infrastructure/skills/gnupg/SKILL.md
GnuPG encryption and signing tools for GPG agent forwarding. Use when working with GPG, encryption, signing, or the gnupg layer.
npx skillsauth add overthinkos/overthink-plugins gnupgInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
| Property | Value |
|----------|-------|
| Install files | layer.yml (packages only) |
RPM: gnupg2 · PAC: gnupg · DEB: gnupg — full cross-distro parity. Note: gnupg is also in the debian distro's bootstrap package set (see /ov-distros:debian) because downstream layers need gpg --dearmor at build time.
# image.yml
my-image:
layers:
- gnupg
Typically used as part of the agent-forwarding composition layer rather than directly.
Provides gpg, gpgconf, gpg-agent, gpg-connect-agent binaries inside the container. When combined with SSH/GPG agent forwarding (ov shell, ov start direct mode), the container's GPG uses the host's agent for private key operations (signing, decryption) via a forwarded socket.
The container has its own keyring (public keys must be imported separately with gpg --import). No host keyring is mounted — only the agent socket is forwarded.
Part of agent-forwarding composition layer, used in 27 application images including: arch-ov, fedora-ov, nvidia, jupyter, ollama, openclaw, immich, comfyui, selkies-desktop, and all other non-base images.
/ov-distros:agent-forwarding -- metalayer that includes gnupg + direnv + ssh-client/ov-coder:direnv -- environment variable loading from .envrc/.secrets/ov-infrastructure:ssh-client -- OpenSSH client for SSH agent forwarding/ov-build:secrets -- ov secrets gpg commands: key management (import-key, export-key), GPG agent setup (setup), health check (doctor), and .secrets file management/ov-core:shell -- agent socket forwarding happens at ov shell invocation time/ov-core:service -- agent forwarding in ov start direct modeUse when the user asks about:
gnupg layer/ov-image:layer — layer authoring reference (layer.yml schema, task verbs, service declarations)/ov-eval:eval — declarative testing (eval: block, ov eval image, ov eval live)development
Claude Code multi-agent support in Overthink — sub-agents, dynamic workflows, and agent teams, and how each drives the existing `ov eval` disposable beds to test and verify. MUST be invoked before authoring or invoking an ov sub-agent / dynamic workflow / agent team, wiring agent-lifecycle hooks, or asking "which primitive should drive the R10 beds?".
tools
Mounts a virtiofs share tagged `workspace` at /workspace inside a VM guest via a systemd .mount unit. Use when a kind:vm entity shares a host directory into the guest and you need it auto-mounted (and re-mounted at every boot).
development
MUST be invoked before any work involving: the `kind: android` schema kind, a `target: android` deploy, the `apk:` layer package format (installing Android apps declaratively), AndroidDeployTarget, an in-pod emulator OR a remote/physical adb-endpoint device, or nested `pod → android` deployment. The first-class Android device + app surface that sits above `ov eval adb`/`appium`.
tools
Use when committing, branching, pushing, merging, tagging, creating PRs, or approving/merging PRs with gh — the feat/-branch, R10-gated, never-force-push landing workflow across the main repo + the plugins submodule + image/<distro> submodules. Covers sync-to-upstream, branch/worktree pruning, the fork+PR path for contributors without write access, and cross-repo @github landing order.