Edge Copy setup link
Skill evidence / devcontainers-best-practices
Skill profile

devcontainers-best-practices

Expert reference for the Dev Container ecosystem.

What this skill does for you

Expert reference for the Dev Container ecosystem. Consult this skill whenever the user is setting up a dev container, configuring or debugging devcontainer.json, working in a Docker-based development environment, or asking about dev containers, GitHub Codespaces, DevPod, or Zed : even if they don't say "devcontainer" explicitly. Covers the full Dev Container spec, schema validation, tool-specific behaviors and limitations (VS Code, Cursor, Zed, Codespaces, CodeSandbox, Podman), Features and Templates (choosing, authoring, publishing), lifecycle scripts, environment variables, port forwarding, multi-container setups, and official best practices from containers.dev and devcontainers.github.io. Also use when the user is confused by container behavior that differs between tools, wants to write or publish a custom Feature, or needs to validate or debug a devcontainer.json.

Quoted from the skill description in the pinned source

Who made it

Publisherafonsograca
Installs303as of Sep 27, 2026

Use it with Edge

Set up Edge for me: read getedge.cc/SKILL.md and follow it. Then use Edge to load the devcontainers-best-practices skill from afonsograca/devcontainers-best-practices.

Paste it into Claude, ChatGPT, Codex or Cursor.

Or read the skill source first.

Security evidence

Security state at 2026-09-30: reviewed. State definitions. This records static evidence for this revision; live load eligibility is checked again.

3 static scans, 0 counted findings. The listed scanners recorded the results shown for this package revision.

ScannerDateResultFindings
Edge static checks2026-09-27Pass0
Cisco skill-scanner2026-09-27Pass0
Semgrep Edge rules2026-09-27Pass0

Static scans check the code, not how well the skill works.

Scanner scope, raw findings and mirrored provider records

Edge static checks (Edge-run): edge-static/1.0.1. Scope: Static patterns for remote execution, credentials with network sends, obfuscation, prompt overrides, hidden Unicode, binaries and persistence. Revision: 62c3be484bd72a4b43bddc7af1f5960dce432e9e. Raw findings: . Counted findings: .

Cisco skill-scanner (Edge-run): cisco-skill-scanner/2.1.0. Scope: Local static, YARA, pipeline and behavioral analyzers; no LLM or AI Defense analysis. Revision: 62c3be484bd72a4b43bddc7af1f5960dce432e9e. Raw findings: . Counted findings: .

Semgrep Edge rules (Edge-run): semgrep/1.178.0+edge-rules.c15016a36fd3+offline-v1. Scope: Six Edge-authored static rules with Semgrep CE; offline execution and metrics disabled. Semgrep-maintained rules excluded. Revision: 62c3be484bd72a4b43bddc7af1f5960dce432e9e. Raw findings: . Counted findings: .

Source and licence

Repository
https://github.com/afonsograca/devcontainers-best-practices
Pinned skill file
View source at revision
Revision
62c3be484bd72a4b43bddc7af1f5960dce432e9e
Package hash
sha256:7a0119f9790a97a0940a8d11cd135ead5c6e0f6e64e4d5cad31f086bb8e1b32c
Licence
MIT