Agent skill

Vm Lab

by forefy in forefy/.context

Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro.

MITAuto-check: notesDevelopment

Install Vm Lab

skills CLI
$ npx skills add forefy/.context --skill vm-lab -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forefy/.context vm-lab --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunter-utils/vm-lab .claude/skills/vm-lab && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vm-lab
GitHub stars
152
Token cost
~1.9k tokens
SKILL.md length
795 words
Files
25
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro.

  • Works in 3 steps: Which guest - macOS, Windows, or Linux?… → Which provider - Parallels / VirtualBox… → Set up fresh, or use an existing guest?
  • Inspect an isolated guest
  • SKILL.md covers The core idea, On every invocation - ask…, Config & connect and Inspecting an app (installed…, plus 5 more sections
  • Runs Shell and PowerShell scripts from its folder; calls ssh and python3

What it does

Vm Lab is an agent skill from forefy/.context. Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro. Use to run or inspect an isolated guest.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 27 other files (for example `LEARNINGS.md`, `bootstrap/linux.sh` and `bootstrap/macos.sh`). Compatibility notes: Requires a hypervisor (Parallels/VirtualBox/VMware) and SSH to the guest

It sits in Development, covering Debugging. It works with Linux and macOS. The repository describes itself as: AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research. The licence is MIT.

When your agent uses it

  • Inspect an isolated guest
  • Tasks that involve Debugging

Example prompts

  • “/vm-lab”

Requirements

  • Python 3
  • A Bash shell
  • PowerShell
  • Compatibility (from SKILL.md): Requires a hypervisor (Parallels/VirtualBox/VMware) and SSH to the guest

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Which guest - macOS, Windows, or Linux? (drives toolkits/.md + SSH gotchas)
  2. Which provider - Parallels / VirtualBox / VMware? (drives providers/.sh)
  3. Set up fresh, or use an existing guest?

What it can do on your machine

Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell and PowerShell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • ssh
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires a hypervisor (Parallels/VirtualBox/VMware) and SSH to the guest

    From compatibility in the SKILL.md frontmatter.

Context cost

Vm Lab loads about 1.9k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 795 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:40
    rc_sudo mac 'fs_usage -w'    # sudo on mac/linux (echoes the guest pw via -S)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 795 words, ~1,905 tokens.

Download SKILL.mdSave it as .claude/skills/vm-lab/SKILL.md (or your agent's skills folder). This skill also uses 24 other files; get the full folder from GitHub.
name
vm-lab
description
Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro. Use to run or inspect an isolated guest.
compatibility
Requires a hypervisor (Parallels/VirtualBox/VMware) and SSH to the guest

VM Lab - cross-OS debugging on any free hypervisor

Disposable local VMs - real macOS, Windows, and Linux, isolated from this host - for cross-OS repro, live process/network/file/memory triage, code-signing checks, and dynamic instrumentation. Works on Parallels, VirtualBox, or VMware with no paid tooling.

The core idea

SSH is the universal substrate. The hypervisor only ever does four things - list, get-ip, power, snapshot - and each of the three has a free way to do all four (providers/*.sh). Everything valuable (the debug toolkit) runs over SSH and is hypervisor-agnostic; it only varies by guest OS and CPU arch. So this skill is a thin swappable provider layer + a big OS/arch-specific debugging core.

On every invocation - ask first, then route

This skill serves three OSes and three providers. Before doing anything, establish:

  1. Which guest - macOS, Windows, or Linux? (drives toolkits/<os>.md + SSH gotchas)
  2. Which provider - Parallels / VirtualBox / VMware? (drives providers/<name>.sh)
  3. Set up fresh, or use an existing guest?
    • Existing → confirm it's in config.local.env, ./ctl.sh <tag> up, ./verify.sh <tag>, go.
    • Fresh → bootstrap/ (Path A one-liner, or Path B unattended), then add to config, verify, snapshot.

If a config.local.env already defines the guest the task needs, skip the questions and use it. Ask only what's genuinely unresolved.

Config & connect

All mutable details live in config.local.env (copy from config.example.env; it's gitignored so your IPs/keys never get shared). Then:

bash
source lib.sh                 # loads config + helpers (rc, rc_sudo, ssh_cmd, prov, ctl)
rc mac 'uname -a'             # run on the macOS guest
rc win 'whoami'              # Windows: auto-wrapped as base64 PowerShell
rc lin 'uname -a'            # Linux
rc_sudo mac 'fs_usage -w'    # sudo on mac/linux (echoes the guest pw via -S)
./verify.sh                   # every guest: tools present + callable, with hints
./ctl.sh doctor               # host preflight: which providers/tools are present here
./ctl.sh win up               # boot + WAIT for sshd; then down|ip|ssh|snaps|vms
push mac ./tool /tmp/tool     # copy to guest (scp); pull mac /tmp/x.pcap ./  to fetch
tun  mac -L 8080:127.0.0.1:8080   # port-forward (MITM/reach a guest service)
./ctl.sh mac reset            # restore the clean snapshot (RESET_SNAPSHOT) - the disposable loop

Guests are tags (mac/win/lin, your choice) with {PROVIDER, OS, ARCH, VMNAME, IP, USER, AUTH, KEY/PW}. Leave IP blank to auto-discover (provider → mDNS → ARP).

Quoting caveat: rc <tag> 'cmd' single-quotes the command, so an embedded ' breaks it. For anything non-trivial (or with quotes) use rcs <tag> <script> [args]

  • it pushes a local script, runs it (bash for mac/linux, powershell -File for windows), and cleans up. Or the heredoc form rc mac 'bash -s' <<'EOF' … EOF. run_win (base64) is quote-safe for Windows one-liners.

Inspecting an app (installed or running)

./inspect-app.sh <tag> <app> - one-command triage of any app on a guest: identity, code signing / notarization, hardened-runtime + injectability verdict (tells you whether the Frida path will even work), entitlements, URL schemes, process tree, loaded modules, bundled runtimes. It auto-detects Electron and chains tools/electron-triage.sh, which maps the renderer↔main attack surface - exposeInMainWorld bridges, .handle("…") IPC channels, webPreferences security flags (contextIsolation/sandbox/nodeIntegration), and privileged custom protocols - all without node (a pure-python tools/asar.py extracts the asar on the guest).

bash
./inspect-app.sh mac Claude        # macOS: codesign/entitlements/schemes + electron map
./inspect-app.sh lin firefox       # linux: dpkg/rpm/flatpak + systemd + maps
./inspect-app.sh win Claude        # windows: uninstall-registry + signature + modules

Per-OS logic is in tools/inspect-<os>.{sh,ps1}; asar.py is a reusable standalone Electron extractor (python3 tools/asar.py app.asar --list).

Fresh guest → SSH (bootstrap)

A pristine guest has no sshd/key, and only VirtualBox can type into the console headlessly. Two paths (Path B detailed in bootstrap/unattended.md):

  • Path A - one-line paste: paste bootstrap/<os>.{sh,ps1} into the guest console once (a human is most reliable here; some GUI consoles mangle synthetic input), then everything is over SSH.
  • Path B - unattended/seed (best for VirtualBox/VMware): bake sshd+key in at install via cloud-init / autounattend.xml (bootstrap/unattended.md). After it connects: pin/blank the IP in config, ./verify.sh <tag>, then snapshot so you never bootstrap again. You supply ISOs; bootstrap/unattended.md lists official sources and can seed them.
Show full SKILL.md (300 more words)Show less

Run commands reliably over SSH - per OS

  • macOS (toolkits/macos.md): no timeout; bound live captures with background+sleep+kill -INT (never -9); eslogger needs a pty (script) or it shows 0 events.
  • Windows (toolkits/windows.md): run_win sends PowerShell as UTF-16LE base64 and strips CLIXML noise; structured output → write-to-file-then-read; cmd one-liners are reliable.
  • Linux (toolkits/linux.md): the easy one - one shell, real timeout, real signals; rc_sudo for root.

Toolkits (task → tool matrix + install recipes)

Each toolkits/<os>.md has the full matrix and arch-forked install steps:

  • macOS/arm64 - built-ins first (ps, eslogger, lsof, nettop, tcpdump, vmmap, codesign, sample, log); CLT for otool/nm; optional Frida. VM caveat: powermetrics needs --samplers tasks; dtruss SIP-blocked.
  • Windows/arm64|x64 - native cmdlets first; add only autorunsc/handle/ sigcheck/procdump/Procmon; optional cdb. VM caveat: wpr fails (0x80070032) → use logman/Procmon. Pick ARM64 vs x64 downloads by ARCH.
  • Linux/x64|arm64 - apt/dnf/pacman install everything: strace, bpftrace, perf, gdb, ss, lsof, tcpdump, auditd. VM caveat: perf hardware counters usually unavailable → software events only.

Maintainable & self-remembering

When you learn a new environment quirk, install recipe, or gotcha, append it to LEARNINGS.md (dated, tagged by OS/arch/provider) - that file travels with the repo, so the knowledge compounds across sessions and users instead of living in one machine's memory. Re-run ./verify.sh anytime to re-prove every tool is callable.

Notes

  • Safety - the default SSH_OPTS disable host-key checking (right for disposable, re-snapshotted VMs; removes MITM protection). Never point this at a machine you care about; override SSH_OPTS in config for anything non-throwaway. config.local.env is sourced as shell - only use configs you trust.
  • Disposable - installing tools, killing processes, editing config, rebooting are all fair game; a snapshot restore recovers anything. Take a clean snapshot right after bootstrap.
  • No paid CLIs: Parallels needs only free prlctl list; VirtualBox's VBoxManage is fully free; VMware Fusion/Workstation are free for personal use. The provider layer degrades to SSH-based fallbacks when a native verb is gated.

© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 24 other files in skills/hunter-utils/vm-lab of forefy/.context.

  • SKILL.md
  • .gitignore
  • LEARNINGS.md
  • bootstrap/linux.sh
  • bootstrap/macos.sh
  • bootstrap/unattended.md
  • bootstrap/windows.ps1
  • config.example.env
  • ctl.sh
  • inspect-app.sh
  • lib.sh
  • providers/common.sh
  • providers/parallels.sh
  • providers/virtualbox.sh
  • providers/vmware.sh
  • toolkits/linux.md
  • toolkits/macos.md
  • toolkits/windows.md
  • … and 7 more

Open the folder on GitHubat commit c8ff161

Compare with similar skills

Vm Lab next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vm Lab compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vm Lab this skillforefy/.context152—~1.9kAutomated safety check: NotesMIT
Gearcoleco Debuggingdrhelius/Gearcoleco141—~3.5kAutomated safety check: PassGPL-3.0
OpenLogi Device DiagnosisAprilNEA/OpenLogi23k—~1.6kAutomated safety check: PassApache-2.0
Dotnet Debuggingnovotnyllc/dotnet-artisan233—~2.1kAutomated safety check: PassMIT
Browser Setupclacky-ai/openclacky1.2k—~3.1kAutomated safety check: NotesMIT
Os Scriptingaiskillstore/marketplace4303 repos~2.2kAutomated safety check: NotesNone

Similar skills

  • Gearcoleco Debugging

    drhelius/Gearcoleco

    Debug and trace ColecoVision and Super Game Module games using the Gearcoleco emulator MCP server.

    141 GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check passed
  • OpenLogi Device Diagnosis

    AprilNEA/OpenLogi

    Finds the first failing layer when an OpenLogi Logitech device is missing or misbehaving across enumeration, open, probe, IPC and UI.

    23k GitHub stars~1.6k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Dotnet Debugging

    novotnyllc/dotnet-artisan

    Debugs Windows and Linux/macOS applications (native, .NET/CLR, mixed-mode) with WinDbg MCP (crash dumps, !analyze, !syncblk, !dlk, !runaway, !dumpheap, !gcroot, BSOD), dotnet-dump, lldb with SOS…

    233 GitHub stars~2.1k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Browser Setup

    clacky-ai/openclacky

    Configure the browser tool for Clacky. An agent skill from clacky-ai/openclacky.

    1.2k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check: notes
  • Os Scripting

    aiskillstore/marketplace

    Operating system and shell scripting troubleshooting workflow for Linux, macOS, and Windows.

    430 GitHub starsUsed in 3 repos~2.2k tokens
    DevelopmentAuto-check: notes
  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed

More from forefy/.context

All 20 skills in this repo
  • Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.

    152 GitHub stars~951 tokensUpdated 2 days ago
    Auto-check passed
  • Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.

    152 GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.

    152 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Audit Scope

    forefy/.context

    Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.

    152 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • External Enumeration

    forefy/.context

    Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

    152 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    Auto-check passed

Works with

Categories

Questions about Vm Lab

What does Vm Lab do?

Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro. context. Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro.

When should I use Vm Lab?

Vm Lab fits situations like: inspect an isolated guest; tasks that involve Debugging.

How do I install Vm Lab in Claude Code?

Run `npx skills add forefy/.context --skill vm-lab -a claude-code`. Or copy the skill folder (skills/hunter-utils/vm-lab in forefy/.context) into .claude/skills/vm-lab in your project. Claude Code loads it when a task matches its description.

How do I install Vm Lab in Codex?

Run `npx skills add forefy/.context --skill vm-lab -a codex`. Or copy the skill folder (skills/hunter-utils/vm-lab in forefy/.context) into .agents/skills/vm-lab in your project. Codex loads it when a task matches its description.

Can I use Vm Lab in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill vm-lab -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vm-lab, .gemini/skills/vm-lab, .github/skills/vm-lab and .opencode/skills/vm-lab in your project.

What does Vm Lab need to run?

Going by SKILL.md and its folder, Vm Lab needs a shell and PowerShell for the scripts in its folder and the command-line tools its instructions call (ssh and python3). Our summary lists: Python 3; A Bash shell; PowerShell. Compatibility (from SKILL.md): Requires a hypervisor (Parallels/VirtualBox/VMware) and SSH to the guest.

Does Vm Lab access the network?

SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Vm Lab safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Vm Lab use?

Vm Lab is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vm Lab use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vm Lab?

Skills that share tags, products or a category with Vm Lab: Gearcoleco Debugging (drhelius/Gearcoleco, 141 stars), OpenLogi Device Diagnosis (AprilNEA/OpenLogi, 23k stars), Dotnet Debugging (novotnyllc/dotnet-artisan, 233 stars) and Browser Setup (clacky-ai/openclacky, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vm Lab?

forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.

Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.