Reflexo Release
Myriad-Dreamin/typst.ts
Guide Reflexo/typst.ts release preparation and operator handoffs.
A skill your agent uses when configuring what a Docker Sandboxes (sbx) sandbox can reach on the network or which credentials it authenticates with, even if the user just says they want to "let the…
$ npx skills add docker/skills --skill docker-sandboxes-network-credentials -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install docker/skills docker-sandboxes-network-credentials --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/docker-sandboxes-network-credentials .claude/skills/docker-sandboxes-network-credentials && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "docker-sandboxes-network-credentials" agent skill from https://github.com/docker/skills/tree/main/skills/docker-sandboxes-network-credentials into .claude/skills/docker-sandboxes-network-credentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker-sandboxes-network-credentials", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/docker/skills/tree/main/skills/docker-sandboxes-network-credentialsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add docker/skills --skill docker-sandboxes-network-credentials -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install docker/skills docker-sandboxes-network-credentials --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/docker-sandboxes-network-credentials .agents/skills/docker-sandboxes-network-credentials && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "docker-sandboxes-network-credentials" agent skill from https://github.com/docker/skills/tree/main/skills/docker-sandboxes-network-credentials into .agents/skills/docker-sandboxes-network-credentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker-sandboxes-network-credentials", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add docker/skills --skill docker-sandboxes-network-credentials -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install docker/skills docker-sandboxes-network-credentials --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/docker-sandboxes-network-credentials .cursor/skills/docker-sandboxes-network-credentials && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "docker-sandboxes-network-credentials" agent skill from https://github.com/docker/skills/tree/main/skills/docker-sandboxes-network-credentials into .cursor/skills/docker-sandboxes-network-credentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker-sandboxes-network-credentials", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/docker/skills.git --path skills/docker-sandboxes-network-credentials--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add docker/skills --skill docker-sandboxes-network-credentials -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install docker/skills docker-sandboxes-network-credentials --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/docker-sandboxes-network-credentials .gemini/skills/docker-sandboxes-network-credentials && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "docker-sandboxes-network-credentials" agent skill from https://github.com/docker/skills/tree/main/skills/docker-sandboxes-network-credentials into .gemini/skills/docker-sandboxes-network-credentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker-sandboxes-network-credentials", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install docker/skills docker-sandboxes-network-credentialsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add docker/skills --skill docker-sandboxes-network-credentials -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/docker-sandboxes-network-credentials .github/skills/docker-sandboxes-network-credentials && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "docker-sandboxes-network-credentials" agent skill from https://github.com/docker/skills/tree/main/skills/docker-sandboxes-network-credentials into .github/skills/docker-sandboxes-network-credentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker-sandboxes-network-credentials", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add docker/skills --skill docker-sandboxes-network-credentials -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install docker/skills docker-sandboxes-network-credentials --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/docker/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/docker-sandboxes-network-credentials .opencode/skills/docker-sandboxes-network-credentials && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "docker-sandboxes-network-credentials" agent skill from https://github.com/docker/skills/tree/main/skills/docker-sandboxes-network-credentials into .opencode/skills/docker-sandboxes-network-credentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker-sandboxes-network-credentials", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
docker-sandboxes-network-credentialsA skill your agent uses when configuring what a Docker Sandboxes (sbx) sandbox can reach on the network or which credentials it authenticates with, even if the user just says they want to "let the…
Docker Sandboxes Network Credentials is an agent skill from docker/skills, published by the product's own GitHub organization. Use this skill when configuring what a Docker Sandboxes (sbx) sandbox can reach on the network or which credentials it authenticates with, even if the user just says they want to "let the agent call an internal API", "block all network access", "give the agent a GitHub token", or "use a private registry image for a sandbox". Covers sbx policy init/allow/deny/ls/inspect/log/check/rm network (global and per-sandbox egress rules, deny-over-allow precedence) and sbx secret set/set-custom/ls/rm/import (service…
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `agents/openai.yaml`, `checks/verification.md` and `references/sources.md`). Compatibility notes: Standalone sbx CLI (not the legacy docker sandbox plugin wrapper). Source-verified against repository docker/sandboxes (github.com/docker/sandboxes) @ commit…
It sits in DevOps & Cloud, covering Containers. It works with Docker and GitHub. The repository describes itself as: A collection of Docker skills for AI coding agents to help them build, test, debug, and optimize containerized apps with consistent, reusable workflows. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit f791727. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dockerghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
OPENAI_API_KEYGH_TOKENANTHROPIC_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Standalone `sbx` CLI (not the legacy `docker sandbox` plugin wrapper). Source-verified against repository docker/sandboxes (github.com/docker/sandboxes) @ commit df5c96ba60484fa2c375469dbac912c205da6c37. Cross-checked against an installed sbx v0.42.0-503-g951b7f6d7 (commit 951b7f6d7f6bb260fac15077b607109ffe8ae012, older than the pinned source); no source-only differences were found for the commands this skill covers. `docker_help` does not cover standalone `sbx` syntax.
From compatibility in the SKILL.md frontmatter.
Docker Sandboxes Network Credentials loads about 3.1k tokens when it runs, and up to ~4.3k if it reads all its reference files. Until then it costs about 171 tokens; SKILL.md has 1,387 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from docker/skills at commit f791727, republished under its Apache-2.0 licence (© docker). 1,387 words, ~3,103 tokens.
.claude/skills/docker-sandboxes-network-credentials/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.This skill owns sbx policy (network egress) and sbx secret (service
secrets and registry credentials). The proxy enforces egress policy and
injects stored credentials on matching domains. Proxy-managed sentinels are
not usable upstream credentials, but OAuth passthrough can expose real
tokens to the sandbox. Egress policy does not protect a real credential
once leaked outside the sandbox; revoke or rotate a leaked credential.
Activate this skill when:
Do not use this skill when:
docker agent run --sandbox or managing its
docker agent sandbox allowlist — use docker-agent-run. If the CLI
is unclear, establish whether the user runs Docker Agent or standalone
sbx before choosing commands.docker-sandboxes-lifecycle.sbxenv.yaml file — use docker-sandboxes-env for the file format (this
skill's rules on precedence and injection scope still apply to what that
file provisions).credentials:/permissions.network:
block in a spec.yaml — use docker-sandboxes-kits for the schema (this
skill's model of what those declarations mean at runtime still applies).sbx policy init <allow-all|balanced|deny-all>. balanced
is the recommended starting point (typical dev traffic — AI services,
package registries — allowed). This is a one-time setup.sbx policy reset is destructive: it deletes the entire local policy
store and stops the daemon and every currently running sandbox. The
daemon restarts on the next daemon-backed command. It is not a lightweight way to "start over" or a
routine diagnostic step — never propose it as a first troubleshooting
move for a single misbehaving rule. Use targeted sbx policy rm network
(by --id or --resource) to remove one rule instead; reserve
sbx policy reset for when the policy store itself needs to be rebuilt
from scratch, and warn the user that it will stop running sandboxes
before running it.sbx policy allow network RESOURCES /
sbx policy deny network RESOURCES. RESOURCES is a comma-separated list
of exact hosts, *.example.com single-label wildcards, **.example.com
multi-label wildcards, optional :port suffixes, CIDR prefixes, or **
for "all hosts".sbx policy init balanced
sbx policy allow network "api.example.com,cdn.example.com"
sbx policy deny network ads.example.com--sandbox NAME to scope it to
one sandbox's local policy instead:sbx policy allow network --sandbox my-sandbox api.example.comsbx create/sbx run accept
--deny-network RESOURCE (repeatable) to add a per-sandbox deny rule. This
is safe to expose even under centralized (org) governance because a local
deny can only narrow, never widen, egress — it can never override an
org-level allow into a broader grant.sbx policy check network [--sandbox NAME] TARGET to test what the
current policy would do for a host/URL before it matters, and
sbx policy log [SANDBOX] to see what was actually allowed or blocked
historically, with the matching rule.sbx policy check network --sandbox my-sandbox api.example.com:443
sbx policy log my-sandbox --jsonsbx policy ls [SANDBOX] [--wide] lists active policies/rules; --wide
adds rule IDs (needed for sbx policy rm network --id) and per-resource
status. sbx policy inspect <policy-or-rule> gives full detail including
each rule's exact removal command or the reason it is read-only (e.g.
org-managed). To remove a sandbox-scoped rule, retain --sandbox NAME;
omitting it targets the global policy instead:sbx policy rm network --sandbox my-sandbox --resource api.example.com
sbx policy check network --sandbox my-sandbox api.example.comsbx secret set [SERVICE] stores a credential the proxy uses to
authenticate outbound requests on behalf of the agent. In the normal
proxy-managed flow, the sandbox sees a sentinel rather than the raw
secret; the proxy substitutes the real value on requests to the domains
the matching kit/binding declares.sbx secret set github # interactive
printf '%s' "$ANTHROPIC_API_KEY" | sbx secret set anthropicsbx policy; check the target domain in the intended scope
before debugging authentication:sbx policy check network --sandbox my-sandbox api.anthropic.comoauth.passthrough: true without a refresh sentinel, the
proxy forwards the real token response to the sandbox. The built-in
devin kit uses this mode. Review the agent's credential configuration
before promising that it cannot read a token; do not enable passthrough
merely to bypass an authentication failure. Even with sentinels, the
agent can exercise the credential's permissions on allowed services —
restrict token privileges as well as network access.--sandbox NAME scopes one to a
single sandbox.--ref (1Password op://... or an AWS Secrets
Manager ARN — requires an authenticated op/aws CLI) or --command
(runs a shell command and uses its stdout). --refresh controls the
resolution/cache policy (default 55m, or on-demand).sbx secret set anthropic --ref 'op://Private/Anthropic/api-key'
sbx secret set github --command 'gh auth token'--command and --ref are resolved on the host, with your own
privileges, and treated as trusted execution — never point --command
at anything an untrusted file or an agent's own output could influence.--env value or as a --kit-arg /
--env-arg value. Both land as literal, unmasked text — in the
sandbox's environment, in sbx env plan's state file, and potentially in
shell history — defeating the entire point of the credential store. Use
sbx secret set (or sbxenv.yaml's secrets:/registries: blocks, which
route through the same store) instead.sbx secret set-custom (experimental) covers a service sbx has no
built-in support for: the sandbox sees a placeholder value in an env var
you name (--env), and the proxy swaps in the real secret only on
requests to the --host pattern(s) you declare.sbx secret ls [--global|--sandbox NAME] [--service NAME] [--json] lists
what is stored, without revealing values. sbx secret rm [SERVICE] [--sandbox NAME] [--all|--registry HOST] [--force] removes it.sbx secret import [SERVICE] [--all] [--dry-run] [--force] offers to
import secrets already sitting in host environment variables (e.g.
OPENAI_API_KEY, GH_TOKEN) into the global store, prompting per entry
unless --all/--force. A service with an OAuth token already configured
is skipped — OAuth takes precedence at runtime over an imported API key.sbx secret set --registry HOST --password-stdin (optionally
--username) stores pull credentials for a container registry, used
to pull private template images and kit artifacts. Unlike service
secrets, registry credentials are host-only by default: they authenticate
pulls on the host and are never injected into any sandbox.gh auth token | sbx secret set --registry ghcr.io --password-stdin--all-sandboxes and --sandbox widen this differently — do not
confuse them:--all-sandboxes: credentials are used for host pulls and injected
by the proxy into every new sandbox's registry login (the
credential itself never enters the sandbox filesystem).--sandbox NAME: credentials are injected into that one sandbox
only.gh auth token | sbx secret set --all-sandboxes --registry ghcr.io --password-stdin
gh auth token | sbx secret set --sandbox my-sandbox --registry ghcr.io --password-stdin--registry-auth-endpoint naming the exact
trusted HTTPS URL — otherwise the cross-host token exchange is rejected.sbx secret rm --registry HOST --sandbox NAME removes only that sandbox's
registry credential; host-only and global (all-sandboxes) entries are
untouched. This does not revoke the upstream token or prevent use of
another applicable credential.sbx secret rm --registry ghcr.io --sandbox my-sandbox--sandbox, sbx secret rm --registry HOST removes both the
host-only and global entries. Add --all-sandboxes to remove only the
global entry instead.For docker agent run --sandbox and docker agent sandbox commands,
use docker-agent-run.
For creating, reattaching to, and removing the sandboxes these policies
and secrets apply to, use docker-sandboxes-lifecycle.
For declaring secrets:/registries:/bindings: inside a checked-in
sbxenv.yaml file that provisions them at environment-create time, use
docker-sandboxes-env.
For a kit's own credentials: and permissions.network: declarations
(what a kit asks for, as opposed to what the user has approved), use
docker-sandboxes-kits.
references/sources.md — provenance for every rule above (help captures, source paths, docs URLs).checks/verification.md — Verification runbook for network policy and secret commands (unexecuted runbook; run manually with an isolated --app-name, no real secret values).© docker, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in skills/docker-sandboxes-network-credentials of docker/skills.
Open the folder on GitHubat commit f791727
Docker Sandboxes Network Credentials next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Docker Sandboxes Network Credentials this skilldocker/skills | 539 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Reflexo ReleaseMyriad-Dreamin/typst.ts | 1.2k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Opentagamplifthq/opentag | 1.4k | — | ~1.3k | Automated safety check: Notes | MIT | |
| 1panel App Builderarch3rPro/1Panel-Appstore | 213 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Releasebmeares/Meerschaum | 154 | — | ~1.1k | Automated safety check: Notes | Apache-2.0 | |
| Releasematrixorigin/memoria | 607 | — | ~494 | Automated safety check: Pass | Apache-2.0 |
Myriad-Dreamin/typst.ts
Guide Reflexo/typst.ts release preparation and operator handoffs.
amplifthq/opentag
Deploy or operate OpenTag's supported paired setup when a user needs to bootstrap the self-hosted Docker Compose Control Plane and Slack Source App, configure or pair a local ACP Runner with a…
arch3rPro/1Panel-Appstore
A skill your agent uses when packaging Docker deployments as 1Panel local app store apps, including GitHub projects, docker-compose.yml files, docker run commands, app metadata, version directories…
bmeares/Meerschaum
Meerschaum release process — bump version, update changelog, stage dev→main PR, run CI, publish to PyPI, tag, GitHub release, build/push Docker images, rebuild docs on prod VPS.
matrixorigin/memoria
Cut a Memoria release. An agent skill from matrixorigin/memoria.
nrwl/nx
The single skill for reproducing an nx issue. An agent skill from nrwl/nx.
docker/skills
A skill your agent uses when creating, modifying, or debugging Docker Compose configurations, even if the user just says they need to wire services together, add a database to their stack, or set up…
docker/skills
A skill your agent uses when writing, reviewing, or optimizing Dockerfiles, even if the user just says their image is too large, their build is slow, or they need to harden a container for production.
docker/skills
A skill your agent uses when creating or editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent), including defining agents, models/providers, built-in or MCP toolsets…
docker/skills
A skill your agent uses when exposing a Docker Agent as a server (MCP, HTTP API, A2A, ACP, or OpenAI-compatible chat), distributing an agent via an OCI registry with docker agent share, or measuring…
docker/skills
A skill your agent uses when setting up, initializing, or Dockerizing a project, even if the user doesn't explicitly mention Docker but describes a need for containerized local development, adding a…
docker/skills
A skill your agent uses when authoring, planning, or running a declarative sbxenv.yaml file for Docker Sandboxes (sbx env create/run/plan/exec/rm), even if the user just says they want to "check in…
Categories
A skill your agent uses when configuring what a Docker Sandboxes (sbx) sandbox can reach on the network or which credentials it authenticates with, even if the user just says they want to "let the…. Docker Sandboxes Network Credentials is an agent skill from docker/skills, published by the product's own GitHub organization. Use this skill when configuring what a Docker Sandboxes (sbx) sandbox can reach on the network or which credentials it authenticates with, even if the user just says they want to "let the agent call an internal API", "block all network access", "give the agent a GitHub token", or "use a private registry image for a sandbox".
Docker Sandboxes Network Credentials fits situations like: configuring what a Docker Sandboxes (sbx) sandbox can reach on the network; which credentials it authenticates with; even if the user just says they want to let the agent call an internal API; block all network access.
Run `npx skills add docker/skills --skill docker-sandboxes-network-credentials -a claude-code`. Or copy the skill folder (skills/docker-sandboxes-network-credentials in docker/skills) into .claude/skills/docker-sandboxes-network-credentials in your project. Claude Code loads it when a task matches its description.
Run `npx skills add docker/skills --skill docker-sandboxes-network-credentials -a codex`. Or copy the skill folder (skills/docker-sandboxes-network-credentials in docker/skills) into .agents/skills/docker-sandboxes-network-credentials in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add docker/skills --skill docker-sandboxes-network-credentials -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker-sandboxes-network-credentials, .gemini/skills/docker-sandboxes-network-credentials, .github/skills/docker-sandboxes-network-credentials and .opencode/skills/docker-sandboxes-network-credentials in your project.
Going by SKILL.md and its folder, Docker Sandboxes Network Credentials needs the command-line tools its instructions call (docker and gh) and credentials named OPENAI_API_KEY, GH_TOKEN and ANTHROPIC_API_KEY. Our summary lists: Docker; A credential in ANTHROPIC_API_KEY; A credential in OPENAI_API_KEY. Compatibility (from SKILL.md): Standalone `sbx` CLI (not the legacy `docker sandbox` plugin wrapper). Source-verified against repository docker/sandboxes (github.com/docker/sandboxes) @ commit df5c96ba60484fa2c375469dbac912c205da6c37. Cross-checked against an installed sbx v0.42.0-503-g951b7f6d7 (commit 951b7f6d7f6bb260fac15077b607109ffe8ae012, older than the pinned source); no source-only differences were found for the commands this skill covers. `docker_help` does not cover standalone `sbx` syntax..
SKILL.md contains no URLs. Its commands use docker and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Docker Sandboxes Network Credentials is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Docker Sandboxes Network Credentials: Reflexo Release (Myriad-Dreamin/typst.ts, 1.2k stars), Opentag (amplifthq/opentag, 1.4k stars), 1panel App Builder (arch3rPro/1Panel-Appstore, 213 stars) and Release (bmeares/Meerschaum, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
docker (a GitHub organization, an official publisher) maintains it in docker/skills, which has 539 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 4, 2026.
Source: docker/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.