Official agent skill

Docker Agent Run

by docker in docker/skills

A skill your agent uses when running a Docker Agent with docker agent run, choosing a safety/approval mode, using the --sandbox isolation flag, setting up aliases, or troubleshooting a run (missing…

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Docker Agent Run

skills CLI
$ npx skills add docker/skills --skill docker-agent-run -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install docker/skills docker-agent-run --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/docker-agent-run .claude/skills/docker-agent-run && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
docker-agent-run
GitHub stars
539
Token cost
~2.2k tokens
SKILL.md length
991 words
Files
6 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when running a Docker Agent with docker agent run, choosing a safety/approval mode, using the --sandbox isolation flag, setting up aliases, or troubleshooting a run (missing…

  • Running a Docker Agent with docker agent run
  • SKILL.md covers Overview, When to use this skill, Do not use this skill when and Core guidance, plus 4 more sections
  • Calls docker
  • Choosing a safety/approval mode

What it does

Docker Agent Run is an agent skill from docker/skills, published by the product's own GitHub organization. Use this skill when running a Docker Agent with docker agent run, choosing a safety/approval mode, using the --sandbox isolation flag, setting up aliases, or troubleshooting a run (missing credentials, worktrees). Even if the user just says they want to "run my agent", "make my agent auto-approve tool calls", "run this agent safely", or "why can't my agent see my API key", this skill applies. Covers --safety (strict/balanced/restricted/autonomous), --yolo, --sandbox and its network allowlist, --worktree, docker…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `agents/openai.yaml`, `checks/verification.md` and `references/safety-and-sandbox.md`). Compatibility notes: Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Sandbox mode (--sandbox) additionally requires the…

It sits in DevOps & Cloud, covering Containers, Git worktrees and Computer vision. It works with Docker. The repository describes itself as: A collection of Docker skills for AI coding agents to help them build, test, debug, and optimize containerized apps with consistent, reusable workflows. The licence is Apache-2.0.

When your agent uses it

  • Running a Docker Agent with docker agent run
  • Choosing a safety/approval mode
  • Using the --sandbox isolation flag
  • Setting up aliases

Example prompts

  • “run my agent”
  • “make my agent auto-approve tool calls”
  • “run this agent safely”
  • “/docker-agent-run”

Requirements

  • Docker
  • Compatibility (from SKILL.md): Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Sandbox mode (`--sandbox`) additionally requires the `sbx` CLI. Verified against docker-agent as shipped with Docker CLI 29.7.2.

What it can do on your machine

Read from SKILL.md and the folder at commit f791727. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Sandbox mode (`--sandbox`) additionally requires the `sbx` CLI. Verified against docker-agent as shipped with Docker CLI 29.7.2.

    From compatibility in the SKILL.md frontmatter.

Context cost

Docker Agent Run loads about 2.2k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 147 tokens; SKILL.md has 991 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~147
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from docker/skills at commit f791727, republished under its Apache-2.0 licence (© docker). 991 words, ~2,159 tokens.

Download SKILL.mdSave it as .claude/skills/docker-agent-run/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
docker-agent-run
description
Use this skill when running a Docker Agent with `docker agent run`, choosing a safety/approval mode, using the `--sandbox` isolation flag, setting up aliases, or troubleshooting a run (missing credentials, worktrees). Even if the user just says they want to "run my agent", "make my agent auto-approve tool calls", "run this agent safely", or "why can't my agent see my API key", this skill applies. Covers `--safety` (strict/balanced/restricted/autonomous), `--yolo`, `--sandbox` and its network allowlist, `--worktree`, `docker agent alias`, and `docker agent doctor`.
compatibility
Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Sandbox mode (`--sandbox`) additionally requires the `sbx` CLI. Verified against docker-agent as shipped with Docker CLI 29.7.2.
license
Apache-2.0

Docker Agent: Running and Operating Agents

Overview

This skill owns the operational side of Docker Agent: invoking docker agent run against a local config, an alias, or a registry reference; choosing how much autonomy the agent gets over tool calls; isolating it in a sandbox VM; and diagnosing why a run fails. It assumes the agent.yaml already exists — see Related skills for authoring it.

When to use this skill

Activate this skill when:

  • The user wants to run an agent interactively or headlessly (--exec).
  • The user is choosing or debugging --safety, --yolo, or approval behavior for tool calls.
  • The user wants to isolate an agent's shell/filesystem access with --sandbox, or hit a sandbox network-policy error.
  • The user wants a reusable shortcut (docker agent alias), a scoped git worktree (--worktree), or is debugging credentials/model availability (docker agent doctor).

Do not use this skill when

Do not use this skill when:

  • The task uses standalone sbx run/create/stop/rm rather than docker agent run --sandbox — use docker-sandboxes-lifecycle.
  • The task is standalone sbx policy or sbx secret configuration — use docker-sandboxes-network-credentials. Establish which CLI is in use before recommending commands when the request only says "my sandbox".
  • The task is writing or editing the agent.yaml itself (models, toolsets, sub_agents) — use docker-agent-config.
  • The task is exposing an agent as a server (serve), sharing it via a registry (share), or evaluating it (evaluation sessions, --baseline regression gates) — use docker-agent-deploy.

Core guidance

Safety modes
  • docker agent run supports four --safety modes; choose the least permissive one that still lets the task finish:
    • strict — ask for approval before every tool call.
    • balanced — auto-approve calls classified as safe, ask for the rest.
    • restricted — auto-approve safe calls, deny the rest outright. Use for unattended/CI runs where no human can answer a prompt.
    • autonomous — approve everything automatically. Equivalent to --yolo.
  • Never default an unattended run (cron, CI, a server endpoint) to autonomous/--yolo. Use restricted for unattended runs so an unexpected tool call fails closed instead of running unreviewed; reserve autonomous/--yolo for a sandboxed or fully trusted interactive session.
    bash
    # CI-safe: unreviewed tool calls are denied, not silently approved.
    docker agent run --exec --safety restricted ./agent.yaml "Triage the failing test"
  • Bake a safety default into an alias so callers don't have to remember it, and note that an explicit CLI --safety/--yolo on docker agent run still overrides the alias:
    bash
    docker agent alias add safe-coder myorg/coder --safety balanced
Sandbox isolation
  • --sandbox runs the agent inside an isolated microVM managed by the sbx CLI (a separate prerequisite — install and configure it first). All shell, filesystem, and process activity started by built-in toolsets happens inside the VM; only the working directory (and, unless --no-kit, a staged "kit" of skills/prompt files) is mounted in. Exception: a local stdio MCP server declared on the agent runs as a host process outside the sandbox VM — treat any such MCP server as a trusted host integration, not a sandboxed one.
    bash
    docker agent run --sandbox ./agent.yaml
  • The sandbox network proxy is default-deny: only the model provider, models.dev, and hosts the toolset resolver can infer are open. A custom MCP server or third-party API often needs an explicit allowlist entry — add it permanently rather than re-discovering it every run:
    bash
    docker agent sandbox allow api.example.com
    docker agent sandbox list
    docker agent sandbox deny api.example.com
  • Prefer baking runtime: {sandbox: true} into the agent's own agent.yaml over remembering --sandbox on every invocation of that agent; an explicit --sandbox=false on the CLI still overrides the config default for a single debug run.
  • Sandboxes persist and are reused across runs from the same workspace — they are not torn down when the session ends. Don't expect a clean VM on every run; if you need one, change the mount set (e.g. a new kit) to force recreation.
Show full SKILL.md (451 more words)Show less
Aliases and default agent
  • Register a shortcut once, then run it by name instead of a path:
    bash
    docker agent alias add code myorg/notion-expert
    docker agent run code
  • For a local run with no agent argument, docker agent run discovers docker-agent.yaml, then docker-agent.yml, then docker-agent.hcl in the current directory (first match wins). Only if none exists does it resolve the default alias, falling back to the built-in default agent. The agent.yaml examples in these skills pass a filename explicitly; agent.yaml is not an auto-discovery name.
  • Set the fallback for directories without a project config with a default alias. To select it even when a project config exists, pass default explicitly:
    bash
    docker agent alias add default ./my-agent.yaml
    docker agent run default
  • CLI flags on docker agent run <alias> always override the alias's own stored options (e.g. docker agent run yolo-coder --yolo=false).
Worktrees
  • Use --worktree (-w) to isolate an agent's file edits from your current checkout — it runs the agent inside a fresh git worktree. For an interactive session, a clean worktree (no uncommitted changes, untracked files, or new commits) is removed automatically when the session ends; one with work prompts you to keep or remove. A headless run (--exec) never auto-cleans its worktree, regardless of state — it is left in place for inspection:
    bash
    docker agent run ./agent.yaml --worktree=auth-refactor --worktree-base origin/main
  • --worktree cannot be combined with --remote or --sandbox. To resume a worktree run, pass --session -1 (or the session id) — do not re-pass --worktree, which fails because the worktree already exists.
Troubleshooting
  • "No model is currently available" or "model ... is not pulled" means the agent's provider has no usable credential, or (for dmr/) the model hasn't been pulled. Run docker agent doctor ./agent.yaml first — it reports the resolved model/provider and whether credentials were found — before touching the YAML. If credentials are missing, export the provider's API key; if a DMR model is missing, run docker model pull <model>. Rerun doctor before retrying the task.
  • An agent that only describes a plan instead of executing it is usually missing the tool it needs (add type: shell or type: todo in agent.yaml), not a model failure — hand this back to docker-agent-config.
  • A 403 Blocked by network policy error inside a sandbox run means the destination isn't allowlisted; use docker agent sandbox allow <host>.
  • For standalone sbx lifecycle commands, use docker-sandboxes-lifecycle.
  • For standalone sbx policy and sbx secret, use docker-sandboxes-network-credentials.
  • For writing or changing the underlying agent.yaml (models, toolsets, sub_agents), use docker-agent-config.
  • For serving, sharing, or evaluating the agent, use docker-agent-deploy.

References

  • references/safety-and-sandbox.md — full safety-mode/flag interaction table and sandbox trust-boundary details.
  • references/sources.md — provenance of every rule in this skill.

Assets

  • None.

Checks

  • checks/verification.md — Verification runbook for a docker agent run invocation.

© docker, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/docker-agent-run of docker/skills.

  • SKILL.md
  • agents/openai.yaml
  • checks/verification.md
  • references/safety-and-sandbox.md
  • references/sources.md
  • skill.yaml

Open the folder on GitHubat commit f791727

Compare with similar skills

Docker Agent Run next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Docker Agent Run compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Docker Agent Run this skilldocker/skills539—~2.2kAutomated safety check: PassApache-2.0
Checkopenwpm/OpenWPM1.4k—~1.5kAutomated safety check: PassCustom licence
Start Temps Clustergotempsh/temps822—~4.5kAutomated safety check: PassApache-2.0
Wp Playgroundbonny/WordPress-Simple-History317—~1kAutomated safety check: NotesNone
Ship ItBlackBeltTechnology/pi-agent-dashboard316—~5.4kAutomated safety check: PassMIT
Metro AI App Recipeopen-edge-platform/edge-ai-suites140—~4.4kAutomated safety check: NotesApache-2.0

Similar skills

  • Check

    openwpm/OpenWPM

    A skill your agent uses to check on background feature agents launched via /kickoff — running in tmux sessions or docker/podman containers.

    1.4k GitHub stars~1.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Start Temps Cluster

    gotempsh/temps

    Start (or restart) a local multi-node Temps cluster using Docker-in-Docker — one control plane + 3 worker nodes, each a privileged DinD container running its own dockerd + temps agent, wired with…

    822 GitHub stars~4.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Wp Playground

    bonny/WordPress-Simple-History

    A skill your agent uses for quick local testing with WordPress Playground CLI.

    317 GitHub stars~1k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Ship It

    BlackBeltTechnology/pi-agent-dashboard

    Worktree-side implementation orchestrator for an OpenSpec change.

    316 GitHub stars~5.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Metro AI App Recipe

    open-edge-platform/edge-ai-suites

    Stand up a complete, ready-to-run computer-vision analytics stack on Intel hardware with one Docker Compose command — point it at your video sources and an OpenVINO/ONNX model to get live annotated…

    140 GitHub stars~4.4k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • OpenVINO — real-time object detection via Docker (NCS2, Intel GPU, CPU)

    3.1k GitHub stars~1.3k tokensUpdated 20 days ago
    AI & LLM EngineeringAuto-check passed

More from docker/skills

All 11 skills in this repo
  • Official

    A skill your agent uses when creating, modifying, or debugging Docker Compose configurations, even if the user just says they need to wire services together, add a database to their stack, or set up…

    539 GitHub stars~2.4k tokensUpdated 3 days ago
    Auto-check: notes
  • Official

    A skill your agent uses when writing, reviewing, or optimizing Dockerfiles, even if the user just says their image is too large, their build is slow, or they need to harden a container for production.

    539 GitHub stars~3k tokensUpdated 3 days ago
    Auto-check: warnings
  • Docker Agent Config

    docker/skills

    Official

    A skill your agent uses when creating or editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent), including defining agents, models/providers, built-in or MCP toolsets…

    539 GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check: notes
  • Docker Agent Deploy

    docker/skills

    Official

    A skill your agent uses when exposing a Docker Agent as a server (MCP, HTTP API, A2A, ACP, or OpenAI-compatible chat), distributing an agent via an OCI registry with docker agent share, or measuring…

    539 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check passed
  • Official

    A skill your agent uses when setting up, initializing, or Dockerizing a project, even if the user doesn't explicitly mention Docker but describes a need for containerized local development, adding a…

    539 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check: warnings
  • Official

    A skill your agent uses when authoring, planning, or running a declarative sbxenv.yaml file for Docker Sandboxes (sbx env create/run/plan/exec/rm), even if the user just says they want to "check in…

    539 GitHub stars~4k tokensUpdated 3 days ago
    Auto-check passed

Works with

Categories

Questions about Docker Agent Run

What does Docker Agent Run do?

A skill your agent uses when running a Docker Agent with docker agent run, choosing a safety/approval mode, using the --sandbox isolation flag, setting up aliases, or troubleshooting a run (missing…. Docker Agent Run is an agent skill from docker/skills, published by the product's own GitHub organization. Use this skill when running a Docker Agent with docker agent run, choosing a safety/approval mode, using the --sandbox isolation flag, setting up aliases, or troubleshooting a run (missing credentials, worktrees).

When should I use Docker Agent Run?

Docker Agent Run fits situations like: running a Docker Agent with docker agent run; choosing a safety/approval mode; using the --sandbox isolation flag; setting up aliases.

How do I install Docker Agent Run in Claude Code?

Run `npx skills add docker/skills --skill docker-agent-run -a claude-code`. Or copy the skill folder (skills/docker-agent-run in docker/skills) into .claude/skills/docker-agent-run in your project. Claude Code loads it when a task matches its description.

How do I install Docker Agent Run in Codex?

Run `npx skills add docker/skills --skill docker-agent-run -a codex`. Or copy the skill folder (skills/docker-agent-run in docker/skills) into .agents/skills/docker-agent-run in your project. Codex loads it when a task matches its description.

Can I use Docker Agent Run in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add docker/skills --skill docker-agent-run -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker-agent-run, .gemini/skills/docker-agent-run, .github/skills/docker-agent-run and .opencode/skills/docker-agent-run in your project.

What does Docker Agent Run need to run?

Going by SKILL.md and its folder, Docker Agent Run needs the command-line tools its instructions call (docker). Our summary lists: Docker. Compatibility (from SKILL.md): Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Sandbox mode (`--sandbox`) additionally requires the `sbx` CLI. Verified against docker-agent as shipped with Docker CLI 29.7.2..

Does Docker Agent Run access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Docker Agent Run safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Docker Agent Run use?

Docker Agent Run is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Docker Agent Run use?

About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 937 tokens, read only when the agent opens those files.

What are the alternatives to Docker Agent Run?

Skills that share tags, products or a category with Docker Agent Run: Check (openwpm/OpenWPM, 1.4k stars), Start Temps Cluster (gotempsh/temps, 822 stars), Wp Playground (bonny/WordPress-Simple-History, 317 stars) and Ship It (BlackBeltTechnology/pi-agent-dashboard, 316 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Docker Agent Run?

docker (a GitHub organization, an official publisher) maintains it in docker/skills, which has 539 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 4, 2026.

Source: docker/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.