Agent skill

Containerized Target Execution

by prime-radiant-inc in prime-radiant-inc/greenfield

Runs untrusted analysis targets inside Docker or Podman containers with memory, CPU and process limits, covering image builds, lifecycle, command execution and cleanup.

Apache-2.0Auto-check passedDevOps & Cloud

Install Containerized Target Execution

skills CLI
$ npx skills add prime-radiant-inc/greenfield --skill container-execution -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install prime-radiant-inc/greenfield container-execution --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/prime-radiant-inc/greenfield.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/container-execution .claude/skills/container-execution && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
container-execution
GitHub stars
292
Token cost
~2.1k tokens
SKILL.md length
305 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs untrusted analysis targets inside Docker or Podman containers with memory, CPU and process limits, covering image builds, lifecycle, command execution and cleanup.

  • Works in 4 steps: Build the Image → Start the Container → Verify Running → …
  • Running an unfamiliar or untrusted codebase for behavioral analysis
  • SKILL.md covers Runtime Detection, Container Naming, Container Lifecycle and Command Execution, plus 6 more sections
  • Calls sh, curl and docker

What it does

This infrastructure skill makes sure that code under analysis in the greenfield pipeline never runs on the host. It detects whether Docker or Podman is available and, if neither is present, treats that as non-fatal and skips the agents that need containers rather than failing. Containers are named deterministically as `greenfield-${WORKSPACE}-target` so the same workspace always maps to the same container and multiple analyses can run side by side without leaking the target's identity.

A Dockerfile at a fixed workspace path is generated per target type, with templates shown for a Node.js CLI or library, a Python project, a compiled binary such as Go, Rust or C, and a web application. The build command logs failures to a build-log file and marks runtime mode unavailable rather than stopping the pipeline. Containers start with memory, CPU and process-count limits, their running state is verified with an inspect command, all interaction goes through `docker exec` or `podman exec`, and cleanup stops and removes the container with a timeout.

When your agent uses it

  • Running an unfamiliar or untrusted codebase for behavioral analysis
  • Building a per-target Docker image based on its detected language
  • Setting resource limits before executing commands inside a target container
  • Cleaning up analysis containers after a run

Example prompts

  • “Set up and start a container for this Python target with memory and CPU limits.”
  • “Docker is not available on this host. Skip the container-based analysis agents.”
  • “Build the runtime image for this Go binary target and verify it started correctly.”

Requirements

  • Docker or Podman

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Build the Image
  2. Start the Container
  3. Verify Running
  4. Cleanup

What it can do on your machine

Read from SKILL.md and the folder at commit 6e6d4b4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • sh
    • curl
    • docker
    • podman

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Containerized Target Execution loads about 2.1k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 305 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from prime-radiant-inc/greenfield at commit 6e6d4b4, republished under its Apache-2.0 licence (© prime-radiant-inc). 305 words, ~2,066 tokens.

Download SKILL.mdSave it as .claude/skills/container-execution/SKILL.md (or your agent's skills folder).
name
container-execution
description
Infrastructure skill for containerized target execution. Runtime detection, container lifecycle, security restrictions, interaction patterns.

Container Execution

All runtime analysis targets run inside containers. Never execute untrusted code on the host.

Runtime Detection

bash
if command -v docker &>/dev/null; then
  RUNTIME="docker"
elif command -v podman &>/dev/null; then
  RUNTIME="podman"
else
  echo "No container runtime found. Runtime observation unavailable."
  # Continue with static analysis modes only
fi

If neither Docker nor Podman is available, skip all agents that require containers. This is not an error — runtime observation is additive.

Container Naming

Container name: greenfield-${WORKSPACE}-target

  • Deterministic (same workspace = same name)
  • Does not leak the target's identity
  • Allows multiple concurrent analyses

Container Lifecycle

dot
digraph container_lifecycle {
    rankdir=TB;

    "Start container lifecycle" [shape=doublecircle];
    "Container runtime available?" [shape=diamond];
    "Build target image" [shape=box];
    "Build succeeded?" [shape=diamond];
    "Start container with resource limits" [shape=box];
    "Verify container is running" [shape=box];
    "Container running?" [shape=diamond];
    "Execute agent commands via docker exec" [shape=box];
    "Stop and remove container" [shape=box];
    "Lifecycle complete" [shape=doublecircle];
    "Skip runtime mode, continue static analysis" [shape=ellipse];
    "Log failure, skip runtime mode" [shape=ellipse];

    "Start container lifecycle" -> "Container runtime available?";
    "Container runtime available?" -> "Build target image" [label="yes"];
    "Container runtime available?" -> "Skip runtime mode, continue static analysis" [label="no"];
    "Build target image" -> "Build succeeded?";
    "Build succeeded?" -> "Start container with resource limits" [label="yes"];
    "Build succeeded?" -> "Log failure, skip runtime mode" [label="no"];
    "Start container with resource limits" -> "Verify container is running";
    "Verify container is running" -> "Container running?";
    "Container running?" -> "Execute agent commands via docker exec" [label="yes"];
    "Container running?" -> "Log failure, skip runtime mode" [label="no"];
    "Execute agent commands via docker exec" -> "Stop and remove container";
    "Stop and remove container" -> "Lifecycle complete";
}
1. Build the Image

The Dockerfile is at workspace/raw/runtime/Dockerfile. It is generated based on target type:

Node.js CLI/Library:

dockerfile
FROM node:lts-slim
WORKDIR /app
COPY target/ /app/
RUN npm install --production 2>/dev/null || true
RUN npm link 2>/dev/null || true
RUN mkdir -p /output
ENTRYPOINT ["sleep", "infinity"]

Python:

dockerfile
FROM python:3.12-slim
WORKDIR /app
COPY target/ /app/
RUN pip install --no-cache-dir -r requirements.txt 2>/dev/null || true
RUN pip install --no-cache-dir -e . 2>/dev/null || true
RUN mkdir -p /output
ENTRYPOINT ["sleep", "infinity"]

Compiled Binary (Go, Rust, C):

dockerfile
FROM ubuntu:22.04
RUN apt-get update && apt-get install -y --no-install-recommends \
    ca-certificates file strace && rm -rf /var/lib/apt/lists/*
COPY target/binary /usr/local/bin/target
RUN chmod +x /usr/local/bin/target
RUN mkdir -p /output
ENTRYPOINT ["sleep", "infinity"]

Web Application:

dockerfile
FROM node:lts-slim
WORKDIR /app
COPY target/ /app/
RUN npm install --production 2>/dev/null || true
RUN mkdir -p /output
EXPOSE 3000
CMD ["npm", "start"]

Build command:

bash
$RUNTIME build -t greenfield-${WORKSPACE}-target \
  -f workspace/raw/runtime/Dockerfile .

If the build fails, log the error to workspace/raw/runtime/build-log.txt and mark runtime mode as unavailable. The pipeline continues with other modes.

2. Start the Container

CLI/Library targets:

bash
$RUNTIME run -d \
  --name greenfield-${WORKSPACE}-target \
  --memory=2g --cpus=2 --pids-limit=256 \
  --network=none --read-only \
  --tmpfs /tmp:rw,noexec,nosuid,size=256m \
  -v "$(pwd)/workspace/raw/runtime:/output:rw" \
  greenfield-${WORKSPACE}-target

Web application targets:

bash
$RUNTIME run -d \
  --name greenfield-${WORKSPACE}-target \
  --memory=2g --cpus=2 --pids-limit=256 \
  --network=none \
  -p 127.0.0.1:3000:3000 \
  -v "$(pwd)/workspace/raw/runtime:/output:rw" \
  greenfield-${WORKSPACE}-target
3. Verify Running
bash
$RUNTIME inspect --format='{{.State.Running}}' greenfield-${WORKSPACE}-target
# Expected: true
4. Cleanup
bash
$RUNTIME stop --time=10 greenfield-${WORKSPACE}-target 2>/dev/null || true
$RUNTIME rm greenfield-${WORKSPACE}-target 2>/dev/null || true

Command Execution

All target interaction goes through docker exec (or podman exec).

Basic Command
bash
timeout 30 $RUNTIME exec greenfield-${WORKSPACE}-target \
  sh -c 'command args 2>&1' \
  > workspace/raw/runtime/cli/output.txt
With Timeout Handling
bash
timeout 30 $RUNTIME exec greenfield-${WORKSPACE}-target \
  sh -c 'command args 2>&1' > output.txt 2>&1

EXIT_CODE=$?
if [ $EXIT_CODE -eq 124 ]; then
  echo "TIMEOUT: Command killed after 30 seconds." >> output.txt
fi
With Environment Variables
bash
$RUNTIME exec -e "DEBUG=true" -e "CONFIG_PATH=/app/config.json" \
  greenfield-${WORKSPACE}-target sh -c 'target-command 2>&1'
With Piped Input
bash
echo "user input here" | \
  timeout 30 $RUNTIME exec -i greenfield-${WORKSPACE}-target \
  sh -c 'target-command' > output.txt 2>&1

Pre-Execution Checklist

Before executing commands, verify:

  1. Container is running: $RUNTIME inspect --format='{{.State.Running}}' greenfield-${WORKSPACE}-target
  2. Output directory is mounted: $RUNTIME exec greenfield-${WORKSPACE}-target test -d /output

Exploration Patterns

CLI Exploration
bash
# Help and version discovery
timeout 30 $RUNTIME exec $CONTAINER sh -c 'target --help 2>&1' > cli/help.txt
timeout 30 $RUNTIME exec $CONTAINER sh -c 'target --version 2>&1' > cli/version.txt

# Subcommand enumeration: parse help output, try each subcommand
# Error exploration: invalid flags, missing args, bad input
# Config discovery: env vars, config files, default paths
Web Endpoint Discovery
bash
# Probe root and common API paths
curl -s -D- http://127.0.0.1:3000/ > web/root-response.txt

for endpoint in /api /health /swagger.json /openapi.json; do
  STATUS=$(curl -s -o /dev/null -w '%{http_code}' "http://127.0.0.1:3000${endpoint}")
  echo "${endpoint} -> ${STATUS}" >> web/endpoint-scan.txt
done

File Extraction

bash
# Copy a file from the container
$RUNTIME cp greenfield-${WORKSPACE}-target:/path/to/file \
  workspace/raw/runtime/extracted/

# List files inside the container
$RUNTIME exec greenfield-${WORKSPACE}-target find /app -type f -name '*.log' 2>/dev/null

Error Handling

Build failure: Log to build-log.txt, skip runtime mode, continue with static analysis.

Command timeout (exit 124): Capture partial output, note timeout, move to next command.

Container crash/OOM:

bash
if [ "$($RUNTIME inspect --format='{{.State.Running}}' $CONTAINER 2>/dev/null)" != "true" ]; then
  $RUNTIME logs $CONTAINER > crash-log.txt 2>&1
  $RUNTIME start $CONTAINER  # Attempt restart
fi

Container errors are behavioral observations — document them as data, not just failures.

Resource Limits

ResourceDefaultNotes
Memory2 GB--memory=2g
CPU2 cores--cpus=2
Command timeout30 secondstimeout 30 on docker exec
PID limit256--pids-limit=256
NetworkNone--network=none (default)
GPUNeverNot granted
PrivilegedNeverNot granted

Security Restrictions (Non-Negotiable)

  • Never use --privileged
  • Never mount host paths outside workspace/raw/runtime/
  • Never bind ports to 0.0.0.0 (always 127.0.0.1)
  • Never grant GPU access
  • Never disable seccomp/AppArmor
  • All captured output goes to workspace/raw/runtime/
  • Avoid including raw credential values in captured output (use judgment, not regex)

© prime-radiant-inc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/container-execution of prime-radiant-inc/greenfield.

Open the folder on GitHubat commit 6e6d4b4

Compare with similar skills

Containerized Target Execution next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Containerized Target Execution compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Containerized Target Execution this skillprime-radiant-inc/greenfield292—~2.1kAutomated safety check: PassApache-2.0
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.0
Container Sbomcdxgen/cdxgen1.1k—~1.5kAutomated safety check: PassApache-2.0
CI/CD Pipeline Principlesirahardianto/awesome-agv157—~2.7kAutomated safety check: NotesMIT
Detecting Container Escape Attemptsmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Container Sbom

    cdxgen/cdxgen

    Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    157 GitHub stars~2.7k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Detecting Container Escape Attempts

    mukul975/Anthropic-Cybersecurity-Skills

    Detects container escape at runtime across tooling - namespace manipulation, capability abuse, kernel exploits, sensitive host mounts, and anomalous syscalls - and explains which signals matter…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Container Image Minimal Base With Distroless

    mukul975/Anthropic-Cybersecurity-Skills

    Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from prime-radiant-inc/greenfield

All 21 skills in this repo
  • Reverse Engineering Analysis Pipeline

    prime-radiant-inc/greenfield

    Master methodology for reverse-engineering a codebase into behavioral specs with cited evidence, reading every line across source, binaries, docs, runtime and git history.

    292 GitHub stars~3.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Community Intelligence Research

    prime-radiant-inc/greenfield

    Mines tutorials, forums, reviews, issues and changelogs for observed product behavior, using six search channels and consensus analysis.

    292 GitHub stars~4.5k tokensUpdated 2 mo ago
    Auto-check passed
  • API Contract Detection

    prime-radiant-inc/greenfield

    Finds OpenAPI, GraphQL, Protobuf and JSON Schema files in a codebase and extracts behavioral claims from them as part of a reverse-engineering workflow.

    292 GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Documentation Research Methodology

    prime-radiant-inc/greenfield

    Method for extracting behavioral specifications from a product's public documentation: tiered search order, claim extraction rules, output structure, stop criteria and gap analysis.

    292 GitHub stars~4.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Ecosystem Analysis

    prime-radiant-inc/greenfield

    Layer 1 skill for SDK and ecosystem analysis. An agent skill from prime-radiant-inc/greenfield.

    292 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Fidelity Validation

    prime-radiant-inc/greenfield

    Cross-validates sanitized output specs against raw source specs to detect lost behavioral detail, dropped constants, missing features, or diluted precision.

    292 GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about Containerized Target Execution

What does Containerized Target Execution do?

Runs untrusted analysis targets inside Docker or Podman containers with memory, CPU and process limits, covering image builds, lifecycle, command execution and cleanup. This infrastructure skill makes sure that code under analysis in the greenfield pipeline never runs on the host. It detects whether Docker or Podman is available and, if neither is present, treats that as non-fatal and skips the agents that need containers rather than failing.

When should I use Containerized Target Execution?

Containerized Target Execution fits situations like: running an unfamiliar or untrusted codebase for behavioral analysis; building a per-target Docker image based on its detected language; setting resource limits before executing commands inside a target container; cleaning up analysis containers after a run.

How do I install Containerized Target Execution in Claude Code?

Run `npx skills add prime-radiant-inc/greenfield --skill container-execution -a claude-code`. Or copy the skill folder (skills/container-execution in prime-radiant-inc/greenfield) into .claude/skills/container-execution in your project. Claude Code loads it when a task matches its description.

How do I install Containerized Target Execution in Codex?

Run `npx skills add prime-radiant-inc/greenfield --skill container-execution -a codex`. Or copy the skill folder (skills/container-execution in prime-radiant-inc/greenfield) into .agents/skills/container-execution in your project. Codex loads it when a task matches its description.

Can I use Containerized Target Execution in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add prime-radiant-inc/greenfield --skill container-execution -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/container-execution, .gemini/skills/container-execution, .github/skills/container-execution and .opencode/skills/container-execution in your project.

What does Containerized Target Execution need to run?

Going by SKILL.md and its folder, Containerized Target Execution needs the command-line tools its instructions call (sh, curl, docker and podman). Our summary lists: Docker or Podman.

Does Containerized Target Execution access the network?

SKILL.md contains no URLs. Its commands use curl and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Containerized Target Execution safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Containerized Target Execution use?

Containerized Target Execution is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Containerized Target Execution use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Containerized Target Execution?

Skills that share tags, products or a category with Containerized Target Execution: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars), Container Sbom (cdxgen/cdxgen, 1.1k stars) and CI/CD Pipeline Principles (irahardianto/awesome-agv, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Containerized Target Execution?

prime-radiant-inc (a GitHub organization) maintains it in prime-radiant-inc/greenfield, which has 292 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on August 6, 2026.

Source: prime-radiant-inc/greenfield on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.