with exact version pins and an explanation of what each Makefile target really does.

    370 GitHub stars~7.3k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Code Review

    Azure/sap-automation

    Official

    Review pull requests in the SAP Deployment Automation Framework.

    145 GitHub stars~7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Env Doctor Free

    aiskillstore/marketplace

    Diagnose local project environment issues that prevent apps from starting or running.

    430 GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Shell

    pproenca/dot-skills

    Shell scripting best practices for writing safe, portable, and maintainable bash/sh scripts.

    214 GitHub stars~1.9k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • CLI Developer

    Jeffallan/claude-skills

    Walks through designing, building and polishing a command-line tool: user workflow and command hierarchy, implementation in commander, click, typer or cobra, completions and cross-platform testing.

    12k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed

More from coreos/coreos-assembler

  • Cosa Basics

    coreos/coreos-assembler

    Initialize a COSA workdir, build or fetch Fedora CoreOS images, and launch local QEMU VMs using coreos-assembler

    395 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Cosa Kola

    coreos/coreos-assembler

    Run kola tests against CoreOS builds using coreos-assembler, including native and external tests

    395 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Cosa Platforms

    coreos/coreos-assembler

    Build disk images, upload to cloud providers, and run tests or spawn instances on non-QEMU platforms (AWS, GCP, Azure, ISO, metal, etc.)

    395 GitHub stars~1.6k tokensUpdated today
    Auto-check: warnings

Works with

Questions about Cosa Dev

What does Cosa Dev do?

Develop and test changes to coreos-assembler itself -- build mantle Go binaries (kola, ore, plume), iterate on Python/shell scripts, or do full container rebuilds. Cosa Dev is an agent skill from coreos/coreos-assembler.

When should I use Cosa Dev?

Cosa Dev fits situations like: tasks that involve Shell scripting; tasks that involve Containers.

How do I install Cosa Dev in Claude Code?

Run `npx skills add coreos/coreos-assembler --skill cosa-dev -a claude-code`. Or copy the skill folder (.agents/skills/cosa-dev in coreos/coreos-assembler) into .claude/skills/cosa-dev in your project. Claude Code loads it when a task matches its description.

How do I install Cosa Dev in Codex?

Run `npx skills add coreos/coreos-assembler --skill cosa-dev -a codex`. Or copy the skill folder (.agents/skills/cosa-dev in coreos/coreos-assembler) into .agents/skills/cosa-dev in your project. Codex loads it when a task matches its description.

Can I use Cosa Dev in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add coreos/coreos-assembler --skill cosa-dev -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cosa-dev, .gemini/skills/cosa-dev, .github/skills/cosa-dev and .opencode/skills/cosa-dev in your project.

What does Cosa Dev need to run?

Going by SKILL.md and its folder, Cosa Dev needs the command-line tools its instructions call (go, podman and make).

Does Cosa Dev access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Cosa Dev safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cosa Dev use?

Cosa Dev is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cosa Dev use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cosa Dev?

Skills that share tags, products or a category with Cosa Dev: New Mac Setup (swyxio/skills, 172 stars), Flowfile Build and Environment Setup (Edwardvaneechoud/Flowfile, 370 stars), Code Review (Azure/sap-automation, 145 stars) and Env Doctor Free (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cosa Dev?

coreos (a GitHub organization) maintains it in coreos/coreos-assembler, which has 395 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.

Source: coreos/coreos-assembler on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.