Gearcoleco Debugging
drhelius/Gearcoleco
Debug and trace ColecoVision and Super Game Module games using the Gearcoleco emulator MCP server.
Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro.
$ npx skills add forefy/.context --skill vm-lab -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forefy/.context vm-lab --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunter-utils/vm-lab .claude/skills/vm-lab && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vm-lab" agent skill from https://github.com/forefy/.context/tree/main/skills/hunter-utils/vm-lab into .claude/skills/vm-lab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vm-lab", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forefy/.context/tree/main/skills/hunter-utils/vm-labType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forefy/.context --skill vm-lab -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forefy/.context vm-lab --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/hunter-utils/vm-lab .agents/skills/vm-lab && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vm-lab" agent skill from https://github.com/forefy/.context/tree/main/skills/hunter-utils/vm-lab into .agents/skills/vm-lab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vm-lab", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forefy/.context --skill vm-lab -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forefy/.context vm-lab --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/hunter-utils/vm-lab .cursor/skills/vm-lab && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vm-lab" agent skill from https://github.com/forefy/.context/tree/main/skills/hunter-utils/vm-lab into .cursor/skills/vm-lab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vm-lab", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forefy/.context.git --path skills/hunter-utils/vm-lab--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forefy/.context --skill vm-lab -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forefy/.context vm-lab --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/hunter-utils/vm-lab .gemini/skills/vm-lab && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vm-lab" agent skill from https://github.com/forefy/.context/tree/main/skills/hunter-utils/vm-lab into .gemini/skills/vm-lab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vm-lab", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forefy/.context vm-labInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forefy/.context --skill vm-lab -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/hunter-utils/vm-lab .github/skills/vm-lab && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vm-lab" agent skill from https://github.com/forefy/.context/tree/main/skills/hunter-utils/vm-lab into .github/skills/vm-lab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vm-lab", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forefy/.context --skill vm-lab -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forefy/.context vm-lab --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/hunter-utils/vm-lab .opencode/skills/vm-lab && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vm-lab" agent skill from https://github.com/forefy/.context/tree/main/skills/hunter-utils/vm-lab into .opencode/skills/vm-lab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vm-lab", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vm-labSpin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro.
Vm Lab is an agent skill from forefy/.context. Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro. Use to run or inspect an isolated guest.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 27 other files (for example `LEARNINGS.md`, `bootstrap/linux.sh` and `bootstrap/macos.sh`). Compatibility notes: Requires a hypervisor (Parallels/VirtualBox/VMware) and SSH to the guest
It sits in Development, covering Debugging. It works with Linux and macOS. The repository describes itself as: AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (Shell and PowerShell, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
sshpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use ssh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires a hypervisor (Parallels/VirtualBox/VMware) and SSH to the guest
From compatibility in the SKILL.md frontmatter.
Vm Lab loads about 1.9k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 795 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
rc_sudo mac 'fs_usage -w' # sudo on mac/linux (echoes the guest pw via -S)Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 795 words, ~1,905 tokens.
.claude/skills/vm-lab/SKILL.md (or your agent's skills folder). This skill also uses 24 other files; get the full folder from GitHub.Disposable local VMs - real macOS, Windows, and Linux, isolated from this host - for cross-OS repro, live process/network/file/memory triage, code-signing checks, and dynamic instrumentation. Works on Parallels, VirtualBox, or VMware with no paid tooling.
SSH is the universal substrate. The hypervisor only ever does four things -
list, get-ip, power, snapshot - and each of the three has a free way to do
all four (providers/*.sh). Everything valuable (the debug toolkit) runs over SSH
and is hypervisor-agnostic; it only varies by guest OS and CPU arch. So this
skill is a thin swappable provider layer + a big OS/arch-specific debugging core.
This skill serves three OSes and three providers. Before doing anything, establish:
toolkits/<os>.md + SSH gotchas)providers/<name>.sh)config.local.env, ./ctl.sh <tag> up, ./verify.sh <tag>, go.bootstrap/ (Path A one-liner, or Path B unattended), then add to config, verify, snapshot.If a config.local.env already defines the guest the task needs, skip the questions
and use it. Ask only what's genuinely unresolved.
All mutable details live in config.local.env (copy from config.example.env;
it's gitignored so your IPs/keys never get shared). Then:
source lib.sh # loads config + helpers (rc, rc_sudo, ssh_cmd, prov, ctl)
rc mac 'uname -a' # run on the macOS guest
rc win 'whoami' # Windows: auto-wrapped as base64 PowerShell
rc lin 'uname -a' # Linux
rc_sudo mac 'fs_usage -w' # sudo on mac/linux (echoes the guest pw via -S)
./verify.sh # every guest: tools present + callable, with hints
./ctl.sh doctor # host preflight: which providers/tools are present here
./ctl.sh win up # boot + WAIT for sshd; then down|ip|ssh|snaps|vms
push mac ./tool /tmp/tool # copy to guest (scp); pull mac /tmp/x.pcap ./ to fetch
tun mac -L 8080:127.0.0.1:8080 # port-forward (MITM/reach a guest service)
./ctl.sh mac reset # restore the clean snapshot (RESET_SNAPSHOT) - the disposable loopGuests are tags (mac/win/lin, your choice) with {PROVIDER, OS, ARCH, VMNAME, IP, USER, AUTH, KEY/PW}. Leave IP blank to auto-discover (provider → mDNS → ARP).
Quoting caveat: rc <tag> 'cmd' single-quotes the command, so an embedded '
breaks it. For anything non-trivial (or with quotes) use rcs <tag> <script> [args]
powershell -File for
windows), and cleans up. Or the heredoc form rc mac 'bash -s' <<'EOF' … EOF.
run_win (base64) is quote-safe for Windows one-liners../inspect-app.sh <tag> <app> - one-command triage of any app on a guest:
identity, code signing / notarization, hardened-runtime + injectability verdict
(tells you whether the Frida path will even work), entitlements, URL schemes,
process tree, loaded modules, bundled runtimes. It auto-detects Electron and
chains tools/electron-triage.sh, which maps the renderer↔main attack surface -
exposeInMainWorld bridges, .handle("…") IPC channels, webPreferences security
flags (contextIsolation/sandbox/nodeIntegration), and privileged custom protocols -
all without node (a pure-python tools/asar.py extracts the asar on the guest).
./inspect-app.sh mac Claude # macOS: codesign/entitlements/schemes + electron map
./inspect-app.sh lin firefox # linux: dpkg/rpm/flatpak + systemd + maps
./inspect-app.sh win Claude # windows: uninstall-registry + signature + modulesPer-OS logic is in tools/inspect-<os>.{sh,ps1}; asar.py is a reusable
standalone Electron extractor (python3 tools/asar.py app.asar --list).
A pristine guest has no sshd/key, and only VirtualBox can type into the console
headlessly. Two paths (Path B detailed in bootstrap/unattended.md):
bootstrap/<os>.{sh,ps1} into the guest
console once (a human is most reliable here; some GUI consoles mangle synthetic
input), then everything is over SSH.bootstrap/unattended.md).
After it connects: pin/blank the IP in config, ./verify.sh <tag>, then snapshot
so you never bootstrap again. You supply ISOs; bootstrap/unattended.md lists
official sources and can seed them.toolkits/macos.md): no timeout; bound live captures with
background+sleep+kill -INT (never -9); eslogger needs a pty (script) or
it shows 0 events.toolkits/windows.md): run_win sends PowerShell as UTF-16LE
base64 and strips CLIXML noise; structured output → write-to-file-then-read;
cmd one-liners are reliable.toolkits/linux.md): the easy one - one shell, real timeout, real
signals; rc_sudo for root.Each toolkits/<os>.md has the full matrix and arch-forked install steps:
ps, eslogger, lsof, nettop, tcpdump,
vmmap, codesign, sample, log); CLT for otool/nm; optional Frida.
VM caveat: powermetrics needs --samplers tasks; dtruss SIP-blocked.autorunsc/handle/
sigcheck/procdump/Procmon; optional cdb. VM caveat: wpr fails
(0x80070032) → use logman/Procmon. Pick ARM64 vs x64 downloads by ARCH.apt/dnf/pacman install everything: strace,
bpftrace, perf, gdb, ss, lsof, tcpdump, auditd. VM caveat: perf
hardware counters usually unavailable → software events only.When you learn a new environment quirk, install recipe, or gotcha, append it to
LEARNINGS.md (dated, tagged by OS/arch/provider) - that file travels with the
repo, so the knowledge compounds across sessions and users instead of living in one
machine's memory. Re-run ./verify.sh anytime to re-prove every tool is callable.
SSH_OPTS disable host-key checking (right for
disposable, re-snapshotted VMs; removes MITM protection). Never point this at a
machine you care about; override SSH_OPTS in config for anything non-throwaway.
config.local.env is sourced as shell - only use configs you trust.prlctl list; VirtualBox's
VBoxManage is fully free; VMware Fusion/Workstation are free for personal use.
The provider layer degrades to SSH-based fallbacks when a native verb is gated.© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 24 other files in skills/hunter-utils/vm-lab of forefy/.context.
Open the folder on GitHubat commit c8ff161
Vm Lab next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vm Lab this skillforefy/.context | 152 | — | ~1.9k | Automated safety check: Notes | MIT | |
| Gearcoleco Debuggingdrhelius/Gearcoleco | 141 | — | ~3.5k | Automated safety check: Pass | GPL-3.0 | |
| OpenLogi Device DiagnosisAprilNEA/OpenLogi | 23k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Dotnet Debuggingnovotnyllc/dotnet-artisan | 233 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Browser Setupclacky-ai/openclacky | 1.2k | — | ~3.1k | Automated safety check: Notes | MIT | |
| Os Scriptingaiskillstore/marketplace | 430 | 3 repos | ~2.2k | Automated safety check: Notes | None |
drhelius/Gearcoleco
Debug and trace ColecoVision and Super Game Module games using the Gearcoleco emulator MCP server.
AprilNEA/OpenLogi
Finds the first failing layer when an OpenLogi Logitech device is missing or misbehaving across enumeration, open, probe, IPC and UI.
novotnyllc/dotnet-artisan
Debugs Windows and Linux/macOS applications (native, .NET/CLR, mixed-mode) with WinDbg MCP (crash dumps, !analyze, !syncblk, !dlk, !runaway, !dumpheap, !gcroot, BSOD), dotnet-dump, lldb with SOS…
clacky-ai/openclacky
Configure the browser tool for Clacky. An agent skill from clacky-ai/openclacky.
aiskillstore/marketplace
Operating system and shell scripting troubleshooting workflow for Linux, macOS, and Windows.
dotnet/skills
Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.
forefy/.context
Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.
forefy/.context
Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.
forefy/.context
Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.
forefy/.context
Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.
forefy/.context
Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.
forefy/.context
Comprehensive smart contract security audit framework with multi-expert analysis.
Categories
Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro. context. Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro.
Vm Lab fits situations like: inspect an isolated guest; tasks that involve Debugging.
Run `npx skills add forefy/.context --skill vm-lab -a claude-code`. Or copy the skill folder (skills/hunter-utils/vm-lab in forefy/.context) into .claude/skills/vm-lab in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forefy/.context --skill vm-lab -a codex`. Or copy the skill folder (skills/hunter-utils/vm-lab in forefy/.context) into .agents/skills/vm-lab in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill vm-lab -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vm-lab, .gemini/skills/vm-lab, .github/skills/vm-lab and .opencode/skills/vm-lab in your project.
Going by SKILL.md and its folder, Vm Lab needs a shell and PowerShell for the scripts in its folder and the command-line tools its instructions call (ssh and python3). Our summary lists: Python 3; A Bash shell; PowerShell. Compatibility (from SKILL.md): Requires a hypervisor (Parallels/VirtualBox/VMware) and SSH to the guest.
SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Vm Lab is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Vm Lab: Gearcoleco Debugging (drhelius/Gearcoleco, 141 stars), OpenLogi Device Diagnosis (AprilNEA/OpenLogi, 23k stars), Dotnet Debugging (novotnyllc/dotnet-artisan, 233 stars) and Browser Setup (clacky-ai/openclacky, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.
Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.