by mensfeld
Give the agent a machine. Just not yours. Each AI coding agent gets its own isolated machine with root, Docker, and systemd - active defense detects and stops threats automatically.
# Add to your Claude Code skills
git clone https://github.com/mensfeld/coiLast scanned: 9/30/2026
{
"issues": [
{
"file": "README.md",
"line": 32,
"type": "remote-install",
"message": "Install command (remote install script piped to a shell — review the source before running): \"curl -fsSL https://raw.githubusercontent.com/mensfeld/coi/master/install.sh | ba\"",
"severity": "low"
}
],
"status": "PASSED",
"scannedAt": "2026-09-30T10:18:41.218Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how coi compares with popular alternatives.
coi is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by mensfeld. Give the agent a machine. Just not yours. Each AI coding agent gets its own isolated machine with root, Docker, and systemd - active defense detects and stops threats automatically. It has 732 GitHub stars.
Yes. coi passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/mensfeld/coi" and add it to your Claude Code skills directory (see the Installation section above).
coi is primarily written in Go. It is open-source under mensfeld on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh coi against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Give the agent a machine. Just not yours.
coi runs your AI coding tool (Claude Code, Codex, opencode, pi, omp) inside its own isolated Linux system: a full-OS container with root access, systemd, Docker, and the freedom to install anything. The agent works like it would on a real server, but it cannot touch your host, cannot see your credentials, and if it does something dangerous, coi pauses or kills the container on its own.
One command drops you into a coding session. Your project is mounted, file permissions just work, and your SSH keys, tokens, and environment variables never enter the container unless you explicitly say so.

# 1. Install
curl -fsSL https://raw.githubusercontent.com/mensfeld/coi/master/install.sh | bash
# 2. Build the base image (first time only, ~5-10 min)
coi build
# 3. Start coding, from any project directory
cd your-project
coi shell
Your agent now runs in an isolated container with your project at /workspace, correct file ownership (no more chown), Docker and gh available inside, and every workspace change saved back to the host. It has no access to your host SSH keys, environment variables, or credentials.
Requires Linux with Incus. macOS works too, via Colima/Lima; see macOS Setup.
chown dance..env, and host environment variables never enter the container unless you mount or forward them.main.coi health.A profile is a reusable, named container setup: image, tool, resource limits, mounts, network mode, build scripts, and AI-agent instructions bundled into one template you apply with a single flag.
coi shell --profile rust-dev # spin up your Rust environment, ready to go
coi profile create rust-dev # scaffold a new profile, then edit its config.toml
coi profile list # see what you have
A profile is just a config.toml:
# ~/.coi/profiles/rust-dev/config.toml
inherits = "hardened" # optional: build on another profile
[container]
image = "coi-default"
persistent = true # keep the box (and its installed packages) between sessions
[tool]
name = "claude"
[limits]
cpu = "4"
memory = "8GiB"
[network]
mode = "restricted" # open / restricted / allowlist
Profiles support inheritance, ship AI-agent context files, and can carry their own build scripts, so "my hardened Python box with these limits and these tools" becomes one word. A built-in hardened preset locks a session down for untrusted code. See the Profiles wiki page for the full reference, the hardened preset, and the schema.
Pick one in config or a profile:
# ~/.coi/config.toml or ./.coi/config.toml
[tool]
name = "claude" # or "codex", "opencode", "pi", "omp"
permission_mode = "bypass" # run autonomously ("bypass") or ask first ("interactive")
Aider and Cursor are on the way. See the Supported Tools wiki page for per-tool auth, and Container Lifecycle and Sessions for running two tools in the same persistent container.
coi shell # interactive AI session (Claude Code by default)
coi run -- npm test # run any command in the sandbox (streams output, propagates exit code)
coi run --prompt-name nightly # run the agent headlessly from a predefined prompt
coi top # per-container CPU/memory/IO, resolved to workspace + alias
coi monitor # real-time security dashboard
coi list --all # active containers + saved sessions
coi attach # attach to a running session
coi audit # stream the JSONL threat-event log (pipe into a SIEM or jq)
coi shutdown / coi kill # stop or force-kill containers
coi clean # remove stopped containers and orphaned resources
Drop a .coi/config.toml in any repo to auto-configure coi for that project, so teams share one image, network mode, and limits. Run coi <command> --help for any command. To run agents unattended with headless prompts and cron, see Headless Orchestration.
The README is the pitch; the wiki is the manual. Everything lives there in full:
hardened preset, inheritance, and the JSON schemacoi run --prompt, predefined prompts, and croncoi health diagnoses your setup end-to-endIncus (a modern LXD fork) gives you system containers, which behave like lightweight VMs (a real init system and full OS userspace) while sharing the host kernel, so they start in seconds, instead of Docker's application containers. That means one clean isolation layer running a full OS with native Docker inside, correct file ownership on the host by default, and no Docker Desktop, no vendor lock-in, and no opaque VM nesting. It is Linux-nativ