Agent skill

Apple Container

by sanjay3290 in sanjay3290/ai-skills

Apple's open-source container CLI to build, run, and manage OCI/Linux containers as lightweight per-container VMs on Apple-silicon macOS — no Docker daemon required.

Apache-2.0Auto-check passedDevOps & Cloud

Install Apple Container

skills CLI
$ npx skills add sanjay3290/ai-skills --skill apple-container -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sanjay3290/ai-skills apple-container --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sanjay3290/ai-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/apple-container .claude/skills/apple-container && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
apple-container
GitHub stars
431
Token cost
~2.2k tokens
SKILL.md length
966 words
Files
5 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
Apache-2.0

At a glance

Apple's open-source container CLI to build, run, and manage OCI/Linux containers as lightweight per-container VMs on Apple-silicon macOS — no Docker daemon required.

  • Works in 3 steps: Download the latest signed installer… → Double-click the downloaded package and… → Start the services and confirm they are…
  • The user mentions the container CLI
  • SKILL.md covers Requirements, Setup, Command groups at a glance and Navigating this skill, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Apple Container is an agent skill from sanjay3290/ai-skills. Apple's open-source container CLI to build, run, and manage OCI/Linux containers as lightweight per-container VMs on Apple-silicon macOS — no Docker daemon required. Use when the user mentions the container CLI, "apple container", running or building containers on macOS without Docker/Podman, container run, container build, container images, container system start, pushing/pulling images to a registry, or container networking on macOS. This is Apple's container tool specifically (repo apple/container), NOT…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/commands.md`, `references/concepts.md` and `references/configuration.md`).

It sits in DevOps & Cloud, covering Containers. It works with Docker, macOS, Linux and Kubernetes. The repository describes itself as: 24 cross-platform agent skills for Claude Code, Cursor, Codex & Gemini CLI — databases, messaging, research, TTS, DevOps, and Google Workspace. The licence is Apache-2.0.

When your agent uses it

  • The user mentions the container CLI
  • Apple container
  • Building containers on macOS without Docker/Podman
  • Container build

Example prompts

  • “apple container”
  • “/apple-container”

Requirements

  • Docker

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Download the latest signed installer .pkg from the
  2. Double-click the downloaded package and follow the prompts, entering your admin
  3. Start the services and confirm they are healthy

What it can do on your machine

Read from SKILL.md and the folder at commit 281d88d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Apple Container loads about 2.2k tokens when it runs, and up to ~31k if it reads all its reference files. Until then it costs about 161 tokens; SKILL.md has 966 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~161
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~31k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sanjay3290/ai-skills at commit 281d88d, republished under its Apache-2.0 licence (© sanjay3290). 966 words, ~2,176 tokens.

Download SKILL.mdSave it as .claude/skills/apple-container/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
apple-container
description
Apple's open-source `container` CLI to build, run, and manage OCI/Linux containers as lightweight per-container VMs on Apple-silicon macOS — no Docker daemon required. Use when the user mentions the `container` CLI, "apple container", running or building containers on macOS without Docker/Podman, `container run`, `container build`, `container images`, `container system start`, pushing/pulling images to a registry, or container networking on macOS. This is Apple's `container` tool specifically (repo `apple/container`), NOT Docker, Podman, containerd, nerdctl, or Kubernetes — the CLI is Docker-like but is a different tool.
license
Apache-2.0
metadata.author
sanjay3290
metadata.version
1.0

Apple container

Apple's container is an open-source CLI for building, running, and managing OCI/Linux containers on Apple-silicon Macs. Each container runs inside its own lightweight virtual machine (backed by the Containerization framework and the Virtualization API), so there is no shared daemon like Docker — services run per-user via launchd. Images are standard OCI artifacts, so they interoperate with Docker registries and other OCI tooling. The CLI is deliberately Docker-like (container run, container build, and image ops under container image push/pull), but it is a distinct tool: do not assume Docker command paths, flags, defaults, or daemon behavior carry over (e.g. there is no container images/push/pull top-level command — image verbs live under container image).

Requirements

  • Apple silicon only (M1 or later). Intel Macs are not supported.
  • macOS 26 (Tahoe) is the officially supported target. The maintainers do not support older macOS and typically will not fix issues that can't be reproduced on 26. The binary still runs on macOS 15 (Sequoia) but with reduced networking: only the single default subnet is available, and the container network group and --network flag error out. macOS-26-gated features are called out throughout the reference files.
  • Version: this skill documents the 1.0.0 release (the fullest feature set). The machine group, container cp, container export, container prune, container image prune, container registry list, and container system version were added in 1.0.0 (not in 0.7.1) — features that postdate 0.7.1 are flagged (1.0.0+) in the reference files. Run container --version and container <group> --help to see what your installed build supports.
  • Install by downloading the signed .pkg installer from the project's GitHub releases (apple/container) and running it. See references/concepts.md for the full requirements/compatibility matrix and how the VM-per-container model works.

Setup

Install the signed package, then start the background services once:

  1. Download the latest signed installer .pkg from the GitHub releases page.
  2. Double-click the downloaded package and follow the prompts, entering your admin password so it can place files under /usr/local. (There is no documented CLI installer invocation — installation is via the GUI package.)
  3. Start the services and confirm they are healthy:
bash
# Start the container services (container-apiserver + helpers via launchd). On first run it
# offers to install the default Linux kernel — accept it, or start non-interactively with
# `--disable-kernel-install` and add a kernel later via `container system kernel set`.
container system start

# Verify services are healthy
container system status

container system start must have run before any container/image/build command works — a connection/XPC error almost always means the services are stopped, so run it again. Stop and deregister the launchd services with container system stop (which takes only -p/--prefix). The startup flags for container system start (-a/--app-root, --install-root, --log-root, --enable-kernel-install/--disable-kernel-install, --timeout) are in references/configuration.md.

Upgrade / downgrade / uninstall use helper scripts in /usr/local/bin (stop first with container system stop): update-container.sh (add -v <version> to pin a version), and uninstall-container.sh -d to remove user data or -k to keep it. Full recipes in references/workflows.md.

Command groups at a glance

Invoke everything as container <group> <subcommand>. Container-lifecycle verbs (run, create, start, stop, exec, logs, inspect, list/ls, delete/rm, kill, stats) and build are top-level; image operations like push, pull, and tag live under container image. Run container <group> --help for exact flags, or read references/commands.md for the exhaustive matrix.

GroupWhat it doesExample
container lifecycleCreate, start, run, stop, exec, inspect, list, remove containerscontainer run --rm -it docker.io/library/alpine sh
buildBuild an OCI image from a Dockerfile in the builder VMcontainer build -t myapp:latest .
imageList, tag, inspect, remove, load/save, prune local images; push/pull to registriescontainer image ls
registryAuthenticate (login/logout/list) to OCI registriescontainer registry login ghcr.io
systemStart/stop/status services, logs, disk usage (df), DNS, kernel, propertiescontainer system status
networkCreate/list/remove container networks (macOS 26 only)container network create mynet
volumeCreate/list/inspect/remove persistent volumescontainer volume create data
builderManage the builder VM that runs container build (start/stop/status)container builder status
machine (1.0.0+)Persistent Linux "machine" environments (added in 1.0.0)container machine --help

Exact subcommand names, aliases, arguments, and flags for each group live in references/commands.md — consult it before running an unfamiliar command rather than guessing Docker-equivalent syntax.

Show full SKILL.md (330 more words)Show less

Navigating this skill

Read the reference file that matches the task; do not guess flags or behavior.

  • references/commands.md — exhaustive CLI reference: every command group, subcommand, alias, argument, and flag. Read this to construct any concrete container ... invocation, or to confirm a flag exists before using it.
  • references/concepts.md — architecture (VM-per-container, Containerization framework), system requirements and macOS 15 vs 26 differences, networking model, per-container IPs, security model, and a Docker-vs-container comparison. Read this to explain how or why something works, or when a Docker mental model gives the wrong answer.
  • references/configuration.md — the system service, config.toml / property model, default kernel, DNS domains, default registry, builder resources, and machine settings. Read this to change defaults, tune CPU/memory, point at a private registry, or manage the kernel.
  • references/workflows.md — copy-pasteable task recipes (run an image, build & push, wire up local DNS, mount a volume, expose ports) and troubleshooting for common failures. Read this first when the user wants to accomplish a concrete end-to-end task.

Key rules

  • This is not Docker. The CLI resembles Docker, but flags, defaults, and daemon behavior differ. Verify syntax in references/commands.md instead of assuming Docker equivalence.
  • Always ensure services are up first. Run container system start (and confirm with container system status) before any container/image/build command; connection errors usually mean the services are stopped.
  • Images are standard OCI artifacts and interoperate with Docker registries and other OCI tools. Image references that omit a registry default to docker.io (configurable via the registry.domain property — see references/configuration.md).
  • Each container gets its own IP address on its network (one lightweight VM per container). There is no shared Docker bridge; reach a container directly by its IP, or set up a local DNS domain (container system dns create ..., admin required) for name-based access.
  • container network requires macOS 26. On macOS 15 only the single default subnet is available and the network command group is unavailable — see references/concepts.md.
  • Use fully-qualified image references when precision matters (e.g. docker.io/library/alpine rather than bare alpine) to avoid ambiguity about the source registry.

© sanjay3290, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/apple-container of sanjay3290/ai-skills.

  • SKILL.md
  • references/commands.md
  • references/concepts.md
  • references/configuration.md
  • references/workflows.md

Open the folder on GitHubat commit 281d88d

Compare with similar skills

Apple Container next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Apple Container compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Apple Container this skillsanjay3290/ai-skills431—~2.2kAutomated safety check: PassApache-2.0
.NET Crash Dump Collectiondotnet/skills5.6k2 repos~1.1kAutomated safety check: PassMIT
Dotnet Debuggingnovotnyllc/dotnet-artisan233—~2.1kAutomated safety check: PassMIT
Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills1481 repos~2.6kAutomated safety check: NotesApache-2.0
Devsydevsy-org/devsy110—~1.7kAutomated safety check: PassMPL-2.0
Build Imageskubernetes-sigs/cloud-provider-azure294—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Dotnet Debugging

    novotnyllc/dotnet-artisan

    Debugs Windows and Linux/macOS applications (native, .NET/CLR, mixed-mode) with WinDbg MCP (crash dumps, !analyze, !syncblk, !dlk, !runaway, !dumpheap, !gcroot, BSOD), dotnet-dump, lldb with SOS…

    233 GitHub stars~2.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub starsUsed in 1 repo~2.6k tokens
    DevOps & CloudAuto-check: notes
  • Devsy

    devsy-org/devsy

    Operate Devsy workspaces and providers for end users. An agent skill from devsy-org/devsy.

    110 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Build Images

    kubernetes-sigs/cloud-provider-azure

    Official

    Build cloud-provider-azure container images through the repo Makefile with explicit IMAGETAG and IMAGEREGISTRY inputs, optional make flag overrides, and opt-in bounded Docker or Podman retries.

    294 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Ama Logs Update Charts Release Notes

    microsoft/Docker-Provider

    Official

    Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.

    174 GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check passed

More from sanjay3290/ai-skills

All 24 skills in this repo
  • Deep Research

    sanjay3290/ai-skills

    Execute autonomous multi-step research using Google Gemini Deep Research Agent.

    431 GitHub starsUsed in 10 repos~683 tokens
    Auto-check: notes
  • Imagen

    sanjay3290/ai-skills

    Generate images using Google Gemini's image generation capabilities.

    431 GitHub starsUsed in 7 repos~657 tokens
    Auto-check passed
  • Whatsapp

    sanjay3290/ai-skills

    Send and receive WhatsApp messages via the unofficial linked-device client pywhats (pip install pywhats) — pair with QR, send text/images, group chat, read receipts, presence/typing, and a…

    431 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Notebooklm

    sanjay3290/ai-skills

    Query and manage Google NotebookLM notebooks with persistent profile auth, source sync, batch/multi queries, and structured exports.

    431 GitHub stars~655 tokensUpdated 27 days ago
    Auto-check passed
  • Elevenlabs

    sanjay3290/ai-skills

    Convert documents and text to audio using ElevenLabs text-to-speech.

    431 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Postgres

    sanjay3290/ai-skills

    Execute read-only SQL queries against multiple PostgreSQL databases.

    431 GitHub starsUsed in 1 repo~975 tokens
    Auto-check passed

Categories

Questions about Apple Container

What does Apple Container do?

Apple's open-source container CLI to build, run, and manage OCI/Linux containers as lightweight per-container VMs on Apple-silicon macOS — no Docker daemon required. Apple Container is an agent skill from sanjay3290/ai-skills. Apple's open-source container CLI to build, run, and manage OCI/Linux containers as lightweight per-container VMs on Apple-silicon macOS — no Docker daemon required.

When should I use Apple Container?

Apple Container fits situations like: the user mentions the container CLI; apple container; building containers on macOS without Docker/Podman; container build.

How do I install Apple Container in Claude Code?

Run `npx skills add sanjay3290/ai-skills --skill apple-container -a claude-code`. Or copy the skill folder (skills/apple-container in sanjay3290/ai-skills) into .claude/skills/apple-container in your project. Claude Code loads it when a task matches its description.

How do I install Apple Container in Codex?

Run `npx skills add sanjay3290/ai-skills --skill apple-container -a codex`. Or copy the skill folder (skills/apple-container in sanjay3290/ai-skills) into .agents/skills/apple-container in your project. Codex loads it when a task matches its description.

Can I use Apple Container in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sanjay3290/ai-skills --skill apple-container -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/apple-container, .gemini/skills/apple-container, .github/skills/apple-container and .opencode/skills/apple-container in your project.

What does Apple Container need to run?

SKILL.md names no scripts, command-line tools or credentials: Apple Container is instructions for the agent only. Our summary lists: Docker.

Does Apple Container access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Apple Container safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Apple Container use?

Apple Container is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Apple Container use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 29k tokens, read only when the agent opens those files.

What are the alternatives to Apple Container?

Skills that share tags, products or a category with Apple Container: .NET Crash Dump Collection (dotnet/skills, 5.6k stars), Dotnet Debugging (novotnyllc/dotnet-artisan, 233 stars), Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars) and Devsy (devsy-org/devsy, 110 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Apple Container?

sanjay3290 (a GitHub user) maintains it in sanjay3290/ai-skills, which has 431 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on September 10, 2026.

Source: sanjay3290/ai-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.