Devcontainer Airlock — AI skill for Claude Code
Secure, layered devcontainers for AI coding agents: the agents work in a workbench with no GitHub token and no ssh key, code runs in isolated containers with no network, and a broker and an egress pro.
How to install Devcontainer Airlock
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open ivan-pinatti-labs/devcontainer-airlock and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Devcontainer Airlock does
Secure, layered devcontainers for AI coding agents: the agents work in a workbench with no GitHub token and no ssh key, code runs in isolated containers with no network, and a broker and an egress proxy guard the way out. Rootless podman.
Alternatives in AI
- Open Science — Open Science Desktop — local-first, model-agnostic AI research workbench for macOS, Windows & Linux 1.5k ★
- Phantom — An AI co-worker with its own computer 1.3k ★
- Openclaw Dashboard — 🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents 654 ★
README
devcontainer-airlock
[](LICENSE.md) [](https://github.com/ivan-pinatti-labs/devcontainer-airlock/issues) [](https://github.com/sponsors/ivan-pinatti) [](https://github.com/ivan-pinatti-labs/devcontainer-airlock) [](https://github.com/ivan-pinatti-labs/devcontainer-airlock/forks) [](https://coderabbit.ai)
Secure, layered devcontainers for AI coding agents.
Coding agents (Claude Code, Codex) and their editor extensions are powerful and trusted with a lot: a GitHub token, an ssh key, the network, and every hook, test and `npm install` they run. devcontainer-airlock splits that into layers by what each one is trusted with:
- A workbench per agent, where you and that agent work. It holds no GitHub token, no ssh key and no other agent's login, and it has no direct network and no container runtime.
- L2 containers for hooks, tests, package installs and throwaway binaries. They get the working tree and nothing else: no network, no credentials.
- Beside them, a GitHub broker that holds the token and runs an allowlist
of
ghcommands, an ssh-agent that holds the key, and an egres
Related Skills
Dev Sandbox
Run untrusted code and AI agents in isolated Podman containers with krun microVMs. Network control, SSH, Privo
Brood Box
10+ Run AI coding agents (Claude Code, Codex, OpenCode) inside hardware-isolated microVMs with snapshot isolat
Modal Claude Agent SDK Python
This package wraps the Claude Agent SDK to execute AI agents in secure, scalable Modal containers. It provides
Homelabhero
Turn a fresh LXC into an AI homelab command center. One command installs Claude Code + a web UI, preloaded wit
Aiterm MCP
One persistent MCP terminal your AI drives — and launches other coding agents (Codex/Grok/Composer) into. SSH,
Nanoclaw Skills
Official skill marketplace for NanoClaw — a lightweight AI assistant that runs agents in isolated containers.
Related Agents
Infra Lan
Internal-network specialist. Switches, APs, internal resolvers (dual Pi-hole-class), internal DNS for SSH alia
Cloud Troubleshooter
Use when inspecting, diagnosing, or validating the actual state of running systems — pods, services, logs, clo
Platform Implementer
Use to implement one approved WP- covering CI/CD, containers, deployment manifests, configuration and secret r