Official agent skill

Setting Up Devbox

by PostHog in PostHog/posthog-foss

Starts, connects to, and troubleshoots a PostHog devbox, a remote Coder workspace for PostHog development that can also run the full stack, through hogli devbox: commands.

OfficialMITAuto-check: notes

Install Setting Up Devbox

skills CLI
$ npx skills add PostHog/posthog-foss --skill setting-up-devbox -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PostHog/posthog-foss setting-up-devbox --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/setting-up-devbox .claude/skills/setting-up-devbox && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
setting-up-devbox
GitHub stars
721
Token cost
~2.6k tokens
SKILL.md length
1,304 words
Files
3 (incl. references)
Skills in repo
213
Repo updated
First seen
Licence
MIT

At a glance

Starts, connects to, and troubleshoots a PostHog devbox, a remote Coder workspace for PostHog development that can also run the full stack, through hogli devbox: commands.

  • Works in 5 steps: Check access → Set up this machine once → Start the box → …
  • Asked to spin up
  • SKILL.md covers Get a box, Run commands on the box, Run the PostHog app and Other tasks, plus 1 more section
  • Calls git, jq and bash; reaches app--devbox-jane-d--jane-d.coder.dev.posthog.dev; needs GH_TOKEN and CLAUDE_CODE_OAUTH_TOKEN

What it does

Setting Up Devbox is an agent skill from PostHog/posthog-foss, published by the product's own GitHub organization. Starts, connects to, and troubleshoots a PostHog devbox, a remote Coder workspace for PostHog development that can also run the full stack, through hogli devbox: commands. Use when asked to spin up or resume a devbox, open a shell or editor on it, run a command on it, mirror a local checkout to it (devbox:sync), run the PostHog app on it and share a link, clone, update, share, or free disk on a devbox, store gh or Claude Code tokens for it, or diagnose a failing devbox command (tailnet, DNS, Coder CLI version…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/access-troubleshooting.md` and `references/sync.md`).

It works with PostHog. The repository describes itself as: PostHog FOSS is a read-only mirror of PostHog, with all proprietary code removed. NOTE: This repo is synced automatically from the main PostHog repo. Please raise any issues and… The licence is MIT.

When your agent uses it

  • Asked to spin up
  • Resume a devbox
  • Run a command on it
  • Mirror a local checkout to it (devbox:sync)

Example prompts

  • “/setting-up-devbox”

Requirements

  • Docker
  • A credential in CLAUDE_CODE_OAUTH_TOKEN
  • A credential in OP_SERVICE_ACCOUNT_TOKEN

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Check access
  2. Set up this machine once
  3. Start the box
  4. Connect
  5. Stop when done

What it can do on your machine

Read from SKILL.md and the folder at commit 2c48221. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • jq
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • app--devbox-jane-d--jane-d.coder.dev.posthog.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GH_TOKEN
    • CLAUDE_CODE_OAUTH_TOKEN
    • OP_SERVICE_ACCOUNT_TOKEN
    • ANTHROPIC_API_KEY
    • OPENAI_API_KEY
    • POSTHOG_GIT_SIGNING_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Setting Up Devbox loads about 2.6k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 162 tokens; SKILL.md has 1,304 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~162
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:47
    n Linux, the reachability check can run `sudo tailscale set --accept-routes` and prompt for a password.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PostHog/posthog-foss at commit 2c48221, republished under its MIT licence (© PostHog). 1,304 words, ~2,553 tokens.

Download SKILL.mdSave it as .claude/skills/setting-up-devbox/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
setting-up-devbox
description
Starts, connects to, and troubleshoots a PostHog devbox, a remote Coder workspace for PostHog development that can also run the full stack, through `hogli devbox:*` commands. Use when asked to spin up or resume a devbox, open a shell or editor on it, run a command on it, mirror a local checkout to it (devbox:sync), run the PostHog app on it and share a link, clone, update, share, or free disk on a devbox, store gh or Claude Code tokens for it, or diagnose a failing devbox command (tailnet, DNS, Coder CLI version, SSH). Not for running the stack on the local machine or for changing the Coder template in posthog-cloud-infra.

Setting up a PostHog devbox

A devbox is a Coder workspace on EC2 for PostHog development. Drive it through hogli devbox:* and don't reimplement what those commands do. A new box has the repo at ~/posthog on master, prewarmed dependencies, and Claude Code installed. hogli devbox:<command> --help has the current flags. This skill covers the order of operations and what the help text leaves out.

People use a box in different ways: a shell or editor for general development, a remote target for a local checkout, or a host for the running PostHog app. Work out which one the user wants, and don't start the PostHog stack unless they ask for the app.

Get a box

Copy this checklist and track it:

text
- [ ] 1. hogli devbox:doctor: the tailnet and control plane checks are ok
- [ ] 2. hogli devbox:setup has run on this machine
- [ ] 3. hogli devbox:start: the box is running
- [ ] 4. The user is connected the way they asked for
- [ ] 5. hogli devbox:stop when the user is done
1. Check access

hogli devbox:doctor is read-only: it never prompts or changes host config. Commands that reach a box run the same reachability check first, so fix a failure here before anything else.

  • The active tailnet must be posthog.com. Doctor prints it and names a wrong tailnet as the cause.
  • Every PostHog employee has the route to the Coder control plane through group:employees in the tailnet policy. Nobody needs a PR to get access.
  • If doctor reports the control plane unreachable, read references/access-troubleshooting.md before changing anything.
  • [missing] Commit signing agent does not block starting or using a box. It matters only for signed commits made on the box.
2. Set up this machine once

hogli devbox:setup is interactive, so ask the user to run it in their own terminal. It installs the Coder CLI at the server's version into ~/.hogli/bin, logs in, installs the pinned mutagen binary for devbox:sync, and writes the coder.* SSH host entries that devbox:ssh and devbox:exec use. ~/.hogli/bin is not on PATH, so call that CLI as ~/.hogli/bin/coder when a step needs coder directly. Each optional step has a --configure-<step> and --skip-configure-<step> flag: ssh, git-identity, git-signing, region, dotfiles, claude. Run it again when a command prints Coder CLI vX does not match server vY, because it reinstalls the matching CLI.

On Linux, the reachability check can run sudo tailscale set --accept-routes and prompt for a password. Run setup interactively once before an agent drives devbox commands unattended.

3. Start the box
bash
hogli devbox:start

This creates the box on first use and resumes it after a stop. It brings up the PostHog stack only when the workspace has --start-app set, which is covered in Run the PostHog app. --disk (100 or 200 GiB) applies only when the box is created. --region (us-east-1 or eu-central-1) starts that region's default box and creates it if it doesn't exist, so leave it off when resuming an existing box. A box's region can't change.

The default box is devbox-<coder-user>, and a labeled box is devbox-<coder-user>-<label>. Boxes in eu-central-1 add an -eu suffix, for example devbox-<coder-user>-eu. hogli devbox:list shows the exact names. Target a labeled box with -n <label> on commands that act on a box.

4. Connect

Match what the user asked for:

5. Stop when done

hogli devbox:stop keeps the disk and stops billing. Stops, starts, and devbox:update keep /home. hogli devbox:destroy deletes it, so don't keep anything irreplaceable only on a box.

Run commands on the box

hogli devbox:exec -- <command> runs one command over SSH and returns its exit code. Wrap the command in bash -lc '...'. A non-login shell doesn't reliably load the shell profile, so tools on a login-shell PATH such as ~/.local/bin report "command not found". Put -- between hogli's flags and the command's own. devbox:exec and devbox:ssh fail to connect until devbox:setup has written the SSH config.

Run the PostHog app

Use this section only when the user wants the app, for example to QA a change or share a link.

Start the stack
  • New or stopped box: hogli devbox:start --start-app. The flag stays set on the workspace, so every later start brings the stack up in the background until hogli devbox:start --no-start-app turns it off. Either flag takes effect only when the box is created or starts from stopped; on a running box hogli skips it and prints a note.
  • Running box: hogli devbox:exec -- bash -lc 'cd ~/posthog && ./bin/hogli up -d -y'.
Wait for it

The stack keeps booting after the start command returns. Poll in a bounded loop until this prints 200 or 302. A 000 or 502 means the stack is still booting.

bash
hogli devbox:exec -- bash -lc "curl -s -o /dev/null -w '%{http_code}' --max-time 10 http://127.0.0.1:8010/"

When resuming QA on an existing box, check it before recreating sync, restarting the stack, or making a new box:

bash
hogli devbox:status
hogli devbox:exec -- bash -lc 'cd ~/posthog && git status --short --branch && git rev-parse --short HEAD'
hogli devbox:sync --json

Keep going when the app serves the intended branch and SHA, the target route loads, and its APIs work. Note unrelated degraded processes instead of chasing full health.

Show full SKILL.md (494 more words)Show less
Give the user the URL

The template exposes the app as a Coder subdomain app that only the box owner can open:

text
https://app--<workspace>--<coder-user>.<coder-host>

<coder-host> is the host of Coder URL in hogli devbox:doctor, and hogli devbox:list shows the workspace name. For example, devbox-jane-d owned by jane-d on coder.dev.posthog.dev is https://app--devbox-jane-d--jane-d.coder.dev.posthog.dev. The user must be on the tailnet, and the browser goes through Coder sign-in first.

Verify the link before handing it over. Coder runs the template's health check against the app, so read that status instead of sending a request with the user's session token:

bash
~/.hogli/bin/coder list --output json | jq -r '.[] | select(.name=="<workspace>") | .latest_build.resources[]?.agents[]?.apps[]? | select(.slug=="app") | .health'

healthy means Coder routes the URL to a working app. initializing means the check hasn't passed yet, and unhealthy means it keeps failing.

hogli devbox:forward is the alternative when the user wants localhost. It tunnels box port 8010 to localhost:8010 and holds the terminal until stopped. Pass --port 8011 when a local stack already uses 8010.

Other tasks

  • Tokens on the box: store them as Coder user secrets, which reach every box the user owns. hogli devbox:secret:set GH_TOKEN reads the value from a hidden prompt or from --file. Never put a token on a command line or in the conversation. A secret reaches only boxes started after it is set, so run hogli devbox:restart on a running box. The template documents CLAUDE_CODE_OAUTH_TOKEN, GH_TOKEN, OP_SERVICE_ACCOUNT_TOKEN, ANTHROPIC_API_KEY, OPENAI_API_KEY, and POSTHOG_GIT_SIGNING_KEY, which hogli devbox:setup --configure-git-signing sets. devbox:secret:list shows names, env vars, and descriptions, never values.
  • A second box with the same state: hogli devbox:clone --as <label> copies a running box's full disk, including any secrets on it, into devbox-<coder-user>-<label> in the source box's region. Stop the stack on the source first for a consistent copy. It asks for confirmation, so pass -y only after the user agrees. Only the owner can clone a box.
  • Template updates: hogli devbox:update applies the latest template when the box is outdated.
  • Disk full: hogli devbox:cleanup:disk -n <label> cleans a labeled box. With no workspace it cleans this machine instead, and the default box has no label, so clean the default box with hogli devbox:exec -- bash -lc 'cd ~/posthog && ./bin/hogli devbox:cleanup:disk'. --docker also prunes stopped containers, and --cargo also removes Rust build output, which forces a full rebuild.
  • Pairing: hogli devbox:share --user <coder-user> --role use grants access, and devbox:users lists usernames. devbox:unshare removes access only after hogli devbox:restart.
  • Build and agent logs: hogli devbox:logs -f.
  • Personal setup: the box works as shipped. Changes made on the box survive stops and updates. hogli devbox:setup --configure-dotfiles saves a dotfiles repo that the box applies on start, running its executable install.sh. A new repo URL reaches a box when it next starts from stopped or runs devbox:update, not on devbox:restart. Neither is required, so don't push one over the other.

Gotchas

  • Never echo a secret value into the transcript, logs, a PR, or a command line.
  • code-server (devbox:open --web) has no SSH agent forwarding, so commit signing fails there. Use VS Code Desktop, Cursor, or JetBrains over SSH to sign commits.

© PostHog, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .agents/skills/setting-up-devbox of PostHog/posthog-foss.

  • SKILL.md
  • references/access-troubleshooting.md
  • references/sync.md

Open the folder on GitHubat commit 2c48221

Compare with similar skills

Setting Up Devbox next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Setting Up Devbox compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Setting Up Devbox this skillPostHog/posthog-foss721—~2.6kAutomated safety check: NotesMIT
Opik Analytics Instrumentationcomet-ml/opik22k—~4.4kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Define Feature Flagmacro-inc/macro4.6k—~780Automated safety check: PassAGPL-3.0
Soku CLIAbout-Intelligence/soku-cli304—~2.4kAutomated safety check: PassMIT
Compare Array Bundle SizePostHog/posthog-js613—~599Automated safety check: PassCustom licence

Similar skills

  • Shows how to add product analytics events to Opik's frontend, Java backend and Python SDK, all reporting through Segment to PostHog with an opik_ name prefix.

    22k GitHub stars~4.4k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Define Feature Flag

    macro-inc/macro

    Define a frontend feature flag with defineFlag and wire its readers.

    4.6k GitHub stars~780 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Soku CLI

    About-Intelligence/soku-cli

    Guides an agent through the soku command line tool for ads, GA4 and PostHog data reads, ads writes, SEO hosting, automations, files and skill management.

    304 GitHub stars~2.4k tokensUpdated 2 days ago
    Marketing & SEOAuto-check passed
  • Compare Array Bundle Size

    PostHog/posthog-js

    Official

    Quickly compare the posthog-js array.js bundle size in the current working tree against a git baseline using the repository's esbuild proxy.

    613 GitHub stars~599 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Telemetry Analytics

    OpenHands/OpenHands

    This skill should be used when the user asks to "add tracking", "add a PostHog event", "change telemetry consent", "instrument onboarding", "debug analytics", or changes telemetry.ts…

    90k GitHub stars~305 tokensUpdated today
    DevOps & CloudAuto-check passed

More from PostHog/posthog-foss

All 213 skills in this repo
  • Authoring Log Alerts

    PostHog/posthog-foss

    Official

    Author useful, low-noise log alerts on services in a PostHog project.

    721 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Autoresolving PR Conflicts

    PostHog/posthog-foss

    Official

    Operating procedure for the conflict-autoresolver agent: sweep open PostHog/posthog PRs that conflict with master, resolve the trivial conflicts (generated artifacts deterministically, source…

    721 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Help users debug PostHog Error Tracking stack-trace symbolication for any supported platform — JavaScript/TypeScript web, React Native (Hermes), Android (Proguard / R8), or iOS / macOS (dSYM).

    721 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Exploring Apm Traces

    PostHog/posthog-foss

    Official

    Investigates distributed application performance using PostHog APM (OpenTelemetry span) data via MCP.

    721 GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Exploring LLM Traces

    PostHog/posthog-foss

    Official

    Debug and inspect LLM/AI agent traces using PostHog's MCP tools.

    721 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Investigate Metric

    PostHog/posthog-foss

    Official

    Diagnose why a product metric changed (dropped, spiked, or plateaued) by orchestrating breakdowns, actors, paths, lifecycle, retention, and annotations queries.

    721 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Questions about Setting Up Devbox

What does Setting Up Devbox do?

Starts, connects to, and troubleshoots a PostHog devbox, a remote Coder workspace for PostHog development that can also run the full stack, through hogli devbox: commands. Setting Up Devbox is an agent skill from PostHog/posthog-foss, published by the product's own GitHub organization. Starts, connects to, and troubleshoots a PostHog devbox, a remote Coder workspace for PostHog development that can also run the full stack, through hogli devbox: commands.

When should I use Setting Up Devbox?

Setting Up Devbox fits situations like: asked to spin up; resume a devbox; run a command on it; mirror a local checkout to it (devbox:sync).

How do I install Setting Up Devbox in Claude Code?

Run `npx skills add PostHog/posthog-foss --skill setting-up-devbox -a claude-code`. Or copy the skill folder (.agents/skills/setting-up-devbox in PostHog/posthog-foss) into .claude/skills/setting-up-devbox in your project. Claude Code loads it when a task matches its description.

How do I install Setting Up Devbox in Codex?

Run `npx skills add PostHog/posthog-foss --skill setting-up-devbox -a codex`. Or copy the skill folder (.agents/skills/setting-up-devbox in PostHog/posthog-foss) into .agents/skills/setting-up-devbox in your project. Codex loads it when a task matches its description.

Can I use Setting Up Devbox in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PostHog/posthog-foss --skill setting-up-devbox -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/setting-up-devbox, .gemini/skills/setting-up-devbox, .github/skills/setting-up-devbox and .opencode/skills/setting-up-devbox in your project.

What does Setting Up Devbox need to run?

Going by SKILL.md and its folder, Setting Up Devbox needs the command-line tools its instructions call (git, jq and bash) and credentials named GH_TOKEN, CLAUDE_CODE_OAUTH_TOKEN, OP_SERVICE_ACCOUNT_TOKEN and ANTHROPIC_API_KEY. Our summary lists: Docker; A credential in CLAUDE_CODE_OAUTH_TOKEN; A credential in OP_SERVICE_ACCOUNT_TOKEN.

Does Setting Up Devbox access the network?

SKILL.md names 1 domain. In commands or code: app--devbox-jane-d--jane-d.coder.dev.posthog.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Setting Up Devbox safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Setting Up Devbox use?

Setting Up Devbox is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Setting Up Devbox use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Setting Up Devbox?

Skills that share tags, products or a category with Setting Up Devbox: Opik Analytics Instrumentation (comet-ml/opik, 22k stars), C15t (c15t/c15t, 1.9k stars), Define Feature Flag (macro-inc/macro, 4.6k stars) and Soku CLI (About-Intelligence/soku-cli, 304 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Setting Up Devbox?

PostHog (a GitHub organization, an official publisher) maintains it in PostHog/posthog-foss, which has 721 GitHub stars. The repository holds 213 skills in this directory. The repository was last updated on October 7, 2026.

Source: PostHog/posthog-foss on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.