Coder Workspaces
v1.5.5Manage Coder workspaces and AI coding agent tasks via CLI. List, create, start, stop, and delete workspaces. SSH into workspaces to run commands. Create and monitor AI coding tasks with Claude Code, Aider, or other agents.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description, required binary (coder), and required env vars (CODER_URL, CODER_SESSION_TOKEN) all align with managing a Coder deployment via the official CLI. Nothing requested appears unrelated to the stated functionality.
Instruction Scope
SKILL.md is instruction-only and confines actions to the coder CLI (list/start/stop/ssh/tasks). This is in-scope. Note: the skill assumes the agent will run coder ssh or coder tasks commands which can execute arbitrary commands inside remote workspaces; the SKILL.md claims those commands run in isolated Coder workspaces rather than on the host — you should verify that isolation in your Coder deployment before granting broad tokens.
Install Mechanism
No install spec or remote downloads; instruction-only skill with links to official Coder docs. Low install risk.
Credentials
Only CODER_URL and CODER_SESSION_TOKEN are required, which is appropriate. However, a session token grants actions on the Coder instance; consider using a token with limited scope, a dedicated service account, and secure storage (OpenClaw config).
Persistence & Privilege
always is false and there are no install scripts or persistent changes. The platform default allows autonomous invocation; combined with a session token this means the skill (when invoked by the agent) can perform actions against your Coder instance without additional prompts. Consider agent confirmation policies for destructive operations (e.g., delete).
Assessment
This skill appears coherent with its purpose, but take these precautions before installing:
- Only provide CODER_SESSION_TOKEN that you trust: prefer a least-privilege token or dedicated service account rather than a personal admin token.
- Store the token securely (OpenClaw config) and rotate/revoke it if you stop using the skill.
- Verify that your Coder deployment actually enforces workspace isolation (so remote commands cannot reach your host or other sensitive resources).
- Test read-only commands (e.g., coder list, coder whoami) first to confirm behavior and connectivity.
- Require confirmation or limit autonomous actions in your agent policy for destructive commands (delete, restart) to avoid accidental or automated destructive changes.
- Install the coder CLI only from your Coder instance or the official docs to avoid tampered binaries.Like a lobster shell, security has layers — review code before you run it.
Runtime requirements
🏗️ Clawdis
Binscoder
EnvCODER_URL, CODER_SESSION_TOKEN
latest
Coder Workspaces
Manage Coder workspaces and AI coding agent tasks via the coder CLI.
Note: Commands execute within isolated, governed Coder workspaces — not the host system.
Setup
Before using coder CLI, configure authentication:
-
Install the CLI from Coder CLI docs
-
Set environment variables:
export CODER_URL=https://your-coder-instance.com export CODER_SESSION_TOKEN=<your-token> # Get from /cli-auth -
Test connection:
coder whoami
Workspace Commands
coder list # List workspaces
coder list --all # Include stopped
coder list -o json # JSON output
coder start <workspace>
coder stop <workspace>
coder restart <workspace> -y
coder delete <workspace> -y
coder ssh <workspace> # Interactive shell
coder ssh <workspace> -- <command> # Run command in workspace
coder logs <workspace>
coder logs <workspace> -f # Follow logs
AI Coding Tasks
Coder Tasks runs AI agents (Claude Code, Aider, etc.) in isolated workspaces.
Creating Tasks
coder tasks create --template <template> --preset "<preset>" "prompt"
- Template: Required. List with
coder templates list - Preset: May be required. Try without first. If creation fails with "Required parameter not provided", get presets with
coder templates presets list <template> -o jsonand use the default. If no default, ask user which preset.
Managing Tasks
coder tasks list # List all tasks
coder tasks logs <task-name> # View output
coder tasks connect <task-name> # Interactive session
coder tasks delete <task-name> -y # Delete task
Task States
- Initializing: Workspace provisioning (timing varies by template)
- Working: Setup script running
- Active: Agent processing prompt
- Idle: Agent waiting for input
Troubleshooting
- CLI not found: See Coder CLI docs
- Auth failed: Verify CODER_URL and CODER_SESSION_TOKEN are set, then run
coder login - Version mismatch: Reinstall CLI from your Coder instance
More Info
Comments
Loading comments...
