Iron Proxy Gateway for NanoClaw
nanocoai/nanoclaw
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
Runs untrusted analysis targets inside Docker or Podman containers with memory, CPU and process limits, covering image builds, lifecycle, command execution and cleanup.
$ npx skills add prime-radiant-inc/greenfield --skill container-execution -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install prime-radiant-inc/greenfield container-execution --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/prime-radiant-inc/greenfield.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/container-execution .claude/skills/container-execution && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "container-execution" agent skill from https://github.com/prime-radiant-inc/greenfield/tree/main/skills/container-execution into .claude/skills/container-execution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "container-execution", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/prime-radiant-inc/greenfield/tree/main/skills/container-executionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add prime-radiant-inc/greenfield --skill container-execution -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install prime-radiant-inc/greenfield container-execution --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/prime-radiant-inc/greenfield.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/container-execution .agents/skills/container-execution && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "container-execution" agent skill from https://github.com/prime-radiant-inc/greenfield/tree/main/skills/container-execution into .agents/skills/container-execution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "container-execution", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add prime-radiant-inc/greenfield --skill container-execution -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install prime-radiant-inc/greenfield container-execution --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/prime-radiant-inc/greenfield.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/container-execution .cursor/skills/container-execution && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "container-execution" agent skill from https://github.com/prime-radiant-inc/greenfield/tree/main/skills/container-execution into .cursor/skills/container-execution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "container-execution", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/prime-radiant-inc/greenfield.git --path skills/container-execution--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add prime-radiant-inc/greenfield --skill container-execution -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install prime-radiant-inc/greenfield container-execution --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/prime-radiant-inc/greenfield.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/container-execution .gemini/skills/container-execution && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "container-execution" agent skill from https://github.com/prime-radiant-inc/greenfield/tree/main/skills/container-execution into .gemini/skills/container-execution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "container-execution", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install prime-radiant-inc/greenfield container-executionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add prime-radiant-inc/greenfield --skill container-execution -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/prime-radiant-inc/greenfield.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/container-execution .github/skills/container-execution && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "container-execution" agent skill from https://github.com/prime-radiant-inc/greenfield/tree/main/skills/container-execution into .github/skills/container-execution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "container-execution", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add prime-radiant-inc/greenfield --skill container-execution -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install prime-radiant-inc/greenfield container-execution --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/prime-radiant-inc/greenfield.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/container-execution .opencode/skills/container-execution && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "container-execution" agent skill from https://github.com/prime-radiant-inc/greenfield/tree/main/skills/container-execution into .opencode/skills/container-execution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "container-execution", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
container-executionRuns untrusted analysis targets inside Docker or Podman containers with memory, CPU and process limits, covering image builds, lifecycle, command execution and cleanup.
This infrastructure skill makes sure that code under analysis in the greenfield pipeline never runs on the host. It detects whether Docker or Podman is available and, if neither is present, treats that as non-fatal and skips the agents that need containers rather than failing. Containers are named deterministically as `greenfield-${WORKSPACE}-target` so the same workspace always maps to the same container and multiple analyses can run side by side without leaking the target's identity.
A Dockerfile at a fixed workspace path is generated per target type, with templates shown for a Node.js CLI or library, a Python project, a compiled binary such as Go, Rust or C, and a web application. The build command logs failures to a build-log file and marks runtime mode unavailable rather than stopping the pipeline. Containers start with memory, CPU and process-count limits, their running state is verified with an inspect command, all interaction goes through `docker exec` or `podman exec`, and cleanup stops and removes the container with a timeout.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6e6d4b4. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
shcurldockerpodmanFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl and docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Containerized Target Execution loads about 2.1k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 305 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from prime-radiant-inc/greenfield at commit 6e6d4b4, republished under its Apache-2.0 licence (© prime-radiant-inc). 305 words, ~2,066 tokens.
.claude/skills/container-execution/SKILL.md (or your agent's skills folder).All runtime analysis targets run inside containers. Never execute untrusted code on the host.
if command -v docker &>/dev/null; then
RUNTIME="docker"
elif command -v podman &>/dev/null; then
RUNTIME="podman"
else
echo "No container runtime found. Runtime observation unavailable."
# Continue with static analysis modes only
fiIf neither Docker nor Podman is available, skip all agents that require containers. This is not an error — runtime observation is additive.
Container name: greenfield-${WORKSPACE}-target
digraph container_lifecycle {
rankdir=TB;
"Start container lifecycle" [shape=doublecircle];
"Container runtime available?" [shape=diamond];
"Build target image" [shape=box];
"Build succeeded?" [shape=diamond];
"Start container with resource limits" [shape=box];
"Verify container is running" [shape=box];
"Container running?" [shape=diamond];
"Execute agent commands via docker exec" [shape=box];
"Stop and remove container" [shape=box];
"Lifecycle complete" [shape=doublecircle];
"Skip runtime mode, continue static analysis" [shape=ellipse];
"Log failure, skip runtime mode" [shape=ellipse];
"Start container lifecycle" -> "Container runtime available?";
"Container runtime available?" -> "Build target image" [label="yes"];
"Container runtime available?" -> "Skip runtime mode, continue static analysis" [label="no"];
"Build target image" -> "Build succeeded?";
"Build succeeded?" -> "Start container with resource limits" [label="yes"];
"Build succeeded?" -> "Log failure, skip runtime mode" [label="no"];
"Start container with resource limits" -> "Verify container is running";
"Verify container is running" -> "Container running?";
"Container running?" -> "Execute agent commands via docker exec" [label="yes"];
"Container running?" -> "Log failure, skip runtime mode" [label="no"];
"Execute agent commands via docker exec" -> "Stop and remove container";
"Stop and remove container" -> "Lifecycle complete";
}The Dockerfile is at workspace/raw/runtime/Dockerfile. It is generated based on target type:
Node.js CLI/Library:
FROM node:lts-slim
WORKDIR /app
COPY target/ /app/
RUN npm install --production 2>/dev/null || true
RUN npm link 2>/dev/null || true
RUN mkdir -p /output
ENTRYPOINT ["sleep", "infinity"]Python:
FROM python:3.12-slim
WORKDIR /app
COPY target/ /app/
RUN pip install --no-cache-dir -r requirements.txt 2>/dev/null || true
RUN pip install --no-cache-dir -e . 2>/dev/null || true
RUN mkdir -p /output
ENTRYPOINT ["sleep", "infinity"]Compiled Binary (Go, Rust, C):
FROM ubuntu:22.04
RUN apt-get update && apt-get install -y --no-install-recommends \
ca-certificates file strace && rm -rf /var/lib/apt/lists/*
COPY target/binary /usr/local/bin/target
RUN chmod +x /usr/local/bin/target
RUN mkdir -p /output
ENTRYPOINT ["sleep", "infinity"]Web Application:
FROM node:lts-slim
WORKDIR /app
COPY target/ /app/
RUN npm install --production 2>/dev/null || true
RUN mkdir -p /output
EXPOSE 3000
CMD ["npm", "start"]Build command:
$RUNTIME build -t greenfield-${WORKSPACE}-target \
-f workspace/raw/runtime/Dockerfile .If the build fails, log the error to workspace/raw/runtime/build-log.txt and mark runtime mode as unavailable. The pipeline continues with other modes.
CLI/Library targets:
$RUNTIME run -d \
--name greenfield-${WORKSPACE}-target \
--memory=2g --cpus=2 --pids-limit=256 \
--network=none --read-only \
--tmpfs /tmp:rw,noexec,nosuid,size=256m \
-v "$(pwd)/workspace/raw/runtime:/output:rw" \
greenfield-${WORKSPACE}-targetWeb application targets:
$RUNTIME run -d \
--name greenfield-${WORKSPACE}-target \
--memory=2g --cpus=2 --pids-limit=256 \
--network=none \
-p 127.0.0.1:3000:3000 \
-v "$(pwd)/workspace/raw/runtime:/output:rw" \
greenfield-${WORKSPACE}-target$RUNTIME inspect --format='{{.State.Running}}' greenfield-${WORKSPACE}-target
# Expected: true$RUNTIME stop --time=10 greenfield-${WORKSPACE}-target 2>/dev/null || true
$RUNTIME rm greenfield-${WORKSPACE}-target 2>/dev/null || trueAll target interaction goes through docker exec (or podman exec).
timeout 30 $RUNTIME exec greenfield-${WORKSPACE}-target \
sh -c 'command args 2>&1' \
> workspace/raw/runtime/cli/output.txttimeout 30 $RUNTIME exec greenfield-${WORKSPACE}-target \
sh -c 'command args 2>&1' > output.txt 2>&1
EXIT_CODE=$?
if [ $EXIT_CODE -eq 124 ]; then
echo "TIMEOUT: Command killed after 30 seconds." >> output.txt
fi$RUNTIME exec -e "DEBUG=true" -e "CONFIG_PATH=/app/config.json" \
greenfield-${WORKSPACE}-target sh -c 'target-command 2>&1'echo "user input here" | \
timeout 30 $RUNTIME exec -i greenfield-${WORKSPACE}-target \
sh -c 'target-command' > output.txt 2>&1Before executing commands, verify:
$RUNTIME inspect --format='{{.State.Running}}' greenfield-${WORKSPACE}-target$RUNTIME exec greenfield-${WORKSPACE}-target test -d /output# Help and version discovery
timeout 30 $RUNTIME exec $CONTAINER sh -c 'target --help 2>&1' > cli/help.txt
timeout 30 $RUNTIME exec $CONTAINER sh -c 'target --version 2>&1' > cli/version.txt
# Subcommand enumeration: parse help output, try each subcommand
# Error exploration: invalid flags, missing args, bad input
# Config discovery: env vars, config files, default paths# Probe root and common API paths
curl -s -D- http://127.0.0.1:3000/ > web/root-response.txt
for endpoint in /api /health /swagger.json /openapi.json; do
STATUS=$(curl -s -o /dev/null -w '%{http_code}' "http://127.0.0.1:3000${endpoint}")
echo "${endpoint} -> ${STATUS}" >> web/endpoint-scan.txt
done# Copy a file from the container
$RUNTIME cp greenfield-${WORKSPACE}-target:/path/to/file \
workspace/raw/runtime/extracted/
# List files inside the container
$RUNTIME exec greenfield-${WORKSPACE}-target find /app -type f -name '*.log' 2>/dev/nullBuild failure: Log to build-log.txt, skip runtime mode, continue with static analysis.
Command timeout (exit 124): Capture partial output, note timeout, move to next command.
Container crash/OOM:
if [ "$($RUNTIME inspect --format='{{.State.Running}}' $CONTAINER 2>/dev/null)" != "true" ]; then
$RUNTIME logs $CONTAINER > crash-log.txt 2>&1
$RUNTIME start $CONTAINER # Attempt restart
fiContainer errors are behavioral observations — document them as data, not just failures.
| Resource | Default | Notes |
|---|---|---|
| Memory | 2 GB | --memory=2g |
| CPU | 2 cores | --cpus=2 |
| Command timeout | 30 seconds | timeout 30 on docker exec |
| PID limit | 256 | --pids-limit=256 |
| Network | None | --network=none (default) |
| GPU | Never | Not granted |
| Privileged | Never | Not granted |
--privilegedworkspace/raw/runtime/0.0.0.0 (always 127.0.0.1)workspace/raw/runtime/© prime-radiant-inc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/container-execution of prime-radiant-inc/greenfield.
Open the folder on GitHubat commit 6e6d4b4
Containerized Target Execution next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Containerized Target Execution this skillprime-radiant-inc/greenfield | 292 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Iron Proxy Gateway for NanoClawnanocoai/nanoclaw | 31k | — | ~4.6k | Automated safety check: Notes | MIT | |
| Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills | 148 | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | |
| Container Sbomcdxgen/cdxgen | 1.1k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| CI/CD Pipeline Principlesirahardianto/awesome-agv | 157 | — | ~2.7k | Automated safety check: Notes | MIT | |
| Detecting Container Escape Attemptsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 |
nanocoai/nanoclaw
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
aliyun/alibabacloud-ecs-troubleshoot-skills
Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。
cdxgen/cdxgen
Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen…
irahardianto/awesome-agv
Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.
mukul975/Anthropic-Cybersecurity-Skills
Detects container escape at runtime across tooling - namespace manipulation, capability abuse, kernel exploits, sensitive host mounts, and anomalous syscalls - and explains which signals matter…
mukul975/Anthropic-Cybersecurity-Skills
Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using…
prime-radiant-inc/greenfield
Master methodology for reverse-engineering a codebase into behavioral specs with cited evidence, reading every line across source, binaries, docs, runtime and git history.
prime-radiant-inc/greenfield
Mines tutorials, forums, reviews, issues and changelogs for observed product behavior, using six search channels and consensus analysis.
prime-radiant-inc/greenfield
Finds OpenAPI, GraphQL, Protobuf and JSON Schema files in a codebase and extracts behavioral claims from them as part of a reverse-engineering workflow.
prime-radiant-inc/greenfield
Method for extracting behavioral specifications from a product's public documentation: tiered search order, claim extraction rules, output structure, stop criteria and gap analysis.
prime-radiant-inc/greenfield
Layer 1 skill for SDK and ecosystem analysis. An agent skill from prime-radiant-inc/greenfield.
prime-radiant-inc/greenfield
Cross-validates sanitized output specs against raw source specs to detect lost behavioral detail, dropped constants, missing features, or diluted precision.
Works with
Categories
Runs untrusted analysis targets inside Docker or Podman containers with memory, CPU and process limits, covering image builds, lifecycle, command execution and cleanup. This infrastructure skill makes sure that code under analysis in the greenfield pipeline never runs on the host. It detects whether Docker or Podman is available and, if neither is present, treats that as non-fatal and skips the agents that need containers rather than failing.
Containerized Target Execution fits situations like: running an unfamiliar or untrusted codebase for behavioral analysis; building a per-target Docker image based on its detected language; setting resource limits before executing commands inside a target container; cleaning up analysis containers after a run.
Run `npx skills add prime-radiant-inc/greenfield --skill container-execution -a claude-code`. Or copy the skill folder (skills/container-execution in prime-radiant-inc/greenfield) into .claude/skills/container-execution in your project. Claude Code loads it when a task matches its description.
Run `npx skills add prime-radiant-inc/greenfield --skill container-execution -a codex`. Or copy the skill folder (skills/container-execution in prime-radiant-inc/greenfield) into .agents/skills/container-execution in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add prime-radiant-inc/greenfield --skill container-execution -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/container-execution, .gemini/skills/container-execution, .github/skills/container-execution and .opencode/skills/container-execution in your project.
Going by SKILL.md and its folder, Containerized Target Execution needs the command-line tools its instructions call (sh, curl, docker and podman). Our summary lists: Docker or Podman.
SKILL.md contains no URLs. Its commands use curl and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Containerized Target Execution is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Containerized Target Execution: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars), Container Sbom (cdxgen/cdxgen, 1.1k stars) and CI/CD Pipeline Principles (irahardianto/awesome-agv, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
prime-radiant-inc (a GitHub organization) maintains it in prime-radiant-inc/greenfield, which has 292 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on August 6, 2026.
Source: prime-radiant-inc/greenfield on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.