Flagged: sudo usage. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by mensfeld · Codex Skill · ★ 728
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is code-on-incus safe to install? View the security audit →
code-on-incus () Isolated machines for AI coding agents - with active defense. COI gives each AI agent its own machine - a full system container with root access, systemd, Docker, and the ability to install anything. Agents work like they would on a real server: run services, manage packages, use cron - without touching your actual system. Files stay correctly owned, no permission hacks needed. Your credentials stay on the host. SSH keys, environment variables, and Git tokens are never exposed to AI tools unless you explicitly mount them. If something goes wrong, COI catches it - reverse shells, credential scanning, data exfiltration - and pauses or kills the container automatically. No manual intervention needed. Built by developers, for developers who run AI agents and want to know what those agents are doing. Not a product, not a startup - a tool that does the job. Who this is for -
| Stars | 728 |
| Forks | 62 |
| Language | Go |
| Category | Codex Skill |
| License | MIT |
| Quality Score | 69.4646781679776/100 |
| Open Issues | 21 |
| Last Updated | 2026-09-22 |
| Created | 2026-01-07 |
| Platforms | claude-code, codex, docker, go |
| Est. Tokens | ~22k |
These tools work well together with code-on-incus for enhanced workflows:
Looking for a code-on-incus alternative? If you're comparing code-on-incus with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Unified CLI for running AI coding agents in isolated containers. Includes built-in local metrics collection, H
Persistent Linux workspaces for agentic development.
Safely run OpenCode, Codex, Claude Code with full permissions.
Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.
AI writes code. This automates everything else · 24 plugins · 49 agents · 44 skills · for Claude Code, OpenCod
MCP-NixOS - Model Context Protocol Server for NixOS resources
Explore other popular codex skill tools:
code-on-incus is Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. It is categorized as a Codex Skill with 728 GitHub stars.
code-on-incus is primarily written in Go. It covers topics such as agentic-ai, ai-tools, anthropic.
You can find installation instructions and usage details in the code-on-incus GitHub repository at github.com/mensfeld/code-on-incus. The project has 728 stars and 62 forks, indicating an active community.
code-on-incus is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to code-on-incus on Agent Skills Hub include vibepod-cli, container, code-container. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: