Agent skill

Convert To Apple Container

by sbusso in sbusso/claudeclaw

Switch from Docker to Apple Container for macOS-native container isolation.

MITAuto-check: notesDevOps & Cloud

Install Convert To Apple Container

skills CLI
$ npx skills add sbusso/claudeclaw --skill convert-to-apple-container -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sbusso/claudeclaw convert-to-apple-container --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sbusso/claudeclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/convert-to-apple-container .claude/skills/convert-to-apple-container && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
convert-to-apple-container
GitHub stars
194
Token cost
~1.4k tokens
SKILL.md length
433 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Switch from Docker to Apple Container for macOS-native container isolation.

  • Works in 3 steps: Pre-flight → Apply Code Changes → Verify
  • The user wants Apple Container instead of Docker
  • SKILL.md covers Prerequisites, Phase 1: Pre-flight, Phase 2: Apply Code Changes and Phase 3: Verify, plus 2 more sections
  • Calls git, npm and docker

What it does

Convert To Apple Container is an agent skill from sbusso/claudeclaw. Switch from Docker to Apple Container for macOS-native container isolation. Use when the user wants Apple Container instead of Docker, or is setting up on macOS and prefers the native runtime. Triggers on "apple container", "convert to apple container", "switch to apple container", or "use apple container".

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers. It works with Docker and macOS. The repository describes itself as: Use Claude to orchestrate agents like OpenClaw. The licence is MIT.

When your agent uses it

  • The user wants Apple Container instead of Docker
  • Is setting up on macOS and prefers the native runtime
  • Apple container
  • Convert to apple container

Example prompts

  • “apple container”
  • “convert to apple container”
  • “switch to apple container”
  • “/convert-to-apple-container”

Requirements

  • Docker

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Pre-flight
  2. Apply Code Changes
  3. Verify

What it can do on your machine

Read from SKILL.md and the folder at commit 1395af4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Convert To Apple Container loads about 1.4k tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 433 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:16
    - Dockerfile entrypoint: `.env` shadowing via `mount --bind` inside the container (Apple Container only supports directo
  • NoteMentions a .env fileSKILL.md:74
    `src/orchestrator/container-runner.ts` — .env shadow mount fix and privilege dropping
  • NoteMentions a .env fileSKILL.md:75
    er/Dockerfile` — entrypoint that shadows .env via `mount --bind`
  • NoteMentions a .env fileSKILL.md:175
    `src/orchestrator/container-runner.ts` | .env shadow mount removed, main containers start as root with privilege drop |
  • NoteMentions a .env fileSKILL.md:176
    erfile` | Entrypoint: `mount --bind` for .env shadowing, `setpriv` privilege drop |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sbusso/claudeclaw at commit 1395af4, republished under its MIT licence (© sbusso). 433 words, ~1,414 tokens.

Download SKILL.mdSave it as .claude/skills/convert-to-apple-container/SKILL.md (or your agent's skills folder).
name
convert-to-apple-container
description
Switch from Docker to Apple Container for macOS-native container isolation. Use when the user wants Apple Container instead of Docker, or is setting up on macOS and prefers the native runtime. Triggers on "apple container", "convert to apple container", "switch to apple container", or "use apple container".

Convert to Apple Container

This skill switches ClaudeClaw's container runtime from Docker to Apple Container (macOS-only). It uses the skills engine for deterministic code changes, then walks through verification.

What this changes:

  • Container runtime binary: docker → container
  • Mount syntax: -v path:path:ro → --mount type=bind,source=...,target=...,readonly
  • Startup check: docker info → container system status (with auto-start)
  • Orphan detection: docker ps --filter → container ls --format json
  • Build script default: docker → container
  • Dockerfile entrypoint: .env shadowing via mount --bind inside the container (Apple Container only supports directory mounts, not file mounts like Docker's /dev/null overlay)
  • Container runner: main-group containers start as root for mount --bind, then drop privileges via setpriv

What stays the same:

  • Mount security/allowlist validation
  • All exported interfaces and IPC protocol
  • Non-main container behavior (still uses --user flag)
  • All other functionality

Prerequisites

Verify Apple Container is installed:

bash
container --version && echo "Apple Container ready" || echo "Install Apple Container first"

If not installed:

Apple Container requires macOS. It does not work on Linux.

Phase 1: Pre-flight

Check if already applied
bash
grep "CONTAINER_RUNTIME_BIN" src/orchestrator/container-runtime.ts

If it already shows 'container', the runtime is already Apple Container. Skip to Phase 3.

Phase 2: Apply Code Changes

Ensure upstream remote
bash
git remote -v

If upstream is missing, add it:

bash
git remote add upstream https://github.com/sbusso/claudeclaw.git
Merge the skill branch
bash
git fetch upstream skill/apple-container
git merge upstream/skill/apple-container

This merges in:

  • src/orchestrator/container-runtime.ts — Apple Container implementation (replaces Docker)
  • src/container-runtime.test.ts — Apple Container-specific tests
  • src/orchestrator/container-runner.ts — .env shadow mount fix and privilege dropping
  • src/runtimes/docker/Dockerfile — entrypoint that shadows .env via mount --bind
  • src/runtimes/docker/build.sh — default runtime set to container

If the merge reports conflicts, resolve them by reading the conflicted files and understanding the intent of both sides.

Validate code changes
bash
npm test
npm run build

All tests must pass and build must be clean before proceeding.

Show full SKILL.md (169 more words)Show less

Phase 3: Verify

Ensure Apple Container runtime is running
bash
container system status || container system start
Build the container image
bash
./src/runtimes/docker/build.sh
Test basic execution
bash
echo '{}' | container run -i --entrypoint /bin/echo claudeclaw-agent:latest "Container OK"
Test readonly mounts
bash
mkdir -p /tmp/test-ro && echo "test" > /tmp/test-ro/file.txt
container run --rm --entrypoint /bin/bash \
  --mount type=bind,source=/tmp/test-ro,target=/test,readonly \
  claudeclaw-agent:latest \
  -c "cat /test/file.txt && touch /test/new.txt 2>&1 || echo 'Write blocked (expected)'"
rm -rf /tmp/test-ro

Expected: Read succeeds, write fails with "Read-only file system".

Test read-write mounts
bash
mkdir -p /tmp/test-rw
container run --rm --entrypoint /bin/bash \
  -v /tmp/test-rw:/test \
  claudeclaw-agent:latest \
  -c "echo 'test write' > /test/new.txt && cat /test/new.txt"
cat /tmp/test-rw/new.txt && rm -rf /tmp/test-rw

Expected: Both operations succeed.

Service name: Derived from the directory name: com.claudeclaw.<dirname> (macOS) / claudeclaw-<dirname> (Linux). For example, if cwd is my-assistant, the service is com.claudeclaw.my-assistant. Determine the correct service name before running service commands below.

Full integration test
bash
npm run build
launchctl kickstart -k gui/$(id -u)/com.claudeclaw

Send a message via WhatsApp and verify the agent responds.

Troubleshooting

Apple Container not found:

Runtime won't start:

bash
container system start
container system status

Image build fails:

bash
# Clean rebuild — Apple Container caches aggressively
container builder stop && container builder rm && container builder start
./src/runtimes/docker/build.sh

Container can't write to mounted directories: Check directory permissions on the host. The container runs as uid 1000.

Summary of Changed Files

FileType of Change
src/orchestrator/container-runtime.tsFull replacement — Docker → Apple Container API
src/container-runtime.test.tsFull replacement — tests for Apple Container behavior
src/orchestrator/container-runner.ts.env shadow mount removed, main containers start as root with privilege drop
src/runtimes/docker/DockerfileEntrypoint: mount --bind for .env shadowing, setpriv privilege drop
src/runtimes/docker/build.shDefault runtime: docker → container

© sbusso, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/convert-to-apple-container of sbusso/claudeclaw.

Open the folder on GitHubat commit 1395af4

Compare with similar skills

Convert To Apple Container next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Convert To Apple Container compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Convert To Apple Container this skillsbusso/claudeclaw194—~1.4kAutomated safety check: NotesMIT
.NET Crash Dump Collectiondotnet/skills5.6k2 repos~1.1kAutomated safety check: PassMIT
Agentdock User Guideuvwt/agentdock1.2k—~1.6kAutomated safety check: PassApache-2.0
Foundationdb AspireSnowBankSDK/foundationdb-dotnet-client158—~3.4kAutomated safety check: PassBSD-3-Clause
Setup Review Sandboxnrwl/nx29k—~1.8kAutomated safety check: NotesMIT
Reproduce Issuenrwl/nx29k—~2.6kAutomated safety check: NotesMIT

Similar skills

  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Agentdock User Guide

    uvwt/agentdock

    当用户询问 AgentDock 是什么、如何使用、配置在哪里、不同平台或安装方式怎样修改配置并生效、如何重启或验证配置、如何发现并配置 Codex/Claude/Grok 等 Coding Agent 的 ACP,以及常见运行问题时使用;覆盖 macOS Desktop、Windows Desktop、Linux 服务、Docker 和直接运行二进制,不用于源码开发与贡献流程。

    1.2k GitHub stars~1.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Foundationdb Aspire

    SnowBankSDK/foundationdb-dotnet-client

    How to run a FoundationDB cluster and connect to it from .NET — getting the IFdbDatabaseProvider that the keys/transactions/layers skills assume you already have.

    158 GitHub stars~3.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • One-time setup of the sandbox prerequisites used by the reproduce-issue skill and the reproduce-verifier agent — Docker, the isolation runtime (gVisor on Linux / Colima on macOS), healthy container…

    29k GitHub stars~1.8k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • The single skill for reproducing an nx issue. An agent skill from nrwl/nx.

    29k GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Osx Tuning

    dimetron/pi-go

    Tune macOS resource limits and sysctls for best performance with Go development, Docker/OrbStack, and Linux VMs.

    209 GitHub stars~1.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes

More from sbusso/claudeclaw

All 23 skills in this repo
  • Debug

    sbusso/claudeclaw

    Debug container agent issues. An agent skill from sbusso/claudeclaw.

    194 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check: notes
  • X Integration

    sbusso/claudeclaw

    X (Twitter) integration for ClaudeClaw. An agent skill from sbusso/claudeclaw.

    194 GitHub stars~3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Add Gmail

    sbusso/claudeclaw

    Add Gmail integration to ClaudeClaw. An agent skill from sbusso/claudeclaw.

    194 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Add Qmd

    sbusso/claudeclaw

    Add QMD (Query Markup Documents) as an advanced memory search backend.

    194 GitHub stars~629 tokensUpdated 1 mo ago
    Auto-check passed
  • Add Telegram

    sbusso/claudeclaw

    Add Telegram as a channel. An agent skill from sbusso/claudeclaw.

    194 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • Add Telegram Swarm

    sbusso/claudeclaw

    Add Agent Swarm (Teams) support to Telegram. An agent skill from sbusso/claudeclaw.

    194 GitHub stars~3.7k tokensUpdated 1 mo ago
    Auto-check: notes

Works with

Categories

Questions about Convert To Apple Container

What does Convert To Apple Container do?

Switch from Docker to Apple Container for macOS-native container isolation. Convert To Apple Container is an agent skill from sbusso/claudeclaw. Switch from Docker to Apple Container for macOS-native container isolation.

When should I use Convert To Apple Container?

Convert To Apple Container fits situations like: the user wants Apple Container instead of Docker; is setting up on macOS and prefers the native runtime; apple container; convert to apple container.

How do I install Convert To Apple Container in Claude Code?

Run `npx skills add sbusso/claudeclaw --skill convert-to-apple-container -a claude-code`. Or copy the skill folder (skills/convert-to-apple-container in sbusso/claudeclaw) into .claude/skills/convert-to-apple-container in your project. Claude Code loads it when a task matches its description.

How do I install Convert To Apple Container in Codex?

Run `npx skills add sbusso/claudeclaw --skill convert-to-apple-container -a codex`. Or copy the skill folder (skills/convert-to-apple-container in sbusso/claudeclaw) into .agents/skills/convert-to-apple-container in your project. Codex loads it when a task matches its description.

Can I use Convert To Apple Container in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sbusso/claudeclaw --skill convert-to-apple-container -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/convert-to-apple-container, .gemini/skills/convert-to-apple-container, .github/skills/convert-to-apple-container and .opencode/skills/convert-to-apple-container in your project.

What does Convert To Apple Container need to run?

Going by SKILL.md and its folder, Convert To Apple Container needs the command-line tools its instructions call (git, npm and docker). Our summary lists: Docker.

Does Convert To Apple Container access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Convert To Apple Container safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Convert To Apple Container use?

Convert To Apple Container is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Convert To Apple Container use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Convert To Apple Container?

Skills that share tags, products or a category with Convert To Apple Container: .NET Crash Dump Collection (dotnet/skills, 5.6k stars), Agentdock User Guide (uvwt/agentdock, 1.2k stars), Foundationdb Aspire (SnowBankSDK/foundationdb-dotnet-client, 158 stars) and Setup Review Sandbox (nrwl/nx, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Convert To Apple Container?

sbusso (a GitHub user) maintains it in sbusso/claudeclaw, which has 194 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on August 12, 2026.

Source: sbusso/claudeclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.