Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/jvgomg/podkit/dockergit clone --depth 1 https://github.com/jvgomg/podkitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.03271 |
| Opus 5 | $0.00000 | $0.01636 |
| Sonnet 5 | $0.00000 | $0.00654 |
| Haiku 4.5 | $0.00000 | $0.00327 |
Grade A, and why
docker scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 217 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Docker Image
Guidance for working on the Docker image and related infrastructure. See AGENTS.md for project overview.
podkit is distributed as a Docker image at ghcr.io/jvgomg/podkit. See docs/getting-started/docker.md for user documentation.
Key Files
| Purpose | Path |
|---|---|
| Dockerfile | packages/podkit-docker/Dockerfile |
| Entrypoint script | packages/podkit-docker/entrypoint.sh |
| Entrypoint tests (bats) | packages/podkit-docker/test/entrypoint.bats |
| Image smoke test | packages/podkit-docker/test/image-smoke.sh, Dockerfile.smoke |
| Docker Compose example | packages/podkit-docker/docker-compose.yml |
| Daemon Compose example | packages/podkit-docker/docker-compose.daemon.yml |
| CI workflow | .github/workflows/docker.yml |
Testing the entrypoint
Shell-level tests of entrypoint.sh (command routing, command-parity, PUID/PGID,
--device/--path injection, su-exec privilege drop) run via bats. These are
the Integration depth in the test taxonomy
(doc-053's rollout stage 2). They stub the external binaries on PATH, so they
need no container and no real sync.
bun run test --filter @podkit/docker # via turbo (also runs in `bun run quality`)
cd packages/podkit-docker && bun run test # directly
bats is a devDependency of @podkit/docker; bun install provides it.
Image smoke test (E2E · host-docker-image · none)
Builds a podkit image for the native arch and asserts it boots and is internally
consistent: --version + doctor run through the image, command-parity holds
against the running binary, ffmpeg is present, both binaries + the entrypoint are
executable. Catches the "image drifted from the CLI" class.
bun run test:smoke --filter @podkit/docker
# or: bash packages/podkit-docker/test/image-smoke.sh
Requires docker and limactl (Lima builder VM). It builds the linux CLI
binary via @podkit/device-testing#build:linux-binary (turbo-cached, Lima
builder), compiles podkit-daemon in the same VM, then builds and exercises the
image. It is deliberately not in the test/quality gate — it is heavy and
host-specific.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 217 lines · 0 tokens per session scan A 5ce0f88b3d37
docker is an agent published in the GitHub repository jvgomg/podkit (39 stars, last pushed 8d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 3,271 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-01.
Other agents, from other repositories
AGENTS
Use uv for every Python command in this repo. Do not use bare python, pip, poetry, or conda.
CONTEXT
Agent "CONTEXT" from TheRealSavi/iOpenPod, covering iopenpod and language.
accessibility-reviewer
Reviews Android Compose / iOS SwiftUI changes for screen-reader and reduce-motion regressions. Use proactively after any UI change, before opening a PR that touches ui/ or iosApp/ Views, or when asked to check TalkBack/VoiceOver accessibility. A core user base is blind and visually impaired — accessibility is treated…
domain
How the engineering skills should consume this repo's domain documentation when exploring the codebase.
triage-labels
The skills speak in terms of five canonical triage roles. This file maps those roles to the actual label strings used in this repo's issue tracker.
issue-tracker
Issues and PRDs for this repo live as GitHub issues. Use the gh CLI for all operations.