Our review
Provisions ephemeral Incus containers (pu boxes) to run commands, CI builds, or capture evidence on a clean, reproducible Linux host.
Strengths
- Total isolation: nothing runs on the user's local machine.
- Reproducible environment via NixOS with flakes.
- Simple lifecycle: create, list, connect, scp, destroy.
- Handles network failure with detection and automatic recreation.
Limitations
- Depends on underlying Incus infrastructure; box unavailable if daemon is down.
- Requires pu tool installed and configured on the host.
- Boxes with no outbound network require manual probing or a detection script.
Use pu whenever a task needs to run on a clean, reproducible Linux host isolated from the local machine (CI, builds, evidence capture, bug reproduction).
Avoid pu if the task requires direct local resource access (devices, local network) or if the environment must persist beyond the session.
Security analysis
SafeThe skill describes a legitimate container management tool with no destructive, exfiltrating, or obfuscated actions. Commands are well-defined and standard (create, connect, destroy, copy files). No risky patterns like remote script execution or disabling safety measures are present.
No concerns found
Examples
pu create mybuild && pu connect mybuild -- 'nix run github:owner/app && cp result /tmp/out && scp -F ~/.pu-state/mybuild/ssh_config mybuild:/tmp/out /tmp/' && pu destroy mybuildpu create evidence-box && pu connect evidence-box -- 'uname -a; nix-shell -p ffmpeg --run "ffmpeg -f x11grab -video_size 1280x720 -i :99 -frames 1 /tmp/screen.png"' && scp -F ~/.pu-state/evidence-box/ssh_config evidence-box:/tmp/screen.png ./evidence.png && pu destroy evidence-boxpu connect mybox -- 'timeout 15 curl -sS -o /dev/null -w "%{http_code}\n" https://api.github.com' || { echo 'no egress — recreating'; pu destroy mybox; pu create mybox; }name: pu
description: >-
Provision and drive a pu box — an Incus container used as
a clean Linux host for CI, builds, and evidence capture. Use when you need to
run something on a fresh remote box instead of the user's machine: nix run a
build, run CI against a real host, capture screenshots/video off-machine, or
reproduce on a pristine environment. Covers create/connect/scp/destroy, running
remote commands, copying artifacts back, and the no-egress failure mode.
Triggers on "pu box", "spin up a box", "run this on a box", "ephemeral host",
"pu create/connect/destroy".
pu — on-demand Incus boxes
pu hands out Linux containers. Each box is a clean NixOS host with Nix
- flakes, reachable over SSH through
pu's own proxy. Use one whenever work should run off the user's machine — a CI run, anix runbuild, evidence capture — so nothing local is at risk and the environment is reproducible. A box can be short-lived (spin up, use,destroy) or kept around long-term — the lifetime is yours to choose.
Lifecycle
pu create "$host" # create; writes ~/.pu-state/$host/ssh_config
pu list # NAME + LOCATION (the physical host it landed on)
pu connect "$host" # interactive ssh
pu connect "$host" -- CMD # run CMD on the box and return
pu destroy "$host" # tear down — always do this when finished
Name is positional. Pick a descriptive, collision-free name (e.g. app-pr-42-evidence).
pu connect is the reliable way in — it reads ~/.pu-state/$host/ssh_config itself, so it
needs no setup. Bare ssh "$host" works only if you've added Include ~/.pu-state/*/ssh_config to ~/.ssh/config (optional, often not set up); otherwise use
pu connect, or pass the config explicitly: ssh -F ~/.pu-state/$host/ssh_config "$host".
Run commands on the box
# One-shot
pu connect "$host" -- 'uname -a'
# Background a long-running server (nohup so it survives the SSH session)
pu connect "$host" -- "nohup nix run github:owner/app -- --port 8080 >/tmp/app.log 2>&1 &"
# Poll until it's healthy
pu connect "$host" -- 'until curl -sf http://127.0.0.1:8080/health; do sleep 2; done'
The box has its own loopback — bind servers to 127.0.0.1 on whatever port you
like; there is no clash with anything on the user's machine.
Copy artifacts back
pu connect is SSH, so scp works against the box's generated config:
scp -F ~/.pu-state/"$host"/ssh_config "$host":/tmp/out.png /tmp/out.png
Failure mode: no outbound network
A box occasionally lands on a host with broken egress — DNS and even raw-IP TCP
time out, so nix run github:... hangs on "Resolving timed out". This is
host-specific, not your fault. Probe egress first; if it fails, destroy and
recreate (a fresh box usually lands on a healthy host):
pu connect "$host" -- 'timeout 15 curl -sS -o /dev/null -w "%{http_code}\n" https://api.github.com' \
|| { echo "no egress — recreating"; pu destroy "$host"; pu create "$host"; }
If retries keep landing on dead hosts, capture diagnostics for the admin — the box's
LOCATION from pu list, /etc/resolv.conf, ip route, and a /dev/tcp connect
test to the gateway and to a raw IP — and hand them over (e.g. a gist).
Next.js App Router Expert
Development
A skill that turns Claude into a Next.js App Router expert.
README Generator
Development
Creates professional and comprehensive README.md files for your projects.
API Documentation Writer
Development
Generates comprehensive API documentation in OpenAPI/Swagger format.