Check
openwpm/OpenWPM
A skill your agent uses to check on background feature agents launched via /kickoff — running in tmux sessions or docker/podman containers.
A skill your agent uses when running a Docker Agent with docker agent run, choosing a safety/approval mode, using the --sandbox isolation flag, setting up aliases, or troubleshooting a run (missing…
$ npx skills add docker/skills --skill docker-agent-run -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install docker/skills docker-agent-run --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/docker-agent-run .claude/skills/docker-agent-run && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "docker-agent-run" agent skill from https://github.com/docker/skills/tree/main/skills/docker-agent-run into .claude/skills/docker-agent-run/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker-agent-run", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/docker/skills/tree/main/skills/docker-agent-runType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add docker/skills --skill docker-agent-run -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install docker/skills docker-agent-run --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/docker-agent-run .agents/skills/docker-agent-run && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "docker-agent-run" agent skill from https://github.com/docker/skills/tree/main/skills/docker-agent-run into .agents/skills/docker-agent-run/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker-agent-run", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add docker/skills --skill docker-agent-run -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install docker/skills docker-agent-run --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/docker-agent-run .cursor/skills/docker-agent-run && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "docker-agent-run" agent skill from https://github.com/docker/skills/tree/main/skills/docker-agent-run into .cursor/skills/docker-agent-run/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker-agent-run", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/docker/skills.git --path skills/docker-agent-run--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add docker/skills --skill docker-agent-run -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install docker/skills docker-agent-run --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/docker-agent-run .gemini/skills/docker-agent-run && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "docker-agent-run" agent skill from https://github.com/docker/skills/tree/main/skills/docker-agent-run into .gemini/skills/docker-agent-run/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker-agent-run", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install docker/skills docker-agent-runInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add docker/skills --skill docker-agent-run -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/docker-agent-run .github/skills/docker-agent-run && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "docker-agent-run" agent skill from https://github.com/docker/skills/tree/main/skills/docker-agent-run into .github/skills/docker-agent-run/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker-agent-run", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add docker/skills --skill docker-agent-run -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install docker/skills docker-agent-run --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/docker-agent-run .opencode/skills/docker-agent-run && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "docker-agent-run" agent skill from https://github.com/docker/skills/tree/main/skills/docker-agent-run into .opencode/skills/docker-agent-run/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker-agent-run", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
docker-agent-runA skill your agent uses when running a Docker Agent with docker agent run, choosing a safety/approval mode, using the --sandbox isolation flag, setting up aliases, or troubleshooting a run (missing…
Docker Agent Run is an agent skill from docker/skills, published by the product's own GitHub organization. Use this skill when running a Docker Agent with docker agent run, choosing a safety/approval mode, using the --sandbox isolation flag, setting up aliases, or troubleshooting a run (missing credentials, worktrees). Even if the user just says they want to "run my agent", "make my agent auto-approve tool calls", "run this agent safely", or "why can't my agent see my API key", this skill applies. Covers --safety (strict/balanced/restricted/autonomous), --yolo, --sandbox and its network allowlist, --worktree, docker…
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `agents/openai.yaml`, `checks/verification.md` and `references/safety-and-sandbox.md`). Compatibility notes: Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Sandbox mode (--sandbox) additionally requires the…
It sits in DevOps & Cloud, covering Containers, Git worktrees and Computer vision. It works with Docker. The repository describes itself as: A collection of Docker skills for AI coding agents to help them build, test, debug, and optimize containerized apps with consistent, reusable workflows. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit f791727. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dockerFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Sandbox mode (`--sandbox`) additionally requires the `sbx` CLI. Verified against docker-agent as shipped with Docker CLI 29.7.2.
From compatibility in the SKILL.md frontmatter.
Docker Agent Run loads about 2.2k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 147 tokens; SKILL.md has 991 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from docker/skills at commit f791727, republished under its Apache-2.0 licence (© docker). 991 words, ~2,159 tokens.
.claude/skills/docker-agent-run/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.This skill owns the operational side of Docker Agent: invoking docker agent run against a local config, an alias, or a registry reference; choosing how
much autonomy the agent gets over tool calls; isolating it in a sandbox VM;
and diagnosing why a run fails. It assumes the agent.yaml already exists —
see Related skills for authoring it.
Activate this skill when:
--exec).--safety, --yolo, or approval behavior for tool calls.--sandbox, or hit a sandbox network-policy error.docker agent alias), a scoped git worktree (--worktree), or is debugging credentials/model availability (docker agent doctor).Do not use this skill when:
sbx run/create/stop/rm rather than
docker agent run --sandbox — use docker-sandboxes-lifecycle.sbx policy or sbx secret configuration — use
docker-sandboxes-network-credentials. Establish which CLI is in use
before recommending commands when the request only says "my sandbox".agent.yaml itself (models, toolsets, sub_agents) — use docker-agent-config.serve), sharing it via a registry (share), or evaluating it (evaluation sessions, --baseline regression gates) — use docker-agent-deploy.docker agent run supports four --safety modes; choose the least
permissive one that still lets the task finish:strict — ask for approval before every tool call.balanced — auto-approve calls classified as safe, ask for the rest.restricted — auto-approve safe calls, deny the rest outright. Use
for unattended/CI runs where no human can answer a prompt.autonomous — approve everything automatically. Equivalent to --yolo.autonomous/--yolo. Use restricted for unattended runs so an
unexpected tool call fails closed instead of running unreviewed; reserve
autonomous/--yolo for a sandboxed or fully trusted interactive session.# CI-safe: unreviewed tool calls are denied, not silently approved.
docker agent run --exec --safety restricted ./agent.yaml "Triage the failing test"--safety/--yolo on docker agent run
still overrides the alias:docker agent alias add safe-coder myorg/coder --safety balanced--sandbox runs the agent inside an isolated microVM managed by the sbx
CLI (a separate prerequisite — install and configure it first). All shell,
filesystem, and process activity started by built-in toolsets happens
inside the VM; only the working directory (and, unless --no-kit, a
staged "kit" of skills/prompt files) is mounted in. Exception: a local
stdio MCP server declared on the agent runs as a host process outside
the sandbox VM — treat any such MCP server as a trusted host integration,
not a sandboxed one.docker agent run --sandbox ./agent.yamlmodels.dev, and hosts the toolset resolver can infer are open. A custom
MCP server or third-party API often needs an explicit allowlist entry —
add it permanently rather than re-discovering it every run:docker agent sandbox allow api.example.com
docker agent sandbox list
docker agent sandbox deny api.example.comruntime: {sandbox: true} into the agent's own agent.yaml
over remembering --sandbox on every invocation of that agent; an
explicit --sandbox=false on the CLI still overrides the config default
for a single debug run.docker agent alias add code myorg/notion-expert
docker agent run codedocker agent run discovers
docker-agent.yaml, then docker-agent.yml, then docker-agent.hcl in
the current directory (first match wins). Only if none exists does it
resolve the default alias, falling back to the built-in default agent.
The agent.yaml examples in these skills pass a filename explicitly;
agent.yaml is not an auto-discovery name.default alias. To select it even when a project config exists, pass
default explicitly:docker agent alias add default ./my-agent.yaml
docker agent run defaultdocker agent run <alias> always override the alias's own
stored options (e.g. docker agent run yolo-coder --yolo=false).--worktree (-w) to isolate an agent's file edits from your current
checkout — it runs the agent inside a fresh git worktree. For an
interactive session, a clean worktree (no uncommitted changes,
untracked files, or new commits) is removed automatically when the
session ends; one with work prompts you to keep or remove. A headless
run (--exec) never auto-cleans its worktree, regardless of state — it is
left in place for inspection:docker agent run ./agent.yaml --worktree=auth-refactor --worktree-base origin/main--worktree cannot be combined with --remote or --sandbox. To resume a
worktree run, pass --session -1 (or the session id) — do not re-pass
--worktree, which fails because the worktree already exists.dmr/) the model
hasn't been pulled. Run docker agent doctor ./agent.yaml first — it
reports the resolved model/provider and whether credentials were found —
before touching the YAML. If credentials are missing, export the provider's
API key; if a DMR model is missing, run docker model pull <model>. Rerun
doctor before retrying the task.type: shell or type: todo in
agent.yaml), not a model failure — hand this back to docker-agent-config.403 Blocked by network policy error inside a sandbox run means the
destination isn't allowlisted; use docker agent sandbox allow <host>.sbx lifecycle commands, use docker-sandboxes-lifecycle.sbx policy and sbx secret, use docker-sandboxes-network-credentials.agent.yaml (models, toolsets, sub_agents), use docker-agent-config.docker-agent-deploy.references/safety-and-sandbox.md — full safety-mode/flag interaction table and sandbox trust-boundary details.references/sources.md — provenance of every rule in this skill.checks/verification.md — Verification runbook for a docker agent run invocation.© docker, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in skills/docker-agent-run of docker/skills.
Open the folder on GitHubat commit f791727
Docker Agent Run next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Docker Agent Run this skilldocker/skills | 539 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Checkopenwpm/OpenWPM | 1.4k | — | ~1.5k | Automated safety check: Pass | Custom licence | |
| Start Temps Clustergotempsh/temps | 822 | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | |
| Wp Playgroundbonny/WordPress-Simple-History | 317 | — | ~1k | Automated safety check: Notes | None | |
| Ship ItBlackBeltTechnology/pi-agent-dashboard | 316 | — | ~5.4k | Automated safety check: Pass | MIT | |
| Metro AI App Recipeopen-edge-platform/edge-ai-suites | 140 | — | ~4.4k | Automated safety check: Notes | Apache-2.0 |
openwpm/OpenWPM
A skill your agent uses to check on background feature agents launched via /kickoff — running in tmux sessions or docker/podman containers.
gotempsh/temps
Start (or restart) a local multi-node Temps cluster using Docker-in-Docker — one control plane + 3 worker nodes, each a privileged DinD container running its own dockerd + temps agent, wired with…
bonny/WordPress-Simple-History
A skill your agent uses for quick local testing with WordPress Playground CLI.
BlackBeltTechnology/pi-agent-dashboard
Worktree-side implementation orchestrator for an OpenSpec change.
open-edge-platform/edge-ai-suites
Stand up a complete, ready-to-run computer-vision analytics stack on Intel hardware with one Docker Compose command — point it at your video sources and an OpenVINO/ONNX model to get live annotated…
SharpAI/DeepCamera
OpenVINO — real-time object detection via Docker (NCS2, Intel GPU, CPU)
docker/skills
A skill your agent uses when creating, modifying, or debugging Docker Compose configurations, even if the user just says they need to wire services together, add a database to their stack, or set up…
docker/skills
A skill your agent uses when writing, reviewing, or optimizing Dockerfiles, even if the user just says their image is too large, their build is slow, or they need to harden a container for production.
docker/skills
A skill your agent uses when creating or editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent), including defining agents, models/providers, built-in or MCP toolsets…
docker/skills
A skill your agent uses when exposing a Docker Agent as a server (MCP, HTTP API, A2A, ACP, or OpenAI-compatible chat), distributing an agent via an OCI registry with docker agent share, or measuring…
docker/skills
A skill your agent uses when setting up, initializing, or Dockerizing a project, even if the user doesn't explicitly mention Docker but describes a need for containerized local development, adding a…
docker/skills
A skill your agent uses when authoring, planning, or running a declarative sbxenv.yaml file for Docker Sandboxes (sbx env create/run/plan/exec/rm), even if the user just says they want to "check in…
Works with
Categories
A skill your agent uses when running a Docker Agent with docker agent run, choosing a safety/approval mode, using the --sandbox isolation flag, setting up aliases, or troubleshooting a run (missing…. Docker Agent Run is an agent skill from docker/skills, published by the product's own GitHub organization. Use this skill when running a Docker Agent with docker agent run, choosing a safety/approval mode, using the --sandbox isolation flag, setting up aliases, or troubleshooting a run (missing credentials, worktrees).
Docker Agent Run fits situations like: running a Docker Agent with docker agent run; choosing a safety/approval mode; using the --sandbox isolation flag; setting up aliases.
Run `npx skills add docker/skills --skill docker-agent-run -a claude-code`. Or copy the skill folder (skills/docker-agent-run in docker/skills) into .claude/skills/docker-agent-run in your project. Claude Code loads it when a task matches its description.
Run `npx skills add docker/skills --skill docker-agent-run -a codex`. Or copy the skill folder (skills/docker-agent-run in docker/skills) into .agents/skills/docker-agent-run in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add docker/skills --skill docker-agent-run -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker-agent-run, .gemini/skills/docker-agent-run, .github/skills/docker-agent-run and .opencode/skills/docker-agent-run in your project.
Going by SKILL.md and its folder, Docker Agent Run needs the command-line tools its instructions call (docker). Our summary lists: Docker. Compatibility (from SKILL.md): Requires the docker-agent CLI plugin (Docker Desktop 4.63+, or standalone via Homebrew/GitHub releases). Sandbox mode (`--sandbox`) additionally requires the `sbx` CLI. Verified against docker-agent as shipped with Docker CLI 29.7.2..
SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Docker Agent Run is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 937 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Docker Agent Run: Check (openwpm/OpenWPM, 1.4k stars), Start Temps Cluster (gotempsh/temps, 822 stars), Wp Playground (bonny/WordPress-Simple-History, 317 stars) and Ship It (BlackBeltTechnology/pi-agent-dashboard, 316 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
docker (a GitHub organization, an official publisher) maintains it in docker/skills, which has 539 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 4, 2026.
Source: docker/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.