Docker Open-Sources Its Agent Skills: One SKILL.md to Teach Every Coding Agent Containers
Docker has published docker/skills, an Apache-2.0 collection of reusable skills that teach AI coding agents to build, test, debug and harden containerized apps — installable into Claude Code, Codex, Cursor, Copilot and Gemini CLI with one command.
Docker has quietly shipped one of the more practical open-source releases of the week: docker/skills, a public, Apache-2.0-licensed collection of “skills” for AI coding agents. The premise is simple and slightly subversive. Instead of every developer re-explaining to Claude Code, Codex or Cursor how to structure a Dockerfile, wire up Compose, or run an agent inside an isolated sandbox, Docker itself now maintains that knowledge as portable, versioned packages that any compliant agent can discover automatically. The repository describes its mission plainly: skills that help agents “build, test, debug, and optimize containerized apps with consistent, reusable workflows.”
What’s actually in the box
The collection is organized around Docker’s product surface rather than around generic prompting tips, and each skill is a self-contained SKILL.md directory that triggers from its own description — there is no master entry-point skill to load first.
- Dockerfile & Build —
docker-project-foundationscovers initializing and structuring a Dockerized project;docker-build-strategiescovers efficient, secure, optimized image builds. - Docker Compose —
docker-compose-patternsencodes patterns for robust, maintainable multi-container configurations. - Docker Sandboxes —
docker-sandboxes-lifecycle,docker-sandboxes-network-credentials, plus experimentaldocker-sandboxes-env(declarativesbxenv.yamlenvironments) anddocker-sandboxes-kits(authoring, signing and composing reusable sandbox kits). - Docker Agent —
docker-agent-config,docker-agent-runanddocker-agent-deploywalk the full lifecycle of Docker’s own agent runtime, fromagent.yamlto serving, OCI-registry distribution and CI regression evaluation. - Cross-product guardrails —
docker-destructive-guardrails, a policy that makes agents confirm irreversible or destructive Docker operations before running them.
The repo also publishes explicit ordering guidance — load docker-project-foundations before docker-build-strategies when a project has no Docker setup yet, docker-agent-config before docker-agent-run before docker-agent-deploy — which reads a lot like a curriculum for machines.
One command, every agent
The most interesting design choice is distribution. The skills CLI installs into “every major coding agent (Claude Code, Codex, Cursor, GitHub Copilot, Gemini CLI, OpenCode, Windsurf, Cline, Kiro, and more)”:
npx skills add docker/skills
Non-interactive variants exist for CI, and each major agent also has a native plugin path — /plugin marketplace add docker/skills in Claude Code, codex plugin marketplace add docker/skills for Codex, gemini extensions install for Gemini CLI. Docker Sandboxes gets a first-class sbx skills add flow, with a shared skill store that provisions installed skills into sandboxes on their next start.
Release discipline is unusually serious for a tooling repo. The main branch is a rolling development channel; tags such as v0.3.0 (released September 23) are immutable, reviewed snapshots that teams can pin for reproducible installs. Version 0.3.0 moved the installation documentation into Docker’s official Docs and retired the repo’s standalone Hugo site, while tightening the development defaults in docker-project-foundations: application and optional Postgres host access now bind to loopback, and unauthenticated Redis stays confined to the Compose network. Version 0.2.0, one day earlier, added OpenSSF Scorecard publication, DCO enforcement on every non-merge commit, and deterministic skill-content risk checks — supply-chain hygiene for knowledge packages.
Why it matters more than it looks
The timing is the story. AI coding agents have become the primary way container configuration gets written, and the failure modes are well known: agents hallucinate deprecated base images, invent latest tags, publish ports that should never be exposed, or happily run docker system prune in the wrong terminal. The industry’s answer so far has been emergent — the agent-skills convention (a SKILL.md directory discovered through standard paths) that Anthropic popularized and that other vendors adopted. Docker adopting the same convention, as the authoritative owner of the domain knowledge, is a meaningful upgrade in the chain of trust: the guidance an agent receives about Docker can now come from Docker, versioned and reviewed, instead of from the statistical average of every Dockerfile ever written.
It also signals where Docker sees its moat in the AI era. The company’s navigation now leads with AI-native products — Docker Sandboxes for isolated agent execution, an AI Governance product for governing agents across an organization, an MCP Enterprise Gateway, the Gordon assistant, and Model Runner for local LLM inference. Skills are the connective tissue: they teach agents to use all of it correctly. A developer whose agent has learned docker-sandboxes-network-credentials is one prompt away from adopting the sandboxing product.
Caveats worth stating
Traction is still early — the repo sits at roughly 115 stars and a handful of contributors since its creation in March 2026, and two of the most ambitious skills (docker-sandboxes-env, docker-sandboxes-kits) are explicitly flagged experimental, with schemas that may still change. Plugin-marketplace updates are gated by each agent’s own release cadence, so teams pinning via npx skills and those installing plugins can drift onto different versions. And skills are guidance, not enforcement — the guardrails skill makes destructive operations ask first, which only helps if the agent actually loads it.
But as a direction, this is hard to argue with. The unit of reuse in AI-assisted development is shifting from libraries and snippets to curated, machine-readable expertise — and vendors who own a domain are going to ship that expertise themselves. Docker publishing reviewed, versioned, cross-agent skills under a permissive license is a template other platform vendors will likely copy. For teams running coding agents against containerized workloads today, npx skills add docker/skills is a two-minute upgrade with a real chance of making the next generated Dockerfile less exciting than the last one.