Official agent skill

Docker Destructive Guardrails

by docker in docker/skills

Use this skill before running, or recommending, any Docker command that deletes, wipes, resets, or otherwise irreversibly changes state — even if the user just says to "clean up", "clear the cache"…

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Docker Destructive Guardrails

skills CLI
$ npx skills add docker/skills --skill docker-destructive-guardrails -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install docker/skills docker-destructive-guardrails --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/docker-destructive-guardrails .claude/skills/docker-destructive-guardrails && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
docker-destructive-guardrails
GitHub stars
539
Token cost
~2.6k tokens
SKILL.md length
1,298 words
Files
6 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Use this skill before running, or recommending, any Docker command that deletes, wipes, resets, or otherwise irreversibly changes state — even if the user just says to "clean up", "clear the cache"…

  • Tasks that involve Containers
  • SKILL.md covers Overview, When to use this skill, Do not use this skill when and Core guidance, plus 4 more sections
  • Calls docker
  • Tasks that involve LLM guardrails

What it does

Docker Destructive Guardrails is an agent skill from docker/skills, published by the product's own GitHub organization. Use this skill before running, or recommending, any Docker command that deletes, wipes, resets, or otherwise irreversibly changes state — even if the user just says to "clean up", "clear the cache", "start fresh", "wipe everything", "nuke it", "reset", "force remove", or "tear down" Docker resources. Covers generic Docker CLI destructive operations not owned by a more specific skill — docker rm, docker rm -f, docker container prune, docker kill, docker system prune, docker rmi/docker image rm, docker image prune…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `agents/openai.yaml`, `checks/verification.md` and `references/cross-skill-destructive-command-index.md`). Compatibility notes: Applies to any Docker CLI version. This is a behavioral guardrail skill, not a Dockerfile or Compose authoring skill.

It sits in DevOps & Cloud, covering Containers and LLM guardrails. It works with Docker. The repository describes itself as: A collection of Docker skills for AI coding agents to help them build, test, debug, and optimize containerized apps with consistent, reusable workflows. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Containers
  • Tasks that involve LLM guardrails

Example prompts

  • “clean up”
  • “clear the cache”
  • “start fresh”
  • “/docker-destructive-guardrails”

Requirements

  • Docker
  • Compatibility (from SKILL.md): Applies to any Docker CLI version. This is a behavioral guardrail skill, not a Dockerfile or Compose authoring skill.

What it can do on your machine

Read from SKILL.md and the folder at commit f791727. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Applies to any Docker CLI version. This is a behavioral guardrail skill, not a Dockerfile or Compose authoring skill.

    From compatibility in the SKILL.md frontmatter.

Context cost

Docker Destructive Guardrails loads about 2.6k tokens when it runs, and up to ~6.6k if it reads all its reference files. Until then it costs about 244 tokens; SKILL.md has 1,298 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~244
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from docker/skills at commit f791727, republished under its Apache-2.0 licence (© docker). 1,298 words, ~2,557 tokens.

Download SKILL.mdSave it as .claude/skills/docker-destructive-guardrails/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
docker-destructive-guardrails
description
Use this skill before running, or recommending, any Docker command that deletes, wipes, resets, or otherwise irreversibly changes state — even if the user just says to "clean up", "clear the cache", "start fresh", "wipe everything", "nuke it", "reset", "force remove", or "tear down" Docker resources. Covers generic Docker CLI destructive operations not owned by a more specific skill — `docker rm`, `docker rm -f`, `docker container prune`, `docker kill`, `docker system prune`, `docker rmi`/`docker image rm`, `docker image prune -a`, `docker network rm`, `docker network prune`, `docker builder prune`, `docker buildx rm`, `docker context rm`, and standalone (non-Compose) `docker volume rm`/`docker volume prune`. Also indexes destructive commands owned by other Docker skills (Compose, sandbox, Desktop). Core rule — state exactly what will be lost and get explicit confirmation first, except narrow, low-friction Tier 1 container cleanup.
compatibility
Applies to any Docker CLI version. This is a behavioral guardrail skill, not a Dockerfile or Compose authoring skill.
license
Apache-2.0

Docker Destructive Command Guardrails

Overview

This skill provides the cross-product policy for handling destructive or irreversible Docker CLI operations: commands that delete data, remove resources, or otherwise cannot be undone. Use it whenever a task could reasonably lead to running one of these commands, even if the user never names the command directly. It covers the generic Docker CLI commands with no home in a more specific skill, and it indexes where other destructive commands (Compose, sandbox, Desktop) are documented.

When to use this skill

Activate this skill when:

  • The user asks to "clean up", "clear the cache", "start fresh", "wipe everything", "nuke it", "reset", "force remove", or "tear down" Docker resources without naming a specific command
  • The agent is considering docker rm, docker rm -f, docker container prune, docker kill, docker stop, docker system prune, docker rmi, docker image rm, docker image prune -a, docker network rm, docker network prune, docker builder prune, docker buildx rm, docker context rm, or standalone (non-Compose) docker volume rm/docker volume prune as a fix for an unrelated problem (disk space, a stuck container, a stale network, a broken build cache, an old builder or volume)
  • The user wants a cross-product overview of destructive commands across Docker skills

Do not use this skill when

Do not use this skill when:

  • The destructive command in question is Compose-specific (docker compose down -v, docker compose rm -v, docker volume rm/docker volume prune in a Compose project) — use docker-compose-patterns directly, which owns that guidance in full detail
  • The task is authoring or reviewing a Dockerfile or compose.yaml with no cleanup or deletion involved
  • The operation is non-Docker (git, filesystem, cloud resources) — this skill covers Docker CLI operations only

Core guidance

The core rule for every command below: state exactly what will be deleted, stopped, or lost, and get explicit confirmation from the user before running it. Never run a destructive command as a default troubleshooting or "just clean it up" reflex — disk space, stuck containers, and stale caches almost always have a narrower, non-destructive fix. See references/docker-cli-destructive-commands.md for exact flags and the safe, scoped alternative for each.

The container-lifecycle commands — docker rm, docker rm -f, docker container prune, and docker kill — don't all carry the same risk, so they're split into two tiers below instead of one flat rule. docker stop follows a related but distinct reversible-action rule right after the tiers. Every other command in this list follows the flat rule stated above with no exceptions: state what's lost, get explicit confirmation, and wait for the user's answer before running it.

Tier 1 — low-friction container cleanup

Applies only to docker rm <name> on an already-stopped container and docker rm -f <name> on a container the agent itself created and started earlier in the same session purely for testing or debugging — the -f carve-out applies even when the container is still running, since that's the only reason -f would be needed. All of the following must hold: the container is already stopped, or was created/started by the agent itself this session for testing/debugging; there's no known unpersisted state at risk; the action targets one specific, identified container rather than an unscoped sweep; and the agent is acting on an explicit user ask this session, not its own initiative. When every condition holds, the agent removes the container, states what it did, and proceeds — no blocking confirmation is required first. Tier 2's docker rm -f rule below applies to every other case.

Tier 2 — container commands needing confirmation

docker kill is always Tier 2 (see the reference for why no stopped-container exception exists for it). Also Tier 2: docker container prune (it always sweeps every stopped container on the host, never just the one the agent is cleaning up), docker rm -f on any container that doesn't meet every Tier 1 condition above (in particular, a running container the agent didn't create/start this session, or one it did but is acting on without an explicit user ask), any other unscoped sweep regardless of container state (e.g. docker rm -f $(docker ps -aq), "remove/kill all containers"), a container the agent didn't create and has no context on, and any action taken on the agent's own initiative rather than an explicit user ask. These carry the same confirmation bar as every flat-rule command in this skill: state exactly what will be lost and get explicit confirmation before running anything — no exception carved out.

Show full SKILL.md (565 more words)Show less
docker stop — reversible, outside the tier model

docker stop doesn't remove anything — the container still exists and can be restarted with docker start — so it sits outside the Tier 1/Tier 2 removal model above. It's still in scope for this skill because it interrupts a running process (SIGTERM, then SIGKILL after the timeout) and discards any unpersisted in-container state. On the agent's own test/debug container from this session, treat it like Tier 1: stop it and state what happened, no blocking confirmation required. On any other container, state that it will stop running and any unsaved in-memory state will be lost, then get confirmation first.

  • docker system prune — deletes stopped containers, unused networks, dangling images, and build cache; -a also deletes unused tagged images, and --volumes also deletes unused anonymous volumes (named volumes are untouched — deleting those needs a separate docker volume rm).
  • docker rmi / docker image rm — deletes a specific image; see the reference for -f's exact (partly unverified) override behavior on multi-tag/referenced images.
  • docker image prune -a — deletes every image not referenced by any container, running or stopped, not just dangling ones.
  • docker network rm — deletes the specifically named network(s) passed as arguments; see the reference for how its -f flag differs from docker context rm -f below.
  • docker network prune — deletes every custom network not attached to a container.
  • docker builder prune — clears the BuildKit cache; -a/--all also removes internal helper/frontend images and cache shared with other build outputs, forcing a cold rebuild for anyone using that cache.
  • docker buildx rm — removes a builder instance, distinct from the cache docker builder prune clears — see the reference for flag details.
  • docker context rm — deletes a context's local connection config; doesn't affect remote resources but may not be trivially reconstructable. Unlike docker network rm -f above, docker context rm -f genuinely forces removal even if the context is currently in use.
  • docker volume rm / docker volume prune (standalone, no Compose project in play) — deletes volume data directly and irreversibly; docker volume prune -a/--all widens the default anonymous-only scope to named volumes too. For a Compose project's own volumes, use docker-compose-patterns instead (see Related skills); for a volume declared external: true in a compose.yaml but not managed by that Compose project, this skill's guidance applies since Compose won't touch it via down -v.
  • For Compose-specific destructive commands (docker compose down -v, docker compose rm -v, docker volume rm/docker volume prune in a Compose context), use docker-compose-patterns — it owns that guidance in full detail; this skill only indexes it. This skill owns the standalone (non-Compose) case for docker volume rm/docker volume prune itself — see Core guidance and references/docker-cli-destructive-commands.md.
  • For Dockerfile internals, build caching, and image size optimization (non-destructive concerns), use docker-build-strategies.
  • For first-time Docker project scaffolding, use docker-project-foundations.
  • For sandbox (sbx) destructive commands (sbx rm, sbx prune), use docker-sandboxes-lifecycle — it owns that guidance in full detail; this skill only indexes it. Docker Desktop destructive-command guardrails will live in their own skill once merged (see references/cross-skill-destructive-command-index.md for tracking status); do not assume their content until that skill ships.

References

  • references/docker-cli-destructive-commands.md — Per-command breakdown of exact flags, what's deleted, and the safe/scoped alternative for each generic Docker CLI destructive command.
  • references/cross-skill-destructive-command-index.md — Cross-product table of destructive commands across all Docker skills, including a pending placeholder for Docker Desktop.

Assets

This skill has no bundled assets.

Checks

  • checks/verification.md — Manual review runbook, including example bad/good dialogues for handling destructive-command requests.

© docker, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/docker-destructive-guardrails of docker/skills.

  • SKILL.md
  • agents/openai.yaml
  • checks/verification.md
  • references/cross-skill-destructive-command-index.md
  • references/docker-cli-destructive-commands.md
  • skill.yaml

Open the folder on GitHubat commit f791727

Compare with similar skills

Docker Destructive Guardrails next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Docker Destructive Guardrails compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Docker Destructive Guardrails this skilldocker/skills539—~2.6kAutomated safety check: PassApache-2.0
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2596 repos~1.1kAutomated safety check: NotesCustom licence
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Build Openshell Mxc WindowsNVIDIA/OpenShell15k—~4.9kAutomated safety check: PassApache-2.0

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    15k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Omnigent Docker Compose Deploy

    omnigent-ai/omnigent

    Brings up the Omnigent server and Postgres as a Docker compose stack on any Docker host, and covers the Dockerfile's runtime and host build targets for extending it to a new platform.

    11k GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from docker/skills

All 11 skills in this repo
  • Official

    A skill your agent uses when creating, modifying, or debugging Docker Compose configurations, even if the user just says they need to wire services together, add a database to their stack, or set up…

    539 GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check: notes
  • Official

    A skill your agent uses when writing, reviewing, or optimizing Dockerfiles, even if the user just says their image is too large, their build is slow, or they need to harden a container for production.

    539 GitHub stars~3k tokensUpdated 2 days ago
    Auto-check: warnings
  • Docker Agent Config

    docker/skills

    Official

    A skill your agent uses when creating or editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent), including defining agents, models/providers, built-in or MCP toolsets…

    539 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check: notes
  • Docker Agent Deploy

    docker/skills

    Official

    A skill your agent uses when exposing a Docker Agent as a server (MCP, HTTP API, A2A, ACP, or OpenAI-compatible chat), distributing an agent via an OCI registry with docker agent share, or measuring…

    539 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Official

    A skill your agent uses when setting up, initializing, or Dockerizing a project, even if the user doesn't explicitly mention Docker but describes a need for containerized local development, adding a…

    539 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check: warnings
  • Official

    A skill your agent uses when authoring, planning, or running a declarative sbxenv.yaml file for Docker Sandboxes (sbx env create/run/plan/exec/rm), even if the user just says they want to "check in…

    539 GitHub stars~4k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Docker Destructive Guardrails

What does Docker Destructive Guardrails do?

Use this skill before running, or recommending, any Docker command that deletes, wipes, resets, or otherwise irreversibly changes state — even if the user just says to "clean up", "clear the cache"…. Docker Destructive Guardrails is an agent skill from docker/skills, published by the product's own GitHub organization. Use this skill before running, or recommending, any Docker command that deletes, wipes, resets, or otherwise irreversibly changes state — even if the user just says to "clean up", "clear the cache", "start fresh", "wipe everything", "nuke it", "reset", "force remove", or "tear down" Docker resources.

When should I use Docker Destructive Guardrails?

Docker Destructive Guardrails fits situations like: tasks that involve Containers; tasks that involve LLM guardrails.

How do I install Docker Destructive Guardrails in Claude Code?

Run `npx skills add docker/skills --skill docker-destructive-guardrails -a claude-code`. Or copy the skill folder (skills/docker-destructive-guardrails in docker/skills) into .claude/skills/docker-destructive-guardrails in your project. Claude Code loads it when a task matches its description.

How do I install Docker Destructive Guardrails in Codex?

Run `npx skills add docker/skills --skill docker-destructive-guardrails -a codex`. Or copy the skill folder (skills/docker-destructive-guardrails in docker/skills) into .agents/skills/docker-destructive-guardrails in your project. Codex loads it when a task matches its description.

Can I use Docker Destructive Guardrails in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add docker/skills --skill docker-destructive-guardrails -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker-destructive-guardrails, .gemini/skills/docker-destructive-guardrails, .github/skills/docker-destructive-guardrails and .opencode/skills/docker-destructive-guardrails in your project.

What does Docker Destructive Guardrails need to run?

Going by SKILL.md and its folder, Docker Destructive Guardrails needs the command-line tools its instructions call (docker). Our summary lists: Docker. Compatibility (from SKILL.md): Applies to any Docker CLI version. This is a behavioral guardrail skill, not a Dockerfile or Compose authoring skill..

Does Docker Destructive Guardrails access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Docker Destructive Guardrails safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Docker Destructive Guardrails use?

Docker Destructive Guardrails is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Docker Destructive Guardrails use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.

What are the alternatives to Docker Destructive Guardrails?

Skills that share tags, products or a category with Docker Destructive Guardrails: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 259 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Docker Destructive Guardrails?

docker (a GitHub organization, an official publisher) maintains it in docker/skills, which has 539 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 4, 2026.

Source: docker/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.