Skillshare DevcontainerSAFE
๐ Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.
Overview
๐ Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.
0d9340b2ca90OBSERVED ยท 2026-10-08What it tells the agent
The instruction file, verbatim from the audited commit โ this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: skillshare-devcontainer
description: >-
Run CLI commands, tests, and debugging inside the skillshare devcontainer.
Use this skill whenever you need to: execute skillshare CLI commands for
verification, run Go tests (unit or integration), reproduce bugs, test new
features, start the web UI, or perform any operation that requires a Linux
environment. All CLI execution MUST happen inside the devcontainer โ never
run skillshare commands on the host. If you are about to use Bash to run
`ss`, `skillshare`, `go test`, or `make test`, stop and use this skill
first to ensure correct container execution.
argument-hint: "[command-to-run | task-description]"
metadata:
targets: [claude, universal]
---
Execute CLI commands and tests inside the devcontainer. The host machine is macOS but the project binary is Linux โ running CLI commands on the host will silently produce wrong results or fail. This skill prevents that mistake.
Before acting, run `python3 scripts/ai-context.py testing` and follow that topic. The topic is the source of truth for repository execution boundaries and test rules; this skill retains the interactive workflow and command recipes.
## When to Use This
- Running `ss` / `skillshare` commands for verification
- Running `go test`, `make test`, `make check`
- Reproducing a bug report
- Testing a feature you just implemented
- Starting the web UI dashboard
- Any command that needs the skillshare binary or Go toolchain
## When NOT to Use This
- Editing source code (do that on host via Read/Edit tools)
- Running `git` commands (git works on host)
- Running `make fmt`, `make lint` (host-safe Go toolchain commands; no container needed)
- E2E test runbooks โ use `cli-e2e-test` skill instead (it handles ssenv isolation)
## Architecture: Two Layers of Isolation
```
Host (macOS)
โโ Devcontainer (Linux, Debian-based)
โโ Default HOME: /home/developer (persistent volume)
โโ Source: /workspace (bind-mount of repo root)
โโ ssenv environments: ~/.ss-envs/<name>/ (isolated HOME dirs)
```
**Devcontainer** = Linux environment with Go, git, pnpm, air (hot-reload). Source code is at `/workspace` (bind-mount of the host repo). The `ss` / `skillshare` wrapper auto-builds from source on every invocation โ **no manual `make build` needed**. Edit code on the host, then immediately `docker exec` to run it; the change is picked up automatically.
**ssenv** = Isolated HOME directories within the devcontainer. Each env gets its own `~/.config/skillshare/`, `~/.claude/`, etc. Use ssenv when you need a clean state (testing init, install, sync) without polluting the container's default HOME.
## Zero-Rebuild Workflow
Source code is bind-mounted into the container at `/workspace`. The `ss` wrapper runs `go build` transparently on every invocation:
1. Edit files on host (Read/Edit tools)
2. `docker exec $CONTAINER ss <command>` โ picks up your changes instantly
3. No `make build`, no restart, no rebuild step
This also applies to `go test` โ tests always compile against the latest source. The Web UI backend uses `air` for hot-reload (same zero-rebuild experience).
## Entering the Devcontainer
The quickest way โ one command builds, initialises, and enters the shell:
```bash
make devc # build + init + interactive shell (one step)
make devc-up # start only (no shell)
make devc-down # stop
make devc-restart # restart + re-run start-dev.sh
make devc-reset # full reset (remove volumes), then `make devc` to re-init
make devc-status # show container status
```
Works with **or without** VS Code โ `make devc` handles the full lifecycle autonomously.
### Programmatic access (for `docker exec` workflows)
```bash
CONTAINER=$(docker compose -f .devcontainer/docker-compose.yml ps -q skillshare-devcontainer 2>/dev/null)
```
If `$CONTAINER` is empty, tell the user:
> Devcontainer is not running. Start it with `make devc-up`.
Then verify the binary:
```bash
docker exec $CONTAINER bash -c \
'/workspace/.devcontainer/ensure-skillshare-linux-binary.sh && ss version'
```
## Running Commands
### Simple command (uses container's default HOME)
```bash
docker exec $CONTAINER ss <command> [flags]
```
Good for: `ss version`, `ss status`, `ss list`, `ss check`, `ss audit`.
### Command with isolated HOME (clean state)
```bash
ENV_NAME="test-$(date +%s)"
docker exec $CONTAINER ssenv create "$ENV_NAME" --init
docker exec $CONTAINER ssenv enter "$ENV_NAME" -- ss status
# Cleanup when done:
docker exec $CONTAINER ssenv delete "$ENV_NAME" --force
```
Good for: testing `init`, `install`, `sync`, `uninstall` โ anything that modifies config/state.
### Multi-command sequence
```bash
docker exec $CONTAINER ssenv enter "$ENV_NAME" -- bash -c '
ss install runkids/demo-skills --track --force
ss list
ss sync
'
```
Always use `bash -c '...'` for multi-command sequences inside `ssenv enter`.
### Go tests
```bash
# All tests (unit + integration)
docker exec $CONTAINER bash -c 'cd /workspace && make test'
# Unit tests only
docker exec $CONTAINER bash -c 'cd /workspace && make test-unit'
# Integration tests only
docker exec $CONTAINER bash -c 'cd /workspace && make test-int'
# Specific test
docker exec $CONTAINER bash -c 'cd /workspace && go test ./tests/integration -run TestInit_Fresh -count=1'
# Specific package
docker exec $CONTAINER bash -c 'cd /workspace && go test ./internal/install/... -count=1'
```
Always `cd /workspace` before Go commands โ ssenv changes HOME which can break module resolution.
### Go tests with auth disabled
Token-resolution tests (`TestResolveToken`, `TestAuthEnv` in `internal/install`) need auth credentials removed:
```bash
docker exec $CONTAINER bash -lc '
eval "$(credential-helper --eval off)"
cd /workspace
go test ./internal/install -run "TestResolveToken|TestAuthEnv" -count=1
eval "$(credential-helper --eval on)"
'
```
## Web UI Dashboard
```bash
# Start (global mode)
docker exec $CONTAINER ui
# Trust audit
SAFEgrade B ยท trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
.devcontainer/bin/dev-servers
Gates applied: no_behavioural_pass.
0d9340b2ca90full audit observations/trust-audit/skill/runkids__skillshare-devcontainer.json ยท Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 0d9340b2ca90 | SAFE | B | 89 | first audit |
Questions
What does the Skillshare Devcontainer skill do?
๐ Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.
Is Skillshare Devcontainer safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Skillshare Devcontainer access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (0d9340b2ca90), read on 2026-10-08. The repository is watched, and a new audit runs when it changes โ this is the first audit.