container-layer — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited container-layer (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Build a reproducible, cached environment overlay for ephemeral containers using a Dockerfile-like spec.
The container resets every session, but your environment shouldn't. This skill:
Containerfile (Dockerfile subset) that declares your environmentuv shim that captures ad-hoc installs back into the Containerfile# Environment variables
ENV KEY=value
# Shell commands (including package installs)
RUN apt-get install -y foo # system packages
RUN uv pip install pandas numpy # Python packages (preferred)
RUN pip install requests # also works
# Fetch files from URLs or GitHub
FETCH https://example.com/file.tar.gz /dest/path
FETCH github:user/repo /dest/path # latest tarball
FETCH github:user/repo@ref /dest/path # specific ref
# Set working directory for subsequent RUN commands
WORKDIR /some/path
# Declare paths to include in the cached layer snapshot
# (auto-detected for FETCH destinations and pip/uv installs)
SNAPSHOT /additional/path/to/capture
# Ignored (Dockerfile compat, no-op here):
# FROM, EXPOSE, CMD, ENTRYPOINT, LABEL, ARG, VOLUME, USER, SHELLfrom scripts.containerfile import ContainerLayer
layer = ContainerLayer(
containerfile_path="/path/to/Containerfile",
cache_repo="oaustegard/claude-container-layers", # GitHub repo for release assets
gh_token="...",
)
# Try cache first, fall back to full build
layer.restore_or_build()Or via CLI:
python -m scripts.cli restore /path/to/Containerfile --repo user/cache-repoDecompose a heavy environment into named layers, each cached independently. Compose them in order on session start so most-changed bits don't invalidate stable bits.
from scripts.containerfile import compose
compose(
containerfile_paths=[
"layers/Containerfile", # name='base' (always-on)
"layers/Containerfile.scientific", # name='scientific'
"layers/Containerfile.mojo", # name='mojo'
],
cache_repo="user/cache-repo",
)Each layer gets its own cache release tag layer-<name>-<hash> so retention policies (keep last N) and cache invalidation operate per-name.
Default layer names are derived from the Containerfile path:
Containerfile → baseContainerfile.scientific → scientificlayers/Containerfile.X → XCLI equivalent:
python -m scripts.cli compose \
layers/Containerfile \
layers/Containerfile.scientific \
layers/Containerfile.mojo \
--repo user/cache-repoIf filename doesn't derive cleanly, pass --name NAME:PATH per layer:
python -m scripts.cli compose \
--name base:weird-named-file.txt \
--name mojo:other-file.txt \
weird-named-file.txt other-file.txtbuild / restore / hash / inspect accept --name:
python -m scripts.cli restore Containerfile.mojo --name mojo
# Cache tag becomes 'layer-mojo-<hash>' instead of 'layer-<hash>'.
# Omit --name to keep the old back-compat tag for existing callers.After building, install the shim to capture future installs:
source /path/to/container-layer/scripts/uv_shim.sh /path/to/ContainerfileNow uv pip install foo both installs the package AND appends RUN uv pip install foo to your Containerfile.
After modifying the Containerfile:
layer.build_and_push() # Execute, snapshot, uploadRead scripts/containerfile.py for the parser/executor and scripts/layer_cache.py for the GitHub Releases caching logic. The cache key is a SHA-256 of the Containerfile contents — any change triggers a rebuild.
The skill expects these environment variables (or pass as constructor args):
GH_TOKEN — GitHub token with repo scope (for releases)This skill is designed to be invoked from a boot script. Example Containerfile:
# Skills
FETCH github:oaustegard/claude-skills /mnt/skills/user
# Python environment
RUN uv pip install --system pandas numpy requests
# Path config
RUN echo '/mnt/skills/user/remembering' > /usr/local/lib/python3.12/dist-packages/muninn-remembering.pth
# Custom setup
ENV MY_VAR=hello
WORKDIR /home/claude~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.