Skopeo
Inspects, copies, signs and deletes container images between registries and storage backends — without a daemon and without pulling the image to run it.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| OCI Image, Runtime and Distribution | transfers |
- Interfaces
clicontainer- Install
-
brew
skopeo - Invoke
skopeo inspect docker://<registry>/<image>:<tag>- Consumes
- oci-image
- Emits
- json, oci-image
- Runtime
- Needs network Deterministic Writes Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Daemonless is the point for agents. In a sandbox with no Docker socket, this still works.
- Website
- https://github.com/podman-container-tools/skopeo
- Repository
- https://github.com/podman-container-tools/skopeo
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-09-17
- Stars
- 11235 · last commit 2026-09-17
- Companies hiring
- 1 — distinct companies whose job postings name this tool, Q3-2026. A demand signal, not a deployment count.
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.