docker-agent-run
Use this skill when running a Docker Agent with `docker agent run`, choosing a safety/approval mode, using the `--sandbox` isolation flag, setting up aliases, or troubleshooting a run (missing credentials, worktrees). Even if the user just says they want to "run my agent", "make my agent auto-approv
- 0
- Installs
- —
- Rating
- —
- Success rate
- 6
- Files scanned
Do not let an agent install this unattended
Security scan
FlaggedHigh-risk patterns found. A human should read the source before any agent installs this.
- highDisables agent or tool safety checks
references/safety-and-sandbox.md:9
| `autonomous` (`--yolo`) | Approve everything | Fully trusted or already-sandboxed agent |
Turning off permission prompts, sandboxes, hooks or TLS verification removes the guardrails that catch mistakes and attacks.
- highDisables agent or tool safety checks
references/safety-and-sandbox.md:11
Precedence: an explicit `--safety`/`--yolo` on the `docker agent run` command
Turning off permission prompts, sandboxes, hooks or TLS verification removes the guardrails that catch mistakes and attacks.
- highDisables agent or tool safety checks
SKILL.md:3
description: Use this skill when running a Docker Agent with `docker agent run`, choosing a safety/approval mode, using the `--sandbox` isolation flag, setti…
Turning off permission prompts, sandboxes, hooks or TLS verification removes the guardrails that catch mistakes and attacks.
- highDisables agent or tool safety checks
SKILL.md:20
- The user is choosing or debugging `--safety`, `--yolo`, or approval behavior for tool calls.
Turning off permission prompts, sandboxes, hooks or TLS verification removes the guardrails that catch mistakes and attacks.
- highDisables agent or tool safety checks
SKILL.md:43
- `autonomous` — approve everything automatically. Equivalent to `--yolo`.
Turning off permission prompts, sandboxes, hooks or TLS verification removes the guardrails that catch mistakes and attacks.
- highDisables agent or tool safety checks
SKILL.md:47
`autonomous`/`--yolo` for a sandboxed or fully trusted interactive session.
Turning off permission prompts, sandboxes, hooks or TLS verification removes the guardrails that catch mistakes and attacks.
- highDisables agent or tool safety checks
skill.yaml:14
- The task is choosing or debugging --safety, --yolo, or --sandbox behavior for a run.
Turning off permission prompts, sandboxes, hooks or TLS verification removes the guardrails that catch mistakes and attacks.
- mediumDisables agent or tool safety checks (appears in a warning/example)
SKILL.md:45
`autonomous`/`--yolo`. Use `restricted` for unattended runs so an
Turning off permission prompts, sandboxes, hooks or TLS verification removes the guardrails that catch mistakes and attacks.
Content sha256 ced50eb0cf97f7d9… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Docker Agent: Running and Operating Agents
Overview
This skill owns the operational side of Docker Agent: invoking docker agent run against a local config, an alias, or a registry reference; choosing how
much autonomy the agent gets over tool calls; isolating it in a sandbox VM;
and diagnosing why a run fails. It assumes the agent.yaml already exists —
see Related skills for authoring it.
When to use this skill
Activate this skill when:
- The user wants to run an agent interactively or headlessly (
--exec). - The user is choosing or debugging
--safety,--yolo, or approval behavior for tool calls. - The user wants to isolate an agent's shell/filesystem access with
--sandbox, or hit a sandbox network-policy error. - The user wants a reusable shortcut (
docker agent alias), a scoped git worktree (--worktree), or is debugging credentials/model availability (docker agent doctor).
Do not use this skill when
Do not use this skill when:
- The task uses standalone
sbx run/create/stop/rmrather thandocker agent run --sandbox— usedocker-sandboxes-lifecycle. - The task is standalone
sbx policyorsbx secretconfiguration — usedocker-sandboxes-network-credentials. Establish which CLI is in use before recommending commands when the request only says "my sandbox". - The task is writing or editing the
agent.yamlitself (models, toolsets, sub_agents) — usedocker-agent-config. - The task is exposing an agent as a server (
serve), sharing it via a registry (share), or evaluating it (evaluation sessions,--baselineregression gates) — usedocker-agent-deploy.
Core guidance
Safety modes
docker agent runsupports four--safetymodes; choose the least permissive one that still lets the task finish:strict— ask for approval before every tool call.balanced— auto-approve calls classified as safe, ask for the rest.restricted— auto-approve safe calls, deny the rest outright. Use for unattended/CI runs where no human can answer a prompt.autonomous— approve everything automatically. Equivalent to--yolo.
- Never default an unattended run (cron, CI, a server endpoint) to
autonomous/--yolo. Userestrictedfor unattended runs so an unexpected tool call fails closed instead of running unreviewed; reserveautonomous/--yolofor a sandboxed or fully trusted interactive session.# CI-safe: unreviewed tool calls are denied, not silently approved. docker agent run --exec --safety restricted ./agent.yaml "Triage the failing test" - Bake a safety default into an alias so callers don't have to remember it,
and note that an explicit CLI
--safety/--yoloondocker agent runstill overrides the alias:docker agent alias add safe-coder myorg/coder --safety balanced
Sandbox isolation
--sandboxruns the agent inside an isolated microVM managed by thesbxCLI (a separate prerequisite — install and configure it first). All shell, filesystem, and process activity started by built-in toolsets happens inside the VM; only the working directory (and, unless--no-kit, a staged "kit" of skills/prompt files) is mounted in. Exception: a local stdio MCP server declared on the agent runs as a host process outside the sandbox VM — treat any such MCP server as a trusted host integration, not a sandboxed one.docker agent run --sandbox ./agent.yaml- The sandbox network proxy is default-deny: only the model provider,
models.dev, and hosts the toolset resolver can infer are open. A custom MCP server or third-party API often needs an explicit allowlist entry — add it permanently rather than re-discovering it every run:docker agent sandbox allow api.example.com docker agent sandbox list docker agent sandbox deny api.example.com - Prefer baking
runtime: {sandbox: true}into the agent's ownagent.yamlover remembering--sandboxon every invocation of that agent; an explicit--sandbox=falseon the CLI still overrides the config default for a single debug run. - Sandboxes persist and are reused across runs from the same workspace — they are not torn down when the session ends. Don't expect a clean VM on every run; if you need one, change the mount set (e.g. a new kit) to force recreation.
Aliases and default agent
- Register a shortcut once, then run it by name instead of a path:
docker agent alias add code myorg/notion-expert docker agent run code - For a local run with no agent argument,
docker agent rundiscoversdocker-agent.yaml, thendocker-agent.yml, thendocker-agent.hclin the current directory (first match wins). Only if none exists does it resolve thedefaultalias, falling back to the built-in default agent. Theagent.yamlexamples in these skills pass a filename explicitly;agent.yamlis not an auto-discovery name. - Set the fallback for directories without a project config with a
defaultalias. To select it even when a project config exists, passdefaultexplicitly:docker agent alias add default ./my-agent.yaml docker agent run default - CLI flags on
docker agent run <alias>always override the alias's own stored options (e.g.docker agent run yolo-coder --yolo=false).
Worktrees
- Use
--worktree(-w) to isolate an agent's file edits from your current checkout — it runs the agent inside a fresh git worktree. For an interactive session, a clean worktree (no uncommitted changes, untracked files, or new commits) is removed automatically when the session ends; one with work prompts you to keep or remove. A headless run (--exec) never auto-cleans its worktree, regardless of state — it is left in place for inspection:docker agent run ./agent.yaml --worktree=auth-refactor --worktree-base origin/main --worktreecannot be combined with--remoteor--sandbox. To resume a worktree run, pass--session -1(or the session id) — do not re-pass--worktree, which fails because the worktree already exists.
Troubleshooting
- "No model is currently available" or "model ... is not pulled" means the
agent's provider has no usable credential, or (for
dmr/) the model hasn't been pulled. Rundocker agent doctor ./agent.yamlfirst — it reports the resolved model/provider and whether credentials were found — before touching the YAML. If credentials are missing, export the provider's API key; if a DMR model is missing, rundocker model pull <model>. Rerundoctorbefore retrying the task. - An agent that only describes a plan instead of executing it is usually
missing the tool it needs (add
type: shellortype: todoinagent.yaml), not a model failure — hand this back todocker-agent-config. - A
403 Blocked by network policyerror inside a sandbox run means the destination isn't allowlisted; usedocker agent sandbox allow <host>.
Related skills
- For standalone
sbxlifecycle commands, usedocker-sandboxes-lifecycle. - For standalone
sbx policyandsbx secret, usedocker-sandboxes-network-credentials. - For writing or changing the underlying
agent.yaml(models, toolsets, sub_agents), usedocker-agent-config. - For serving, sharing, or evaluating the agent, use
docker-agent-deploy.
References
references/safety-and-sandbox.md— full safety-mode/flag interaction table and sandbox trust-boundary details.references/sources.md— provenance of every rule in this skill.
Assets
- None.
Checks
checks/verification.md— Verification runbook for adocker agent runinvocation.
Files
6- SKILL.md
0ad212ab938.5 KB - agents/openai.yaml
a9b4b79ae6404 B - checks/verification.md
2c3ffb6a7f1.7 KB - references/safety-and-sandbox.md
55af31032f2.1 KB - references/sources.md
119220a7b81.6 KB - skill.yaml
1ec155f0e91.1 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from docker/skills8
Use this skill when creating or editing an agent.yaml (or .yml/.hcl) configuration file for Docker Agent (cagent), including defining agents, models/providers, built-in or MCP toolsets, multi-agent teams with sub_agents. Even if the user just says they want to "build an AI agent with Docker", "make
Use this skill when exposing a Docker Agent as a server (MCP, HTTP API, A2A, ACP, or OpenAI-compatible chat), distributing an agent via an OCI registry with `docker agent share`, or measuring agent quality with `docker agent eval`. Even if the user just says they want to "turn my agent into an MCP s
Use this skill when writing, reviewing, or optimizing Dockerfiles, even if the user just says their image is too large, their build is slow, or they need to harden a container for production. Covers multi-stage builds, layer caching, .dockerignore, non-root users, and image size optimization.
Use this skill when creating, modifying, or debugging Docker Compose configurations, even if the user just says they need to wire services together, add a database to their stack, or set up a local development environment with multiple containers. Covers service definitions, health checks, dependenc
Use this skill before running, or recommending, any Docker command that deletes, wipes, resets, or otherwise irreversibly changes state — even if the user just says to "clean up", "clear the cache", "start fresh", "wipe everything", "nuke it", "reset", "force remove", or "tear down" Docker resources
Use this skill when setting up, initializing, or Dockerizing a project, even if the user doesn't explicitly mention Docker but describes a need for containerized local development, adding a database or cache dependency, or running services without host-level installs. Covers Dockerfile, compose.yaml
Use this skill when authoring, planning, or running a declarative `sbxenv.yaml` file for Docker Sandboxes (`sbx env create/run/plan/exec/rm`), even if the user just says they want to "check in a sandbox config", "make onboarding reproducible for a sandbox", "run a setup script before the agent start
Use this skill when authoring, validating, packaging, signing, or composing a Docker Sandboxes kit `spec.yaml` (`sbx kit add/inspect/pack/pull/push/sign/validate/verify`), even if the user just says they want to "add a tool to a sandbox agent", "build a reusable sandbox extension", "publish a kit to
Related devops skillsscan passed
Run repeated rollouts ("Prime Gauss" style recursive prompting) while keeping an append-only decision ledger of trials, marks, coherence checks, and promotion gates, so recursive confidence never auto-approves live trading, deploy, or destructive actions. Use when the user asks for repeated rollouts
Land and deploy workflow. (gstack)
Migrate Cloudflare Sandbox apps from stable @cloudflare/sandbox to @cloudflare/sandbox@next (SDK 1.0 preview). Use sandbox-next for apps already on the preview.
Deploy tRPC on AWS Lambda with awsLambdaRequestHandler() from @trpc/server/adapters/aws-lambda for API Gateway v1 (REST, APIGatewayProxyEvent) and v2 (HTTP, APIGatewayProxyEventV2), and Lambda Function URLs. Enable response streaming with awsLambdaStreamingRequestHandler() wrapped in awslambda.strea
Automates CI/CD pipeline setup. Use when setting up or modifying build and deployment pipelines. Use when you need to automate quality gates, configure test runners in CI, or establish deployment strategies.
Deploys and configures classic Firebase Hosting for static websites, single-page apps (SPAs), and microservices. Use when deploying static sites/SPAs, setting up custom domains, configuring firebase.json hosting settings (redirects, rewrites, headers, multi-site), or managing preview channels. Don't