Agent skill

Containers Internals

by mohitmishra786 in mohitmishra786/low-level-dev-skills

Linux containers internals skill for namespaces, cgroups, and OCI.

MITAuto-check: notesDevOps & Cloud

Install Containers Internals

skills CLI
$ npx skills add mohitmishra786/low-level-dev-skills --skill containers-internals -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitmishra786/low-level-dev-skills containers-internals --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/virtualization/containers-internals .claude/skills/containers-internals && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
containers-internals
GitHub stars
252
Token cost
~1.6k tokens
SKILL.md length
292 words
Files
1
Skills in repo
138
Repo updated
First seen
Licence
MIT

At a glance

Linux containers internals skill for namespaces, cgroups, and OCI.

  • Works in 8 steps: Namespaces → cgroups v2 → overlayfs → …
  • Understanding clone/unshare namespaces
  • SKILL.md covers Purpose, When to Use, Workflow and Common Problems, plus 1 more section
  • Calls docker; reaches github.com

What it does

Containers Internals is an agent skill from mohitmishra786/low-level-dev-skills. Linux containers internals skill for namespaces, cgroups, and OCI. Use when understanding clone/unshare namespaces, cgroups v2 limits, overlayfs, runc, seccomp profiles, capabilities, or escape mitigations. Activates on queries about namespaces, cgroups, overlayfs, runc, seccomp-bpf, OCI spec, or container escape.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers. It works with Linux and Docker. The repository describes itself as: A curated suite of AI agent skills for systems and low-level programming with C/C++, Rust, and Zig toolchains, covering compilers, debuggers, profilers, build systems…. The licence is MIT.

When your agent uses it

  • Understanding clone/unshare namespaces
  • Cgroups v2 limits
  • Seccomp profiles
  • Escape mitigations

Example prompts

  • “/containers-internals”

Requirements

  • Docker

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Namespaces
  2. cgroups v2
  3. overlayfs
  4. runc and OCI spec
  5. seccomp-bpf
  6. Linux capabilities
  7. User namespace rootless
  8. Escape mitigations

What it can do on your machine

Read from SKILL.md and the folder at commit bdc5847. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Containers Internals loads about 1.6k tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 292 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:122
    sudo runc run mycontainer

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitmishra786/low-level-dev-skills at commit bdc5847, republished under its MIT licence (© mohitmishra786). 292 words, ~1,617 tokens.

Download SKILL.mdSave it as .claude/skills/containers-internals/SKILL.md (or your agent's skills folder).
name
containers-internals
description
Linux containers internals skill for namespaces, cgroups, and OCI. Use when understanding clone/unshare namespaces, cgroups v2 limits, overlayfs, runc, seccomp profiles, capabilities, or escape mitigations. Activates on queries about namespaces, cgroups, overlayfs, runc, seccomp-bpf, OCI spec, or container escape.

Containers Internals

Purpose

Guide agents through Linux container internals: namespaces (clone, unshare, nsenter), cgroups v2 resource limits, overlayfs storage, runc and the OCI runtime spec, seccomp-bpf filtering, Linux capabilities for privilege dropping, and container escape mitigations.

When to Use

  • Understanding how Docker/Podman isolate processes under the hood
  • Debugging container resource limits (OOM, CPU throttling)
  • Writing custom seccomp profiles for sandboxed workloads
  • Building minimal containers without Docker
  • Investigating container escape vulnerabilities
  • Tuning cgroups v2 for Kubernetes pods

Workflow

1. Namespaces
bash
# List namespaces for a process
ls -la /proc/self/ns/
readlink /proc/self/ns/pid
readlink /proc/1234/ns/net

# Enter container namespaces
nsenter -t <pid> -m -u -i -n -p bash

# Unshare namespaces (manual container)
unshare --fork --mount-proc --pid --net --uts --ipc bash
NamespaceIsolates
CLONE_NEWNS (mount)Mount points, filesystem roots
CLONE_NEWPIDProcess IDs
CLONE_NEWNETNetwork stack
CLONE_NEWUTSHostname
CLONE_NEWIPCSysV IPC, POSIX message queues
CLONE_NEWUSERUID/GID mappings
CLONE_NEWCGROUPcgroup root view
c
// clone() with namespaces
#define _GNU_SOURCE
#include <sched.h>

int container_init(void *arg) {
    sethostname("container", 9);
    mount("proc", "/proc", "proc", 0, NULL);
    execv("/bin/sh", (char *[]){"/bin/sh", NULL});
    return 1;
}

int stack[1024 * 1024];
clone(container_init, stack + sizeof(stack)/sizeof(int),
      CLONE_NEWPID | CLONE_NEWNS | CLONE_NEWNET | SIGCHLD, NULL);
2. cgroups v2
bash
# Unified hierarchy (cgroup v2)
mount -t cgroup2 none /sys/fs/cgroup

# Create cgroup and set limits
mkdir /sys/fs/cgroup/mycontainer
echo $$ > /sys/fs/cgroup/mycontainer/cgroup.procs

# Memory limit 256MB
echo 256M > /sys/fs/cgroup/mycontainer/memory.max

# CPU weight (relative to siblings, default 100)
echo 50 > /sys/fs/cgroup/mycontainer/cpu.weight

# IO weight
echo default 100 > /sys/fs/cgroup/mycontainer/io.weight
bash
# Check current cgroup
cat /proc/self/cgroup

# OOM events
cat /sys/fs/cgroup/mycontainer/memory.events
3. overlayfs
overlayfs layers
├── lowerdir (read-only image layers)
├── upperdir (container writes)
├── workdir (internal bookkeeping)
└── merged (mount point seen by container)
bash
mount -t overlay overlay \
  -o lowerdir=lower1:lower2,upperdir=upper,workdir=work \
  merged

# Docker stores layers in /var/lib/docker/overlay2/

Copy-on-write: reads from lower, writes go to upper.

4. runc and OCI spec
bash
# Generate default OCI config
mkdir -p mycontainer/rootfs
runc spec

# Edit config.json — namespaces, mounts, process args
# Run container
sudo runc run mycontainer

# List
runc list

config.json key sections:

json
{
  "ociVersion": "1.0.2",
  "process": {
    "args": ["/bin/sh"],
    "capabilities": { "bounding": ["CAP_NET_BIND_SERVICE"] }
  },
  "linux": {
    "namespaces": [
      {"type": "pid"}, {"type": "network"}, {"type": "mount"}
    ],
    "seccomp": { ... },
    "resources": {
      "memory": { "limit": 268435456 }
    }
  },
  "root": { "path": "rootfs", "readonly": false }
}
5. seccomp-bpf
c
// libseccomp example — block mount
#include <seccomp.h>

scmp_filter_ctx ctx = seccomp_init(SCMP_ACT_ALLOW);
seccomp_rule_add(ctx, SCMP_ACT_ERRNO(EPERM), SCMP_SYS(mount), 0);
seccomp_rule_add(ctx, SCMP_ACT_ERRNO(EPERM), SCMP_SYS(pivot_root), 0);
seccomp_load(ctx);
bash
# Docker default seccomp profile (JSON)
# https://github.com/moby/moby/blob/master/profiles/seccomp/default.json

# Audit blocked syscalls
# kernel: seccomp log via auditd
ausearch -m SECCOMP
ActionEffect
SCMP_ACT_KILLKill process
SCMP_ACT_ERRNO(n)Return error
SCMP_ACT_TRACENotify tracer
SCMP_ACT_ALLOWPermit syscall
6. Linux capabilities
bash
# Drop all caps except needed
capsh --drop=all --add=net_bind_service -- -c '/app/server'

# File capabilities
setcap cap_net_bind_service+ep /usr/bin/myserver
getcap /usr/bin/myserver

In containers: default Docker drops CAP_SYS_ADMIN, CAP_NET_RAW, etc. Run as non-root with minimal bounding set.

7. User namespace rootless
bash
# Rootless podman/docker maps root in container to unprivileged UID on host
cat /proc/self/uid_map
#          0       1000          1
# container UID 0 → host UID 1000

Rootless limits: cannot mount most filesystems, no CAP_SYS_ADMIN.

8. Escape mitigations
Defense layers
├── User namespace (rootless)
├── seccomp (block dangerous syscalls)
├── AppArmor/SELinux (MAC)
├── Capabilities drop (--cap-drop=ALL)
├── Read-only rootfs
├── no-new-privileges
└── Seccomp + Landlock for filesystem
bash
docker run --read-only --cap-drop=ALL --security-opt=no-new-privileges \
  --security-opt seccomp=default.json myimage

Known escape vectors: mounted docker.sock, privileged mode, kernel CVEs, /proc leaks.

Common Problems

SymptomCauseFix
Container OOMKilledmemory.max exceededRaise limit or fix leak
CPU throttledcpu.max quota lowAdjust cpu.max or weight
Permission denied in containerCapability droppedAdd specific cap or fix app
seccomp kill on startMissing syscall in profilestrace to find; allow syscall
overlay mount failworkdir not emptyClean workdir; check permissions
Rootless mount failUser namespace limitsUse volume mounts from host
  • skills/virtualization/qemu-kvm — VM isolation vs containers
  • skills/security/kernel-security — SELinux, AppArmor, seccomp depth
  • skills/observability/ebpf — trace container syscalls
  • skills/runtimes/binary-hardening — seccomp and capabilities in production
  • skills/kernel/kernel-internals — cgroups and namespaces in kernel
  • skills/profilers/strace-ltrace — syscall tracing for seccomp tuning

© mohitmishra786, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/virtualization/containers-internals of mohitmishra786/low-level-dev-skills.

Open the folder on GitHubat commit bdc5847

Compare with similar skills

Containers Internals next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Containers Internals compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Containers Internals this skillmohitmishra786/low-level-dev-skills252—~1.6kAutomated safety check: NotesMIT
Swig CI Reproswig/swig6.3k—~1.2kAutomated safety check: PassCustom licence
.NET Crash Dump Collectiondotnet/skills5.6k2 repos~1.1kAutomated safety check: PassMIT
Docker Jfr Benchmark Loopeclipse-rdf4j/rdf4j420—~945Automated safety check: PassBSD-3-Clause
Minimegasandia-minimega/minimega160—~3.2kAutomated safety check: PassGPL-3.0-only
Oneclickvirtoneclickvirt/oneclickvirt372—~1.1kAutomated safety check: PassGPL-3.0

Similar skills

  • Swig CI Repro

    swig/swig

    Reproduce a GitHub Actions Linux CI failure locally when it does not happen on your machine: a podman/docker image that mirrors the ubuntu-22.04 runner by reusing the real Tools/CI-linux-.sh install…

    6.3k GitHub stars~1.2k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Docker Jfr Benchmark Loop

    eclipse-rdf4j/rdf4j

    Run a repeatable RDF4J performance loop against one JMH benchmark in Docker with Linux Java 26 and JFR CPU-time profiling.

    420 GitHub stars~945 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Minimega

    sandia-minimega/minimega

    This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…

    160 GitHub stars~3.2k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Oneclickvirt

    oneclickvirt/oneclickvirt

    OneClickVirt operations skill for managing containers, virtual machines, provider nodes, health checks, and metrics through MCP.

    372 GitHub stars~1.1k tokensUpdated 8 days ago
    DevOps & CloudAuto-check passed
  • Devsy

    devsy-org/devsy

    Operate Devsy workspaces and providers for end users. An agent skill from devsy-org/devsy.

    112 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed

More from mohitmishra786/low-level-dev-skills

All 138 skills in this repo
  • ARM and AArch64 Assembly

    mohitmishra786/low-level-dev-skills

    Guides reading and writing AArch64 and ARM Thumb assembly: compiler output, inline asm, registers, the AAPCS calling convention and NEON or SVE basics.

    252 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • RISC-V Assembly Guide

    mohitmishra786/low-level-dev-skills

    Reference for RISC-V assembly on RV32 and RV64: register names and calling convention, extension naming, GCC and Clang inline asm, and QEMU with GDB debugging.

    252 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • x86-64 Assembly Reference

    mohitmishra786/low-level-dev-skills

    Explains x86-64 registers, the System V AMD64 calling convention, and how to read compiler-generated or inline assembly.

    252 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Bazel for C and C++

    mohitmishra786/low-level-dev-skills

    Guides your agent through Bazel for C/C++ projects: BUILD files, Bzlmod dependencies, toolchain registration, remote execution, dependency queries and sandbox debugging.

    252 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Binary Hardening

    mohitmishra786/low-level-dev-skills

    Binary hardening skill for security-hardened C/C++ builds. An agent skill from mohitmishra786/low-level-dev-skills.

    252 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed
  • Binutils

    mohitmishra786/low-level-dev-skills

    GNU binutils skill for binary manipulation and analysis. An agent skill from mohitmishra786/low-level-dev-skills.

    252 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Categories

Questions about Containers Internals

What does Containers Internals do?

Linux containers internals skill for namespaces, cgroups, and OCI. Containers Internals is an agent skill from mohitmishra786/low-level-dev-skills. Linux containers internals skill for namespaces, cgroups, and OCI.

When should I use Containers Internals?

Containers Internals fits situations like: understanding clone/unshare namespaces; cgroups v2 limits; seccomp profiles; escape mitigations.

How do I install Containers Internals in Claude Code?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill containers-internals -a claude-code`. Or copy the skill folder (skills/virtualization/containers-internals in mohitmishra786/low-level-dev-skills) into .claude/skills/containers-internals in your project. Claude Code loads it when a task matches its description.

How do I install Containers Internals in Codex?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill containers-internals -a codex`. Or copy the skill folder (skills/virtualization/containers-internals in mohitmishra786/low-level-dev-skills) into .agents/skills/containers-internals in your project. Codex loads it when a task matches its description.

Can I use Containers Internals in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitmishra786/low-level-dev-skills --skill containers-internals -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/containers-internals, .gemini/skills/containers-internals, .github/skills/containers-internals and .opencode/skills/containers-internals in your project.

What does Containers Internals need to run?

Going by SKILL.md and its folder, Containers Internals needs the command-line tools its instructions call (docker). Our summary lists: Docker.

Does Containers Internals access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Containers Internals safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Containers Internals use?

Containers Internals is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Containers Internals use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Containers Internals?

Skills that share tags, products or a category with Containers Internals: Swig CI Repro (swig/swig, 6.3k stars), .NET Crash Dump Collection (dotnet/skills, 5.6k stars), Docker Jfr Benchmark Loop (eclipse-rdf4j/rdf4j, 420 stars) and Minimega (sandia-minimega/minimega, 160 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Containers Internals?

mohitmishra786 (a GitHub user) maintains it in mohitmishra786/low-level-dev-skills, which has 252 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on June 27, 2026.

Source: mohitmishra786/low-level-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.