Official agent skill

Docker Agent Deploy

by docker in docker/skills

A skill your agent uses when exposing a Docker Agent as a server (MCP, HTTP API, A2A, ACP, or OpenAI-compatible chat), distributing an agent via an OCI registry with docker agent share, or measuring…

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Docker Agent Deploy

skills CLI
$ npx skills add docker/skills --skill docker-agent-deploy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install docker/skills docker-agent-deploy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/docker-agent-deploy .claude/skills/docker-agent-deploy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
docker-agent-deploy
GitHub stars
539
Token cost
~1.9k tokens
SKILL.md length
849 words
Files
7 (incl. references, assets)
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when exposing a Docker Agent as a server (MCP, HTTP API, A2A, ACP, or OpenAI-compatible chat), distributing an agent via an OCI registry with docker agent share, or measuring…

  • Exposing a Docker Agent as a server (MCP
  • SKILL.md covers Overview, When to use this skill, Do not use this skill when and Core guidance, plus 4 more sections
  • Calls docker; needs GITHUB_TOKEN and ANTHROPIC_API_KEY
  • OpenAI-compatible chat)

What it does

Docker Agent Deploy is an agent skill from docker/skills, published by the product's own GitHub organization. Use this skill when exposing a Docker Agent as a server (MCP, HTTP API, A2A, ACP, or OpenAI-compatible chat), distributing an agent via an OCI registry with docker agent share, or measuring agent quality with docker agent eval. Even if the user just says they want to "turn my agent into an MCP server", "let Claude Desktop use my agent", "publish my agent to Docker Hub", "push my agent like an image", or "test my agent in CI", this skill applies. Covers serve mcp/api/a2a/acp/chat listen addresses and auth flags…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files and assets (for example `agents/openai.yaml`, `assets/eval-session-example.json` and `checks/verification.md`). Compatibility notes: Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone). docker agent eval additionally requires a Docker-compatible container runtime…

It sits in DevOps & Cloud, covering Containers, REST APIs and MCP servers. It works with Docker, Model Context Protocol and OpenAI. The repository describes itself as: A collection of Docker skills for AI coding agents to help them build, test, debug, and optimize containerized apps with consistent, reusable workflows. The licence is Apache-2.0.

When your agent uses it

  • Exposing a Docker Agent as a server (MCP
  • OpenAI-compatible chat)
  • Distributing an agent via an OCI registry with docker agent share
  • Measuring agent quality with docker agent eval

Example prompts

  • “turn my agent into an MCP server”
  • “let Claude Desktop use my agent”
  • “publish my agent to Docker Hub”
  • “/docker-agent-deploy”

Requirements

  • Docker
  • A credential in ANTHROPIC_API_KEY
  • A credential in OPENAI_API_KEY
  • Compatibility (from SKILL.md): Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone). `docker agent eval` additionally requires a Docker-compatible container runtime (Docker Desktop/Engine, or Podman via `--container-runtime`). Verified against docker-agent as shipped with Docker CLI 29.7.2.

What it can do on your machine

Read from SKILL.md and the folder at commit f791727. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • ANTHROPIC_API_KEY
    • OPENAI_API_KEY
    • GH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone). `docker agent eval` additionally requires a Docker-compatible container runtime (Docker Desktop/Engine, or Podman via `--container-runtime`). Verified against docker-agent as shipped with Docker CLI 29.7.2.

    From compatibility in the SKILL.md frontmatter.

Context cost

Docker Agent Deploy loads about 1.9k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 161 tokens; SKILL.md has 849 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~161
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from docker/skills at commit f791727, republished under its Apache-2.0 licence (© docker). 849 words, ~1,935 tokens.

Download SKILL.mdSave it as .claude/skills/docker-agent-deploy/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
docker-agent-deploy
description
Use this skill when exposing a Docker Agent as a server (MCP, HTTP API, A2A, ACP, or OpenAI-compatible chat), distributing an agent via an OCI registry with `docker agent share`, or measuring agent quality with `docker agent eval`. Even if the user just says they want to "turn my agent into an MCP server", "let Claude Desktop use my agent", "publish my agent to Docker Hub", "push my agent like an image", or "test my agent in CI", this skill applies. Covers `serve mcp/api/a2a/acp/chat` listen addresses and auth flags, `share push/pull`, eval session JSON format, scoring metrics, and the `--baseline` regression gate.
compatibility
Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone). `docker agent eval` additionally requires a Docker-compatible container runtime (Docker Desktop/Engine, or Podman via `--container-runtime`). Verified against docker-agent as shipped with Docker CLI 29.7.2.
license
Apache-2.0

Docker Agent: Serving, Sharing, and Evaluating

Overview

This skill owns the integration surface of Docker Agent: making an agent reachable by other software (docker agent serve), distributing it through an OCI registry the way container images are distributed (docker agent share), and proving it still behaves after a change (docker agent eval). It assumes the agent config already exists — see docker-agent-config for authoring it, and docker-agent-run for interactive/local invocation.

When to use this skill

Activate this skill when:

  • The user wants an agent reachable over MCP, an OpenAI-compatible chat endpoint, a plain HTTP API, or A2A/ACP.
  • The user wants to publish an agent to Docker Hub (or any OCI registry) or pull one someone else published.
  • The user wants automated evaluations (regression tests) for an agent, or wants to gate CI on eval results.

Do not use this skill when

Do not use this skill when:

  • The task is authoring the agent.yaml itself (models, toolsets, sub_agents) — use docker-agent-config.
  • The task is running the agent interactively on a developer's machine, choosing --safety/--sandbox, or aliases — use docker-agent-run.

Core guidance

Serving an agent
  • Five server modes, each with its own default loopback listen address — never expose any of them beyond loopback without authentication:

    ModeDefault listenAuth flagHas --safety?
    serve mcp127.0.0.1:8081--auth-token (only with --http)Yes (only with --http)
    serve api127.0.0.1:8080--auth-tokenNo
    serve chat127.0.0.1:8083--api-key / --api-key-envYes
    serve a2a127.0.0.1:8082--auth-tokenYes
    serve acp(stdio only)n/aNo
    bash
    docker agent serve mcp ./agent.yaml --http --listen 127.0.0.1:9090 --auth-token "$TOKEN"
  • serve mcp defaults to stdio transport (for local clients like Claude Desktop); pass --http only when you need a network-reachable MCP endpoint, and set --auth-token whenever you do.

  • Binding any server flag to a non-loopback address without an auth token/key is refused; --insecure-no-auth exists to force it and must be treated as a deliberate, documented exception, never a default.

  • serve mcp (with --http), serve chat, and serve a2a expose --safety (strict/balanced/restricted/autonomous); Docker's docs state it defaults to restricted for these modes when unset. serve api and serve acp expose no --safety flag at all. Never raise --safety to autonomous on a network-reachable listener; if a served agent must approve more, prefer balanced and keep auth enabled.

  • serve api accepts a directory instead of a single file: every .yaml/.yml/.hcl in it is exposed under /api/agents. Use --session-workingdir-root to confine session working directories when the server is reachable by more than one user.

Sharing agents via OCI registries
  • Push and pull agent configs the same way you push and pull images — same registry, same docker login auth:
    bash
    docker agent share push ./agent.yaml docker.io/username/my-agent:latest
    docker agent share pull docker.io/username/my-agent:latest
  • instruction_file contents are inlined into the pushed artifact automatically, so a published agent stays self-contained — you do not need to bundle the referenced files separately.
  • Pin sub_agents that reference the pushed artifact to a digest (name@sha256:...) once published, to avoid a per-run registry lookup and to guarantee the exact config a consumer gets.
  • Use --force on share pull only when you intend to overwrite a local copy that already exists; without it, an existing local config is left untouched.
Show full SKILL.md (364 more words)Show less
Evaluating agents
  • Evals live in an evals/ directory next to the agent config by default; each eval is one JSON session file capturing a user message, the recorded tool calls, and an evals object with the scoring criteria.
  • Create eval sessions from real conversations rather than hand-writing JSON: run the agent interactively, then use the /eval slash command in the TUI to save the session, and edit in relevance/size/assertions criteria afterward.
  • Four scoring dimensions: Tool Calls (F1 against the recorded sequence), Relevance (LLM-judge, --judge-model, default anthropic/claude-opus-5), Size (S/M/L/XL response-length bucket), and Assertions (deterministic checks; see the complete assertion-type list in references/eval-format.md). Prefer assertions over relevance when a check can be exact: they need no judge model and are deterministic, not approximation-prone.
  • Evaluations run inside containers for isolation; a Docker-compatible runtime is required. Dedicated provider API keys (ANTHROPIC_API_KEY/OPENAI_API_KEY) are forwarded automatically. GITHUB_TOKEN/GH_TOKEN are not forwarded automatically (they're broad host credentials, not model keys) — pass them explicitly with -e GITHUB_TOKEN when an agent's provider needs one (e.g. github-copilot).
  • Gate CI on regressions, not on absolute scores, with --baseline:
    bash
    docker agent eval ./agent.yaml --baseline results/2026-08-01-run.json --regression-tolerance 0.05
    A previously-passing eval that now fails always gates regardless of tolerance; cost changes are reported but never gate. A baseline or run with zero evaluations (e.g. an --only pattern matching nothing) is rejected rather than reported as passing.
  • Use --keep-containers plus your runtime's exec to inspect a failed eval's container; the eval's .db session file holds the full conversation for offline debugging.
Verify
  • After changing a served agent's config, re-run its evals with the same explicit --safety value used in the deployment before restarting the listener — this catches an approval-policy regression before it reaches traffic. If a rollout must be rolled back, restore the prior config and safety flag; never restore an unauthenticated listener as a rollback shortcut.
  • For writing or changing the underlying agent.yaml, use docker-agent-config.
  • For local/interactive runs, safety-mode choice, and sandboxing, use docker-agent-run.

References

  • references/eval-format.md — full eval session JSON schema and CLI flag table.
  • references/sources.md — provenance of every rule in this skill.

Assets

  • assets/eval-session-example.json — a minimal eval session file to copy and adapt.

Checks

  • checks/verification.md — Verification runbook for serving, sharing, and evaluating an agent.

© docker, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references, assets) in skills/docker-agent-deploy of docker/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/eval-session-example.json
  • checks/verification.md
  • references/eval-format.md
  • references/sources.md
  • skill.yaml

Open the folder on GitHubat commit f791727

Compare with similar skills

Docker Agent Deploy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Docker Agent Deploy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Docker Agent Deploy this skilldocker/skills539—~1.9kAutomated safety check: PassApache-2.0
Unraiddinglebear-ai/unraid135—~5.4kAutomated safety check: NotesMIT
Oneclickvirtoneclickvirt/oneclickvirt372—~1.1kAutomated safety check: PassGPL-3.0
Devsydevsy-org/devsy110—~1.7kAutomated safety check: PassMPL-2.0
Agentdock User Guideuvwt/agentdock1.2k—~1.6kAutomated safety check: PassApache-2.0
Pluggedin Stack OpsVeriTeknik/pluggedin-app103—~1.3kAutomated safety check: NotesMIT

Similar skills

  • Unraid

    dinglebear-ai/unraid

    This skill should be used when the user mentions Unraid, asks to check server health, monitor array or disk status, list or restart Docker containers, start or stop VMs, read system logs, check…

    135 GitHub stars~5.4k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Oneclickvirt

    oneclickvirt/oneclickvirt

    OneClickVirt operations skill for managing containers, virtual machines, provider nodes, health checks, and metrics through MCP.

    372 GitHub stars~1.1k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Devsy

    devsy-org/devsy

    Operate Devsy workspaces and providers for end users. An agent skill from devsy-org/devsy.

    110 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Agentdock User Guide

    uvwt/agentdock

    当用户询问 AgentDock 是什么、如何使用、配置在哪里、不同平台或安装方式怎样修改配置并生效、如何重启或验证配置、如何发现并配置 Codex/Claude/Grok 等 Coding Agent 的 ACP,以及常见运行问题时使用;覆盖 macOS Desktop、Windows Desktop、Linux 服务、Docker 和直接运行二进制,不用于源码开发与贡献流程。

    1.2k GitHub stars~1.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Pluggedin Stack Ops

    VeriTeknik/pluggedin-app

    A skill your agent uses when deploying, restarting, verifying or rolling back the containerised plugged.in production stack, when the site returns 404 or 5xx after a deploy or git operation, or when…

    103 GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Unraid

    dinglebear-ai/unraid

    Query and monitor an Unraid NAS/homelab server — array health, disk temperatures, Docker containers, virtual machines, system metrics, notifications, alerts, shares, UPS status, log files, network…

    135 GitHub stars~2.8k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed

More from docker/skills

All 11 skills in this repo
  • Official

    A skill your agent uses when creating, modifying, or debugging Docker Compose configurations, even if the user just says they need to wire services together, add a database to their stack, or set up…

    539 GitHub stars~2.4k tokensUpdated 3 days ago
    Auto-check: notes
  • Official

    A skill your agent uses when writing, reviewing, or optimizing Dockerfiles, even if the user just says their image is too large, their build is slow, or they need to harden a container for production.

    539 GitHub stars~3k tokensUpdated 3 days ago
    Auto-check: warnings
  • Docker Agent Config

    docker/skills

    Official

    A skill your agent uses when creating or editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent), including defining agents, models/providers, built-in or MCP toolsets…

    539 GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check: notes
  • Official

    A skill your agent uses when setting up, initializing, or Dockerizing a project, even if the user doesn't explicitly mention Docker but describes a need for containerized local development, adding a…

    539 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check: warnings
  • Official

    A skill your agent uses when authoring, planning, or running a declarative sbxenv.yaml file for Docker Sandboxes (sbx env create/run/plan/exec/rm), even if the user just says they want to "check in…

    539 GitHub stars~4k tokensUpdated 3 days ago
    Auto-check passed
  • Official

    A skill your agent uses when creating, running, reattaching to, listing, stopping, or removing Docker Sandboxes (the standalone sbx CLI that runs AI coding agents in isolated microVMs), even if the…

    539 GitHub starsUsed in 1 repo~3.2k tokens
    Auto-check passed

Categories

Questions about Docker Agent Deploy

What does Docker Agent Deploy do?

A skill your agent uses when exposing a Docker Agent as a server (MCP, HTTP API, A2A, ACP, or OpenAI-compatible chat), distributing an agent via an OCI registry with docker agent share, or measuring…. Docker Agent Deploy is an agent skill from docker/skills, published by the product's own GitHub organization. Use this skill when exposing a Docker Agent as a server (MCP, HTTP API, A2A, ACP, or OpenAI-compatible chat), distributing an agent via an OCI registry with docker agent share, or measuring agent quality with docker agent eval.

When should I use Docker Agent Deploy?

Docker Agent Deploy fits situations like: exposing a Docker Agent as a server (MCP; openAI-compatible chat); distributing an agent via an OCI registry with docker agent share; measuring agent quality with docker agent eval.

How do I install Docker Agent Deploy in Claude Code?

Run `npx skills add docker/skills --skill docker-agent-deploy -a claude-code`. Or copy the skill folder (skills/docker-agent-deploy in docker/skills) into .claude/skills/docker-agent-deploy in your project. Claude Code loads it when a task matches its description.

How do I install Docker Agent Deploy in Codex?

Run `npx skills add docker/skills --skill docker-agent-deploy -a codex`. Or copy the skill folder (skills/docker-agent-deploy in docker/skills) into .agents/skills/docker-agent-deploy in your project. Codex loads it when a task matches its description.

Can I use Docker Agent Deploy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add docker/skills --skill docker-agent-deploy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker-agent-deploy, .gemini/skills/docker-agent-deploy, .github/skills/docker-agent-deploy and .opencode/skills/docker-agent-deploy in your project.

What does Docker Agent Deploy need to run?

Going by SKILL.md and its folder, Docker Agent Deploy needs the command-line tools its instructions call (docker) and credentials named GITHUB_TOKEN, ANTHROPIC_API_KEY, OPENAI_API_KEY and GH_TOKEN. Our summary lists: Docker; A credential in ANTHROPIC_API_KEY; A credential in OPENAI_API_KEY. Compatibility (from SKILL.md): Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone). `docker agent eval` additionally requires a Docker-compatible container runtime (Docker Desktop/Engine, or Podman via `--container-runtime`). Verified against docker-agent as shipped with Docker CLI 29.7.2..

Does Docker Agent Deploy access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Docker Agent Deploy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Docker Agent Deploy use?

Docker Agent Deploy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Docker Agent Deploy use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Docker Agent Deploy?

Skills that share tags, products or a category with Docker Agent Deploy: Unraid (dinglebear-ai/unraid, 135 stars), Oneclickvirt (oneclickvirt/oneclickvirt, 372 stars), Devsy (devsy-org/devsy, 110 stars) and Agentdock User Guide (uvwt/agentdock, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Docker Agent Deploy?

docker (a GitHub organization, an official publisher) maintains it in docker/skills, which has 539 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 4, 2026.

Source: docker/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.