Official agent skill

Kit Author

by docker in docker/sbx-kits-contrib

Author Docker Sandboxes kits (agents and mixins) — spec.yaml schema, full lifecycle from sourcing through composition, injection, and runtime, plus distribution and TCK testing.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Kit Author

skills CLI
$ npx skills add docker/sbx-kits-contrib --skill kit-author -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install docker/sbx-kits-contrib kit-author --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/docker/sbx-kits-contrib.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kit-author .claude/skills/kit-author && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kit-author
GitHub stars
165
Token cost
~989 tokens
SKILL.md length
420 words
Files
11
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Author Docker Sandboxes kits (agents and mixins) — spec.yaml schema, full lifecycle from sourcing through composition, injection, and runtime, plus distribution and TCK testing.

  • Tasks that involve Containers
  • SKILL.md covers References and Topics
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Kit Author is an agent skill from docker/sbx-kits-contrib, published by the product's own GitHub organization. Author Docker Sandboxes kits (agents and mixins) — spec.yaml schema, full lifecycle from sourcing through composition, injection, and runtime, plus distribution and TCK testing.

Its SKILL.md is about 990 tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files (for example `topics/authoring.md`, `topics/bindings.md` and `topics/composition.md`).

It sits in DevOps & Cloud, covering Containers. It works with Docker. The repository describes itself as: Community repository for sbx kits. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Containers

Example prompts

  • “/kit-author”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 1710564. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.docker.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kit Author loads about 989 tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 420 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~989

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from docker/sbx-kits-contrib at commit 1710564, republished under its Apache-2.0 licence (© docker). 420 words, ~989 tokens.

Download SKILL.mdSave it as .claude/skills/kit-author/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
kit-author
description
Author Docker Sandboxes kits (agents and mixins) — spec.yaml schema, full lifecycle from sourcing through composition, injection, and runtime, plus distribution and TCK testing.
globs
**/spec.yaml, **/spec.yml, spec/**, tck/**

Kit Author Skill

How to design, write, validate, and distribute kit artifacts (kind: sandbox and kind: mixin) for Docker Sandboxes. Kits are declarative — a spec.yaml plus an optional files/ tree — and the sbx engine translates them into container customizations at sandbox creation or kit add time.

Use this skill when:

  • Writing a new kit (mixin or agent) from scratch
  • Editing an existing kit in this repository
  • Debugging why a kit's commands, files, network rules, or credentials are not taking effect
  • Packaging, publishing, or consuming kits from OCI or git sources
  • Reviewing kit PRs in this repository

References

Topics

Primary topics describe the v2 spec form (schemaVersion: "2"):

  • Spec anatomy — spec.yaml top-level fields (mixins, licenses, extends, locked, args) and every section (sandbox with image:/build: + entrypoint/command, agentInstructions with filename/content, credentials[] with apiKey/oauth and the scheme sugar, permissions.network, ports, environment, setup with install/startup/files, volumes, files/).
  • Lifecycle — Sourcing → load (schemaVersion-forked decode) → normalize → validate → extends → compose → configure → hooks → container → runtime. What happens at each stage as observed by the kit author.
  • Composition — extends: inheritance vs --kit composition. Merge strategies per section, conflict rules, what "last wins" means.
  • Authoring guide — Step-by-step recipes for a minimal mixin and a full sandbox kit. Where to put files. When to use files/ vs setup.files.
  • Bindings — The user-side ~/.config/sbx/credentials.yaml file: how kits and users split the credential contract.
  • Image publishing — For a kind: sandbox kit whose image this repo builds: drop a Dockerfile at the kit root and name it docker.io/sbx/<kit>-image:latest; CI discovers it, no workflow edit. Why sandbox.build: is not the answer yet, and the pre-publish window where the TCK cannot pull the image.
  • Distribution — Local dir, OCI digests, git commit-SHA references. Strict pinning rule. Schema-version compatibility (v2 is a breaking grammar). sbx kit push/pull/inspect/validate/delete.
  • Testing — TCK suite, e2e under deny-all (mandatory locally — CI's e2e legs are skipped for fork PRs), manual sbx kit add verification, proving allow-list enforcement.
  • Pitfalls — Surprises seen in practice: install-completed is exit-code only, setup.startup runs on every container start (idempotency required), kit add cannot apply immutable settings, setup.install idempotency + duplication footguns + SBX_CRED_<SERVICE>_MODE contract, inject/binding domain intersection.
Show full SKILL.md (48 more words)Show less

Legacy reference:

  • v1 → v2 migration — Every v1 surface, its v2 equivalent, the migrate-v1-to-v2.go script's coverage, and what to migrate by hand. The loader forks on schemaVersion; v2 is a clean grammar with no shims, while v1 keeps loading with deprecation warnings on Artifact.Warnings until the Phase 6 cutover.

© docker, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files in skills/kit-author of docker/sbx-kits-contrib.

  • SKILL.md
  • topics/authoring.md
  • topics/bindings.md
  • topics/composition.md
  • topics/distribution.md
  • topics/image-publishing.md
  • topics/lifecycle.md
  • topics/pitfalls.md
  • topics/spec-anatomy.md
  • topics/testing.md
  • topics/v1-migration.md

Open the folder on GitHubat commit 1710564

Compare with similar skills

Kit Author next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kit Author compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kit Author this skilldocker/sbx-kits-contrib165—~989Automated safety check: PassApache-2.0
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Build Openshell Mxc WindowsNVIDIA/OpenShell15k—~4.9kAutomated safety check: PassApache-2.0

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    15k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Omnigent Docker Compose Deploy

    omnigent-ai/omnigent

    Brings up the Omnigent server and Postgres as a Docker compose stack on any Docker host, and covers the Dockerfile's runtime and host build targets for extending it to a new platform.

    11k GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check: notes

Works with

Categories

Questions about Kit Author

What does Kit Author do?

Author Docker Sandboxes kits (agents and mixins) — spec.yaml schema, full lifecycle from sourcing through composition, injection, and runtime, plus distribution and TCK testing. Kit Author is an agent skill from docker/sbx-kits-contrib, published by the product's own GitHub organization.yaml schema, full lifecycle from sourcing through composition, injection, and runtime, plus distribution and TCK testing.

When should I use Kit Author?

Kit Author fits situations like: tasks that involve Containers.

How do I install Kit Author in Claude Code?

Run `npx skills add docker/sbx-kits-contrib --skill kit-author -a claude-code`. Or copy the skill folder (skills/kit-author in docker/sbx-kits-contrib) into .claude/skills/kit-author in your project. Claude Code loads it when a task matches its description.

How do I install Kit Author in Codex?

Run `npx skills add docker/sbx-kits-contrib --skill kit-author -a codex`. Or copy the skill folder (skills/kit-author in docker/sbx-kits-contrib) into .agents/skills/kit-author in your project. Codex loads it when a task matches its description.

Can I use Kit Author in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add docker/sbx-kits-contrib --skill kit-author -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kit-author, .gemini/skills/kit-author, .github/skills/kit-author and .opencode/skills/kit-author in your project.

What does Kit Author need to run?

SKILL.md names no scripts, command-line tools or credentials: Kit Author is instructions for the agent only. Our summary lists: Docker.

Does Kit Author access the network?

SKILL.md names 1 domain. As links in the text: docs.docker.com. This is read from the text; nothing was executed.

Is Kit Author safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kit Author use?

Kit Author is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kit Author use?

About 989 tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kit Author?

Skills that share tags, products or a category with Kit Author: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kit Author?

docker (a GitHub organization, an official publisher) maintains it in docker/sbx-kits-contrib, which has 165 GitHub stars. The repository was last updated on October 7, 2026.

Source: docker/sbx-kits-contrib on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.