Official agent skill

Docker Agent Config

by docker in docker/skills

A skill your agent uses when creating or editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent), including defining agents, models/providers, built-in or MCP toolsets…

OfficialApache-2.0Auto-check: notesDevOps & Cloud

Install Docker Agent Config

skills CLI
$ npx skills add docker/skills --skill docker-agent-config -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install docker/skills docker-agent-config --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/docker-agent-config .claude/skills/docker-agent-config && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
docker-agent-config
GitHub stars
539
Token cost
~2.5k tokens
SKILL.md length
1,036 words
Files
7 (incl. references, assets)
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when creating or editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent), including defining agents, models/providers, built-in or MCP toolsets…

  • Editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent)
  • SKILL.md covers Overview, When to use this skill, Do not use this skill when and Core guidance, plus 4 more sections
  • Calls docker
  • Including defining agents

What it does

Docker Agent Config is an agent skill from docker/skills, published by the product's own GitHub organization. Use this skill when creating or editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent), including defining agents, models/providers, built-in or MCP toolsets, multi-agent teams with subagents. Even if the user just says they want to "build an AI agent with Docker", "make a coding agent config", "add a tool to my agent", or "set up a team of agents", this skill applies. Covers agent properties (model, instruction, toolsets, subagents, fallback), the models/providers sections, built-in…

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files and assets (for example `agents/openai.yaml`, `assets/team-agent.yaml` and `checks/verification.md`). Compatibility notes: Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Verified against docker-agent as shipped with Docker…

It sits in DevOps & Cloud, covering Containers and Subagents. It works with Docker and Model Context Protocol. The repository describes itself as: A collection of Docker skills for AI coding agents to help them build, test, debug, and optimize containerized apps with consistent, reusable workflows. The licence is Apache-2.0.

When your agent uses it

  • Editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent)
  • Including defining agents
  • Models/providers
  • Multi-agent teams with subagents

Example prompts

  • “build an AI agent with Docker”
  • “make a coding agent config”
  • “add a tool to my agent”
  • “/docker-agent-config”

Requirements

  • Docker
  • A credential in MY_API_KEY
  • Compatibility (from SKILL.md): Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Verified against docker-agent as shipped with Docker CLI 29.7.2. Config directories still use the legacy `cagent` name (`~/.config/cagent`, `~/.cagent`).

What it can do on your machine

Read from SKILL.md and the folder at commit f791727. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Verified against docker-agent as shipped with Docker CLI 29.7.2. Config directories still use the legacy `cagent` name (`~/.config/cagent`, `~/.cagent`).

    From compatibility in the SKILL.md frontmatter.

Context cost

Docker Agent Config loads about 2.5k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 160 tokens; SKILL.md has 1,036 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~160
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:86
    `~/.config/cagent/.env` written by `docker agent setup`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from docker/skills at commit f791727, republished under its Apache-2.0 licence (© docker). 1,036 words, ~2,485 tokens.

Download SKILL.mdSave it as .claude/skills/docker-agent-config/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
docker-agent-config
description
Use this skill when creating or editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent), including defining agents, models/providers, built-in or MCP toolsets, multi-agent teams with sub_agents. Even if the user just says they want to "build an AI agent with Docker", "make a coding agent config", "add a tool to my agent", or "set up a team of agents", this skill applies. Covers agent properties (model, instruction, toolsets, sub_agents, fallback), the models/providers sections, built-in toolsets (filesystem, shell, think, todo, memory, fetch), MCP toolset references, and named commands.
compatibility
Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Verified against docker-agent as shipped with Docker CLI 29.7.2. Config directories still use the legacy `cagent` name (`~/.config/cagent`, `~/.cagent`).
license
Apache-2.0

Docker Agent Configuration

Overview

Docker Agent (the CLI is docker agent, the open-source project is cagent) runs AI agents declared in a YAML file instead of application code. This skill owns the agent.yaml artifact: the agents section (each entry's model, instruction, and its own toolsets/sub_agents), the top-level models/providers sections referenced from agents, and a top-level commands group agents can opt into with use_commands. It does not cover invoking the CLI or serving/sharing the config — see Related skills.

When to use this skill

Activate this skill when:

  • The user is creating, editing, or reviewing an agent.yaml/agent.yml/agent.hcl file.
  • The user wants to add a tool/toolset, an MCP server, or a sub-agent to an agent config.
  • The user wants to choose or configure a model/provider (OpenAI, Anthropic, Google, Bedrock, Docker Model Runner, custom endpoint) for an agent.
  • The user wants a multi-agent "team" with a coordinator delegating to specialists.

Do not use this skill when

Do not use this skill when:

  • The task is about running the CLI (docker agent run flags, --safety, --sandbox, aliases, worktrees) — use docker-agent-run.
  • The task is about exposing an agent as a server (serve mcp/api/a2a/acp/chat), distributing it (share push/pull), or evaluating it (evaluation sessions, --baseline regression gates) — use docker-agent-deploy.
  • The task is about a generic Dockerfile or Compose service unrelated to Docker Agent — use docker-build-strategies or docker-compose-patterns.

Core guidance

File structure
  • Every config needs at least one agent under top-level agents:. The agent named root, or the first agent defined, is the entry point that receives user messages.
    yaml
    agents:
      root:
        model: anthropic/claude-sonnet-4-5
        description: A coding assistant
        instruction: |
          You are an expert developer. Help users write clean,
          efficient code. Explain your reasoning step by step.
        toolsets:
          - type: filesystem
          - type: shell
          - type: think
  • Required agent properties: model, description, instruction (or instruction_file). description is not decoration — other agents read it to decide whether to delegate to this one, so keep it accurate.
  • Use instruction_file (a relative path, no ..) instead of an inline instruction for long prompts; this keeps diffs focused on behavior, not YAML escaping. instruction and instruction_file are mutually exclusive. instruction_file is not supported for agents loaded from an OCI reference or URL — inline instruction there.
Models and providers
  • Two ways to set a model: inline provider/model shorthand, or a named entry under top-level models: referencing a provider. Use the named form whenever you need temperature, max_tokens, thinking_budget, or reuse across agents.
    yaml
    models:
      claude:
        provider: anthropic
        model: claude-sonnet-4-5
        max_tokens: 64000
    
    agents:
      root:
        model: claude
  • Built-in provider keys: openai, anthropic, google, amazon-bedrock, dmr (Docker Model Runner, local, no API key), ollama (local). Dozens of additional built-in aliases exist (mistral, groq, xai, together, azure, github-copilot, openrouter, ...) — each needs its own <PROVIDER>_API_KEY-style env var; run docker agent models --all to see what's resolvable, and docker agent setup to register credentials interactively instead of hand-editing env vars.
  • Never hardcode an API key in agent.yaml. Provider credentials come from environment variables (token_key for custom providers) or from ~/.config/cagent/.env written by docker agent setup.
  • Prefer dmr/<model> for agents that must run offline or must not send data to a third party; it costs nothing and needs no credential. Use a paid cloud provider only when the task needs it.
  • Give resilience-critical agents a fallback so a provider outage or rate limit does not stop the run:
    yaml
    agents:
      root:
        model: anthropic/claude-sonnet-4-5
        fallback:
          models: [openai/gpt-5, google/gemini-3.5-flash]
          retries: 2      # per model, for 5xx errors
          cooldown: 1m    # stick with fallback after a 429
  • For a self-hosted/OpenAI-compatible endpoint (vLLM, LiteLLM, a corporate gateway), define a providers: entry with base_url and token_key rather than putting the URL inline on every model:
    yaml
    providers:
      my_gateway:
        base_url: https://api.example.com/v1
        token_key: MY_API_KEY
    models:
      my_model:
        provider: my_gateway
        model: gpt-4o
Toolsets
  • Built-in toolsets need no external dependency: filesystem, shell, think, todo, tasks, memory, fetch, background-jobs, script, lsp, api. Add one per list entry:
    yaml
    toolsets:
      - type: filesystem
      - type: shell
  • If an agent only describes a plan but never executes it, add type: todo (or shell) — a common symptom of an agent missing the tool it needs to act, not a model problem.
  • For external tools, prefer an MCP server from Docker's MCP catalog over a bespoke integration — it runs containerized and is reusable across agents:
    yaml
    toolsets:
      - type: mcp
        ref: docker:duckduckgo
    Local stdio and remote HTTP/SSE MCP servers are also supported; see references/toolsets-and-providers.md.
  • Use defer: true on a toolset (MCP or otherwise) to load its tools on-demand instead of at startup, when the agent has many toolsets and startup latency matters.
  • Set readonly: true on an agent to restrict every toolset it uses to read-only tools — use this for reviewer/analysis agents that must not mutate anything.
Show full SKILL.md (388 more words)Show less
Multi-agent teams
  • A coordinator delegates via sub_agents: [name, ...]; listing sub-agents automatically enables the transfer_task tool on the parent.
    yaml
    # Fragment: coder and reviewer are defined separately in the full asset.
    agents:
      root:
        sub_agents: [coder, reviewer]
    Use assets/team-agent.yaml for the complete runnable team, including the reviewer's readonly: true restriction. Keep that restriction when adapting the template; a filesystem toolset alone also exposes writes.
  • sub_agents also accepts external OCI references (myorg/agent:tag). Pin external references to a digest (name@sha256:...) in production configs to skip the per-run registry lookup that a tag incurs.
  • Use transfer_task (via sub_agents) for delegation with a clean, isolated result; use a commands: entry with an agent: field only when you want the user to become that agent for the rest of the session.
Safety and hygiene
  • Set redact_secrets: true on any agent that runs shell/fetch tools against untrusted input. It scrubs recognized secret patterns from tool arguments, outgoing messages, and tool output. This is defense in depth, not a guarantee: arbitrary passwords, tokens, or customer data may go undetected.
  • Set max_iterations on any agent that loops autonomously (default is unlimited) to bound cost and prevent runaway loops; max_consecutive_tool_calls (default 5) already guards against identical-call loops.
  • Keep credentials, tokens, and sensitive customer data out of instruction, instruction_file, and command prompts, whether literal or interpolated. ${env.VAR} expands values into prompt text sent to the model; storing a value in an env file does not prevent this disclosure. Use interpolation only for non-sensitive context.
  • Supply provider credentials through docker agent setup or the provider's supported environment variables. For custom providers, token_key: MY_API_KEY names the environment variable, not its value; do not interpolate it. Configure tool/MCP credentials through that integration's authentication mechanism, not through prompts or model-supplied tool arguments. Prompts should describe the authenticated capability without containing its secret. Do not ask the agent to read or print credential files or environment values to check authentication.
  • For running the agent (docker agent run, safety modes, sandbox, aliases), use docker-agent-run.
  • For serving, sharing, or evaluating the agent, use docker-agent-deploy.

References

  • references/toolsets-and-providers.md — full built-in toolset list, MCP connection modes, and the provider/env-var table.
  • references/sources.md — provenance of every rule in this skill.

Assets

  • assets/team-agent.yaml — a runnable multi-agent team template (coordinator + coder + reviewer).

Checks

  • Before running an agent, follow checks/verification.md to confirm its resolved config, exposed tools, and provider connectivity, then smoke-test it.

© docker, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references, assets) in skills/docker-agent-config of docker/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/team-agent.yaml
  • checks/verification.md
  • references/sources.md
  • references/toolsets-and-providers.md
  • skill.yaml

Open the folder on GitHubat commit f791727

Compare with similar skills

Docker Agent Config next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Docker Agent Config compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Docker Agent Config this skilldocker/skills539—~2.5kAutomated safety check: NotesApache-2.0
Unraiddinglebear-ai/unraid135—~5.4kAutomated safety check: NotesMIT
Devsydevsy-org/devsy109—~1.7kAutomated safety check: PassMPL-2.0
Pluggedin Stack OpsVeriTeknik/pluggedin-app103—~1.3kAutomated safety check: NotesMIT
Skillz Integrationgithub/gh-aw5.3k—~905Automated safety check: PassMIT
Cognee Docker Setuptopoteretes/cognee32k1 repos~901Automated safety check: NotesApache-2.0

Similar skills

  • Unraid

    dinglebear-ai/unraid

    This skill should be used when the user mentions Unraid, asks to check server health, monitor array or disk status, list or restart Docker containers, start or stop VMs, read system logs, check…

    135 GitHub stars~5.4k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Devsy

    devsy-org/devsy

    Operate Devsy workspaces and providers for end users. An agent skill from devsy-org/devsy.

    109 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Pluggedin Stack Ops

    VeriTeknik/pluggedin-app

    A skill your agent uses when deploying, restarting, verifying or rolling back the containerised plugged.in production stack, when the site returns 404 or 5xx after a deploy or git operation, or when…

    103 GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Skillz Integration

    github/gh-aw

    Official

    Run and integrate Skillz MCP server with Docker for skill execution.

    5.3k GitHub stars~905 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cognee Docker Setup

    topoteretes/cognee

    Runs the Cognee AI memory platform in Docker, from a one-file prebuilt image to a full compose stack with UI, MCP server, Postgres and Neo4j.

    32k GitHub starsUsed in 1 repo~901 tokens
    DevOps & CloudAuto-check: notes
  • Oneclickvirt

    oneclickvirt/oneclickvirt

    OneClickVirt operations skill for managing containers, virtual machines, provider nodes, health checks, and metrics through MCP.

    372 GitHub stars~1.1k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed

More from docker/skills

All 11 skills in this repo
  • Official

    A skill your agent uses when creating, modifying, or debugging Docker Compose configurations, even if the user just says they need to wire services together, add a database to their stack, or set up…

    539 GitHub stars~2.4k tokensUpdated 3 days ago
    Auto-check: notes
  • Official

    A skill your agent uses when writing, reviewing, or optimizing Dockerfiles, even if the user just says their image is too large, their build is slow, or they need to harden a container for production.

    539 GitHub stars~3k tokensUpdated 3 days ago
    Auto-check: warnings
  • Docker Agent Deploy

    docker/skills

    Official

    A skill your agent uses when exposing a Docker Agent as a server (MCP, HTTP API, A2A, ACP, or OpenAI-compatible chat), distributing an agent via an OCI registry with docker agent share, or measuring…

    539 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check passed
  • Official

    A skill your agent uses when setting up, initializing, or Dockerizing a project, even if the user doesn't explicitly mention Docker but describes a need for containerized local development, adding a…

    539 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check: warnings
  • Official

    A skill your agent uses when authoring, planning, or running a declarative sbxenv.yaml file for Docker Sandboxes (sbx env create/run/plan/exec/rm), even if the user just says they want to "check in…

    539 GitHub stars~4k tokensUpdated 3 days ago
    Auto-check passed
  • Official

    A skill your agent uses when authoring, validating, packaging, signing, or composing a Docker Sandboxes kit spec.yaml (sbx kit add/inspect/pack/pull/push/sign/validate/verify), even if the user just…

    539 GitHub stars~4.2k tokensUpdated 3 days ago
    Auto-check passed

Questions about Docker Agent Config

What does Docker Agent Config do?

A skill your agent uses when creating or editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent), including defining agents, models/providers, built-in or MCP toolsets…. Docker Agent Config is an agent skill from docker/skills, published by the product's own GitHub organization.hcl) configuration file for Docker Agent (cagent), including defining agents, models/providers, built-in or MCP toolsets, multi-agent teams with subagents.

When should I use Docker Agent Config?

Docker Agent Config fits situations like: editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent); including defining agents; models/providers; multi-agent teams with subagents.

How do I install Docker Agent Config in Claude Code?

Run `npx skills add docker/skills --skill docker-agent-config -a claude-code`. Or copy the skill folder (skills/docker-agent-config in docker/skills) into .claude/skills/docker-agent-config in your project. Claude Code loads it when a task matches its description.

How do I install Docker Agent Config in Codex?

Run `npx skills add docker/skills --skill docker-agent-config -a codex`. Or copy the skill folder (skills/docker-agent-config in docker/skills) into .agents/skills/docker-agent-config in your project. Codex loads it when a task matches its description.

Can I use Docker Agent Config in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add docker/skills --skill docker-agent-config -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker-agent-config, .gemini/skills/docker-agent-config, .github/skills/docker-agent-config and .opencode/skills/docker-agent-config in your project.

What does Docker Agent Config need to run?

Going by SKILL.md and its folder, Docker Agent Config needs the command-line tools its instructions call (docker). Our summary lists: Docker; A credential in MY_API_KEY. Compatibility (from SKILL.md): Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Verified against docker-agent as shipped with Docker CLI 29.7.2. Config directories still use the legacy `cagent` name (`~/.config/cagent`, `~/.cagent`)..

Does Docker Agent Config access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Docker Agent Config safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Docker Agent Config use?

Docker Agent Config is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Docker Agent Config use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Docker Agent Config?

Skills that share tags, products or a category with Docker Agent Config: Unraid (dinglebear-ai/unraid, 135 stars), Devsy (devsy-org/devsy, 109 stars), Pluggedin Stack Ops (VeriTeknik/pluggedin-app, 103 stars) and Skillz Integration (github/gh-aw, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Docker Agent Config?

docker (a GitHub organization, an official publisher) maintains it in docker/skills, which has 539 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 4, 2026.

Source: docker/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.