container-host-aiops
Use this skill whenever the user needs to operate a single container host through the Docker Engine API, Portainer, or Podman — a one-shot host overview; container reads (list/inspect, logs tail, CPU/memory stats, top processes, restart summary); image reads (list, inspect with history, dangling, disk usage); volume reads (list, inspect, dangling); network reads (list, inspect); system reads (info, version, df disk-usage, recent events); Portainer stacks + endpoints; Compose-project rollups (list_compose_stacks, docker+podman); Podman pods (list_pods, podman-only); three flagship analyses — restart-loop RCA (crash-looping containers + cause/action), resource-pressure analysis (CPU/memory vs limits), and image & volume bloat (prune candidates + reclaimable bytes); and eight guarded writes (restart/stop/start/remove a container, prune images/volumes, update resource limits, recreate a Portainer stack). Always use this skill for "Docker host overview", "which containers are crash-looping", "restart loop", "why does this container keep restarting", "container CPU/memory usage", "docker logs", "which containers are near their limits", "resource pressure", "dangling images/volumes", "reclaim disk", "prune images", "stop/start/restart a container", "update a container's memory limit", "Portainer stacks", "compose stacks", "Podman pods" when the context is a Docker, Portainer, or Podman container host. Do NOT use when the target is a cluster orchestrator, a hypervisor, a storage appliance, a backup product, network device config, or OT/industrial equipment — route those to the appropriate other AIops-tools skill. This is for NON-orchestrator container hosts. Governed Docker/Portainer/Podman container-host operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). Exercised against a live Docker Engine 27.5.1 daemon (doctor, overview, the three flagship analyses, and a governed stop_container with audit + undo recorded); the Portainer and Podman API paths are covered by the mock suite only. See docs/VERIFICATION.md.
Rank
62
Safety
84
Downloads
1.4k
Updated
Oct 10, 2026
Version
0.11.3
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.4K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.4K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.11.3release · observed Sep 15, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:container-host-aiops- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:container-host-aiops` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/container-host-aiops before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-container-host-aiops/snapshot"
Documentation
CLAWHUB
150,520 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: container-host-aiops
slug: container-host-aiops
displayName: "Container Host AIops"
summary: "Governed Docker + Portainer container-host ops: reads, RCA analyses, guarded writes. 38 tools."
license: MIT
homepage: https://github.com/AIops-tools/Container-Host-AIops
tags: [aiops, mcp, governance, container-host]
description: >
Use this skill whenever the user needs to operate a single container host through the Docker Engine API, Portainer, or Podman — a one-shot host overview; container reads (list/inspect, logs tail, CPU/memory stats, top processes, restart summary); image reads (list, inspect with history, dangling, disk usage); volume reads (list, inspect, dangling); network reads (list, inspect); system reads (info, version, df disk-usage, recent events); Portainer stacks + endpoints; Compose-project rollups (list_compose_stacks, docker+podman); Podman pods (list_pods, podman-only); three flagship analyses — restart-loop RCA (crash-looping containers + cause/action), resource-pressure analysis (CPU/memory vs limits), and image & volume bloat (prune candidates + reclaimable bytes); and eight guarded writes (restart/stop/start/remove a container, prune images/volumes, update resource limits, recreate a Portainer stack).
Always use this skill for "Docker host overview", "which containers are crash-looping", "restart loop", "why does this container keep restarting", "container CPU/memory usage", "docker logs", "which containers are near their limits", "resource pressure", "dangling images/volumes", "reclaim disk", "prune images", "stop/start/restart a container", "update a container's memory limit", "Portainer stacks", "compose stacks", "Podman pods" when the context is a Docker, Portainer, or Podman container host.
Do NOT use when the target is a cluster orchestrator, a hypervisor, a storage appliance, a backup product, network device config, or OT/industrial equipment — route those to the appropriate other AIops-tools skill. This is for NON-orchestrator container hosts.
Governed Docker/Portainer/Podman container-host operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). Exercised against a live Docker Engine 27.5.1 daemon (doctor, overview, the three flagship analyses, and a governed stop_container with audit + undo recorded); the Portainer and Podman API paths are covered by the mock suite only. See docs/VERIFICATION.md.
installer:
kind: uv
package: container-host-aiops
argument-hint: "[container/image/volume id or describe your container-host task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["container-host-aiops","uvx"]},"optional":{"env":["CONTAINER_HOST_AIOPS_CONFIG","CONTAINER_HOST_AIOPS_MASTER_PASSWORD"]},"homepage":"https://github.com/AIops-tools/Container-Host-AIops","emoji":"🐳","os":["macos","linux"]}}
compatibility: >
Standalone, self-governed Docker + Portainer + Podman container-host operations. The governance harness (audit, policy, token/r_meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "container-host-aiops",
"version": "0.11.3",
"publishedAt": 1789451605853
}references/agent-guardrails.md
# Agent guardrails — running container-host-aiops with a smaller / local model
If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,
Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably
better results with a short system prompt. This page gives you one, and — more
importantly — tells you which guardrails you **no longer need to write**, because
the tool now enforces them itself.
The distinction matters. A guardrail in a prompt is a request. A guardrail in the
harness is a guarantee. Anything below that we could move into the harness, we did.
## Authorization is not this tool's job — decide it where it belongs
Whether a write should happen is your decision, or the account's. The tool does
not gate it — there is no read-only switch and no approval prompt to configure.
The two right places to control read vs write:
- **The account you connect with.** Give it a Docker socket mounted read-only,
or a Portainer account without write scope. A write then fails at the server,
which is the only place the permission actually lives — no skill-side flag can
be argued around by a model, but a revoked permission cannot be.
- **Your agent's system prompt.** If you want an observe-only session, tell the
model not to call the write tools (they are clearly tagged `[WRITE]`).
What the tool *does* guarantee is that you can always see what happened:
## What the tool enforces — do not waste prompt budget on these
| You might be tempted to prompt | Why you don't need to |
|---|---|
| "Log everything you do, over both MCP and the CLI" | Every operation is audited to `~/.container-host-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. |
| "Don't invent a value when a field is missing" | The Docker Engine omits keys it has nothing to say about — a created-but-never-started container has no `Status`, a dangling image has no `RepoTags`. Those come back as `null`, never as `""`. An id in particular is `null` when unknown, so a blank string is never mistaken for a real identifier. |
| "Tell me if the log was cut off" | `container_logs` returns `{"lines": [...], "returned": N, "limit": L, "truncated": true/false}`, and `system_events` the same shape. Truncation is measured — one extra line is requested from Docker — not guessed from a length coincidence. |
| "Preserve the ordering / tell me what's most urgent" | `restart_loop_rca` and `resource_pressure_analysis` rank worst-first and carry the measured number (restart count, exit code, CPU%, memory%) in each entry. Priority is in the payload, not implied by list position. |
| "Confirm before anything destructive" | `remove_container`, `prune_images` and `prune_volumes` require a `--dry-run`-able preview plus double confirmation at the CLI. |
| "Don't get stuck retrying" | The runaway guard trips references/capabilities.md
# container-host-aiops capabilities
> **38 MCP tools** (29 read, 9 write) across the Docker
> Engine API (unix socket or TCP), Portainer (management API + proxied Docker),
> and Podman (rootful/rootless socket — Docker-compat layer + libpod-native
> endpoints). Docker/Portainer/Podman API responses are mocked and need live
> verification.
Every tool is wrapped with the bundled `@governed_tool` harness (audit, policy,
token/runaway budget, undo, risk-tiers). All host-returned text is sanitized.
## Overview (read)
| Tool | Docker/Portainer path | Returns |
|------|-----------------------|---------|
| `overview` | `/info` + `/containers/json` + `/system/df` | host summary: platform, server version, container state rollup, disk headline |
## Containers (read)
| Tool | Path | Returns |
|------|------|---------|
| `list_containers` | `/containers/json?all=` | containers bucketed by state (running/exited/…), compact rows |
| `inspect_container` | `/containers/{id}/json` | full inspect (config, state, mounts, network) |
| `container_logs` | `/containers/{id}/logs?tail=N` | last N log lines (demuxed stdout+stderr) |
| `container_stats` | `/containers/{id}/stats?stream=false` | CPU% + memory% snapshot (Docker's own delta formula) |
| `container_top` | `/containers/{id}/top` | processes running inside the container |
| `container_restart_summary` | `/containers/json` + per-container inspect | restart count + exit code + OOM, worst-first |
## Images (read)
| Tool | Path | Returns |
|------|------|---------|
| `list_images` | `/images/json` | images (tags, size, dangling), largest first |
| `inspect_image` | `/images/{id}/json` + `/images/{id}/history` | inspect + build history (layers, sizes, commands) |
| `dangling_images` | `/images/json?filters=dangling` | untagged images + reclaimable bytes |
| `image_disk_usage` | `/system/df` (Images) | total, shared, reclaimable image bytes |
## Volumes (read)
| Tool | Path | Returns |
|------|------|---------|
| `list_volumes` | `/volumes` | named volumes (driver, mountpoint, scope) |
| `inspect_volume` | `/volumes/{name}` | one volume in detail |
| `dangling_volumes` | `/system/df` (Volumes, RefCount=0) | unreferenced volumes + reclaimable bytes |
## Networks (read)
| Tool | Path | Returns |
|------|------|---------|
| `list_networks` | `/networks` | networks bucketed by driver |
| `inspect_network` | `/networks/{id}` | driver, IPAM subnet/gateway, attached containers |
## System (read)
| Tool | Path | Returns |
|------|------|---------|
| `system_info` | `/info` | container/image counts, storage driver, kernel, resources |
| `system_version` | `/version` | version, API version, Go version, components |
| `system_df` | `/system/df` | disk-usage breakdown: images, containers, volumes, build cache |
| `system_events` | `/events?since=&until=` | recent daemon events, rolled up by type+action |
## Stacks — Portainer (read; requires a portainer target)
| Tool | Path | Returns |
|------|------|---------|
|references/cli-reference.md
# container-host-aiops CLI reference
> Covers the Docker Engine API (unix socket or TCP), Portainer (management API), and
> Podman (rootful/rootless socket — Docker-compat + libpod). The Docker path has been
> exercised against a live daemon; Portainer and Podman responses are mock-validated
> only — see `docs/VERIFICATION.md`.
## Setup
```bash
container-host-aiops init # interactive wizard (Docker/Podman socket or Portainer)
container-host-aiops doctor # verify config, secrets, connectivity
# Docker/Podman: GET /version · Portainer: GET /api/endpoints
container-host-aiops doctor --skip-auth # config/secret checks only (no connectivity)
```
## Secrets (Portainer only)
```bash
container-host-aiops secret set <target> [--value <token>] # store a Portainer token (hidden prompt if no --value)
container-host-aiops secret list # list target names with a stored token
container-host-aiops secret rm <target> # delete a stored token
container-host-aiops secret migrate # import a legacy plaintext .env
container-host-aiops secret rotate-password # re-encrypt under a new master password
```
## Overview
```bash
container-host-aiops overview [--target <name>] # one-shot host health
```
## Containers
```bash
container-host-aiops container list [--running] # all states, or only running
container-host-aiops container inspect <id>
container-host-aiops container logs <id> [--tail 200]
container-host-aiops container stats <id> # CPU% / memory%
container-host-aiops container top <id> # processes inside
container-host-aiops container restarts # restart-count + exit-code summary
```
## Images / Volumes / Networks
```bash
container-host-aiops image list [--all]
container-host-aiops image inspect <id> # + build history
container-host-aiops image dangling
container-host-aiops image disk-usage
container-host-aiops volume list
container-host-aiops volume inspect <name>
container-host-aiops volume dangling
container-host-aiops network list
container-host-aiops network inspect <id>
```
## System
```bash
container-host-aiops system info
container-host-aiops system version
container-host-aiops system df # disk-usage breakdown
container-host-aiops system events [--since 3600] [--type container]
```
## Stacks
```bash
container-host-aiops stack endpoints # Portainer target
container-host-aiops stack list # Portainer target
container-host-aiops stack detail <stack_id> # Portainer target
container-host-aiops stack compose # Compose projects by label (docker OR podman) + health rollup
```
## Pods (Podman target)
```bash
container-host-aiops pod list # Podman pods (libpod); errors on docker/portainer
```
## Analyses (flAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/container-host-aiops",
"sourceUrl": "https://clawhub.ai/zw008/skills/container-host-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T13:19:49.871Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-container-host-aiops/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-container-host-aiops/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T13:19:49.871Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.4K downloads",
"href": "https://clawhub.ai/zw008/container-host-aiops",
"sourceUrl": "https://clawhub.ai/zw008/container-host-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T13:19:49.871Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.11.3",
"href": "https://clawhub.ai/zw008/container-host-aiops",
"sourceUrl": "https://clawhub.ai/zw008/container-host-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-15T05:53:25.853Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-container-host-aiops/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-container-host-aiops/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.11.3",
"description": "container-host-aiops 0.11.3 - Removed the sample file skill-card.md from the repository. - No user-facing functionality changes in this release.",
"href": "https://clawhub.ai/zw008/container-host-aiops",
"sourceUrl": "https://clawhub.ai/zw008/container-host-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-15T05:53:25.853Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
