Atlas / Skills / runkids / Skillshare Devcontainer

Skillshare DevcontainerSAFE

skills/runkids/skillshare-devcontainer

๐Ÿ“š Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
โ€”
Hosts
โ€”
License
MIT
Stars
2,749
01

Overview

๐Ÿ“š Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.

Read from source at commit 0d9340b2ca90OBSERVED ยท 2026-10-08
02

What it tells the agent

The instruction file, verbatim from the audited commit โ€” this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: skillshare-devcontainer
description: >-
  Run CLI commands, tests, and debugging inside the skillshare devcontainer.
  Use this skill whenever you need to: execute skillshare CLI commands for
  verification, run Go tests (unit or integration), reproduce bugs, test new
  features, start the web UI, or perform any operation that requires a Linux
  environment. All CLI execution MUST happen inside the devcontainer โ€” never
  run skillshare commands on the host. If you are about to use Bash to run
  `ss`, `skillshare`, `go test`, or `make test`, stop and use this skill
  first to ensure correct container execution.
argument-hint: "[command-to-run | task-description]"
metadata: 
  targets: [claude, universal]
---

Execute CLI commands and tests inside the devcontainer. The host machine is macOS but the project binary is Linux โ€” running CLI commands on the host will silently produce wrong results or fail. This skill prevents that mistake.

Before acting, run `python3 scripts/ai-context.py testing` and follow that topic. The topic is the source of truth for repository execution boundaries and test rules; this skill retains the interactive workflow and command recipes.

## When to Use This

- Running `ss` / `skillshare` commands for verification
- Running `go test`, `make test`, `make check`
- Reproducing a bug report
- Testing a feature you just implemented
- Starting the web UI dashboard
- Any command that needs the skillshare binary or Go toolchain

## When NOT to Use This

- Editing source code (do that on host via Read/Edit tools)
- Running `git` commands (git works on host)
- Running `make fmt`, `make lint` (host-safe Go toolchain commands; no container needed)
- E2E test runbooks โ†’ use `cli-e2e-test` skill instead (it handles ssenv isolation)

## Architecture: Two Layers of Isolation

```
Host (macOS)
  โ””โ”€ Devcontainer (Linux, Debian-based)
       โ”œโ”€ Default HOME: /home/developer (persistent volume)
       โ”œโ”€ Source: /workspace (bind-mount of repo root)
       โ””โ”€ ssenv environments: ~/.ss-envs/<name>/ (isolated HOME dirs)
```

**Devcontainer** = Linux environment with Go, git, pnpm, air (hot-reload). Source code is at `/workspace` (bind-mount of the host repo). The `ss` / `skillshare` wrapper auto-builds from source on every invocation โ€” **no manual `make build` needed**. Edit code on the host, then immediately `docker exec` to run it; the change is picked up automatically.

**ssenv** = Isolated HOME directories within the devcontainer. Each env gets its own `~/.config/skillshare/`, `~/.claude/`, etc. Use ssenv when you need a clean state (testing init, install, sync) without polluting the container's default HOME.

## Zero-Rebuild Workflow

Source code is bind-mounted into the container at `/workspace`. The `ss` wrapper runs `go build` transparently on every invocation:

1. Edit files on host (Read/Edit tools)
2. `docker exec $CONTAINER ss <command>` โ€” picks up your changes instantly
3. No `make build`, no restart, no rebuild step

This also applies to `go test` โ€” tests always compile against the latest source. The Web UI backend uses `air` for hot-reload (same zero-rebuild experience).

## Entering the Devcontainer

The quickest way โ€” one command builds, initialises, and enters the shell:

```bash
make devc           # build + init + interactive shell (one step)
make devc-up        # start only (no shell)
make devc-down      # stop
make devc-restart   # restart + re-run start-dev.sh
make devc-reset     # full reset (remove volumes), then `make devc` to re-init
make devc-status    # show container status
```

Works with **or without** VS Code โ€” `make devc` handles the full lifecycle autonomously.

### Programmatic access (for `docker exec` workflows)

```bash
CONTAINER=$(docker compose -f .devcontainer/docker-compose.yml ps -q skillshare-devcontainer 2>/dev/null)
```

If `$CONTAINER` is empty, tell the user:
> Devcontainer is not running. Start it with `make devc-up`.

Then verify the binary:
```bash
docker exec $CONTAINER bash -c \
  '/workspace/.devcontainer/ensure-skillshare-linux-binary.sh && ss version'
```

## Running Commands

### Simple command (uses container's default HOME)

```bash
docker exec $CONTAINER ss <command> [flags]
```

Good for: `ss version`, `ss status`, `ss list`, `ss check`, `ss audit`.

### Command with isolated HOME (clean state)

```bash
ENV_NAME="test-$(date +%s)"
docker exec $CONTAINER ssenv create "$ENV_NAME" --init
docker exec $CONTAINER ssenv enter "$ENV_NAME" -- ss status
# Cleanup when done:
docker exec $CONTAINER ssenv delete "$ENV_NAME" --force
```

Good for: testing `init`, `install`, `sync`, `uninstall` โ€” anything that modifies config/state.

### Multi-command sequence

```bash
docker exec $CONTAINER ssenv enter "$ENV_NAME" -- bash -c '
  ss install runkids/demo-skills --track --force
  ss list
  ss sync
'
```

Always use `bash -c '...'` for multi-command sequences inside `ssenv enter`.

### Go tests

```bash
# All tests (unit + integration)
docker exec $CONTAINER bash -c 'cd /workspace && make test'

# Unit tests only
docker exec $CONTAINER bash -c 'cd /workspace && make test-unit'

# Integration tests only
docker exec $CONTAINER bash -c 'cd /workspace && make test-int'

# Specific test
docker exec $CONTAINER bash -c 'cd /workspace && go test ./tests/integration -run TestInit_Fresh -count=1'

# Specific package
docker exec $CONTAINER bash -c 'cd /workspace && go test ./internal/install/... -count=1'
```

Always `cd /workspace` before Go commands โ€” ssenv changes HOME which can break module resolution.

### Go tests with auth disabled

Token-resolution tests (`TestResolveToken`, `TestAuthEnv` in `internal/install`) need auth credentials removed:

```bash
docker exec $CONTAINER bash -lc '
  eval "$(credential-helper --eval off)"
  cd /workspace
  go test ./internal/install -run "TestResolveToken|TestAuthEnv" -count=1
  eval "$(credential-helper --eval on)"
'
```

## Web UI Dashboard

```bash
# Start (global mode)
docker exec $CONTAINER ui

# 
03

Trust audit

SAFEgrade B ยท trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

MEDIUMInventory / provenance ยท inv.symlink ยท CWE-1104
.devcontainer/bin/dev-servers
.devcontainer/bin/dev-servers
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-10-08 ยท audit v0.4.1 ยท source sha 0d9340b2ca90full audit observations/trust-audit/skill/runkids__skillshare-devcontainer.json ยท Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-080d9340b2ca90SAFEB89first audit
05

Questions

What does the Skillshare Devcontainer skill do?

๐Ÿ“š Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.

Is Skillshare Devcontainer safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Skillshare Devcontainer access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (0d9340b2ca90), read on 2026-10-08. The repository is watched, and a new audit runs when it changes โ€” this is the first audit.

Advertisement