What an extension can do on your machine, five checks you can make before you install one — and how RepoGates answers them for your AI agent.
The short answer. A Docker Desktop extension runs with your permissions, and Docker says so itself. Nobody can tell you one is safe. What you can tell in five minutes is whether it is trustworthy enough to install: whether it is in Docker's Marketplace, who publishes it, what it declares it will put on your machine, whether you can read its source, and whether its age fits its popularity.
An extension is a Docker Hub image with up to three parts: a tab in the dashboard, a backend that runs inside the Docker Desktop VM, and host binaries that Docker Desktop copies onto your machine. Docker's SDK security page states the consequence: extensions "are executed with the same permissions as the Docker Desktop user", can run any Docker command, run their binaries and read the files you can read — and they "are not restricted to execute binaries that they list in the host section". The backend's compose file can mount the Docker socket, which is full control of the engine, and the containers an extension creates are hidden from the dashboard and the CLI by default.
No malicious extension has been publicly reported as of 18 September 2026. What has been reported is the platform's own history: Docker fixed remote code execution through a crafted extension description in 2022 and again in 2024 (CVE-2023-0625, CVE-2024-8695), through crafted publisher and additional URLs in 2024 (CVE-2024-8696), and access-token theft through an extension icon URL in 2023 (CVE-2023-5166). In 2026 it added a notice that extensions are not audited, turned extensions off by default in 4.74.0, and paused new Marketplace submissions on 16 June. The threat model has every date and source.
1. Is it in Docker's Marketplace? Docker's index lists 50 extensions and cannot grow while submissions are paused, so an image that is not in it is sideloaded or private by definition. Since Docker Desktop 4.31.0 such an image installs only after you turn off the setting that allows Marketplace extensions alone — leave it on unless you know exactly why you are turning it off.
2. Who publishes it, and since when? The publisher's Docker Hub page shows a verified-publisher or official badge, if it has one, and when the account joined. Thirty-nine of the fifty listed extensions come from a publisher with no such badge, Tailscale, Lens and ngrok among them, so its absence on an established listing is ordinary. On a namespace that joined last month, it is not.
3. What does it declare it will install? The extension's metadata.json names its host binaries and its VM backend, and the backend's compose file says whether it mounts the Docker socket, joins the host network, adds capabilities or runs privileged. Twenty-one of the fifty listed extensions declare host binaries and twelve mount the socket, so the question is whether what it declares fits what it is for. After an install, docker extension ls shows which ones put binaries on the host.
4. Can you read its source? An image may name its source repository in its labels, or link one from its listing. Twenty-seven of the fifty listed extensions declare one. Without it, the only way to see what the backend or the binaries do is to take the image apart yourself.
5. Do its age and pulls fit? The youngest repository in the Marketplace is over two years old. A new repository with a large pull count, a name close to a known extension, or a listing link with an unusual scheme (the class behind CVE-2024-8696) is worth stopping for.
RepoGates scores a Docker Desktop extension on 11 published checks, the five above among them, reading the Hub record, Docker's index and the image's labels, metadata.json and compose file from the registry — a few kilobytes, with no image pulled. A declared GitHub source is scored through the 22 repository checks on the same pass. It answers through the MCP server and the Claude Code plugin, not in the browser: your agent can ask check_repo with the Docker Desktop platform before it suggests an extension, and the plugin's hook reads docker extension install before Claude Code runs it. On all 50 listed extensions, measured 18 September 2026: 50 PASS, 0 REVIEW, 0 BLOCK — the ordinary Marketplace shapes are notes on a listed, established extension and findings on an unlisted or new one. library/nginx, an image that is no extension at all, comes back REVIEW: the sideloaded shape the checks are graded for.
The plugin's hook sees Bash tool calls in Claude Code and nothing else: it does not see a command you type in your own terminal or one another agent runs. An extension installed from Docker Desktop's own Extensions tab is not a shell line and happens in a native window no browser extension sees, so nothing of ours sees it. The checks read what an image declares, not what its binaries or its backend do; Docker's own words say the declared binaries are not a limit, and reading the image is a deep scan that is decided and not yet built. A verdict is about the image the tag named when it was asked for. A PASS means every check that could run, ran, and none fired — never a claim that the code inside was inspected.
Can RepoGates check an extension I install from Docker Desktop's Extensions tab? No. That install is Docker Desktop's own fetch, from a native window no browser extension sees, and it is not a shell line. The check runs when your agent asks the MCP server, or when the Claude Code plugin sees docker extension install on a command line.
Does Docker review Marketplace extensions for security? Not in the sense the word suggests. Docker paused manual review on 9 January 2024; after that a submission passed automated validation of its labels and metadata schema. Docker's own words: Marketplace extensions are not subject to a full security audit, and extensions installed outside the Marketplace have not been reviewed at all.
Has a malicious Docker Desktop extension been found? None has been publicly reported as of 18 September 2026. The risk is what Docker documents an extension can do, and the vulnerabilities Docker has fixed in how extensions are displayed and installed.
Set up the Claude Code plugin Plans
The checks run on the paid plans, through the MCP server and the Claude Code plugin. Numbers on this page: all 50 extensions in Docker's Marketplace index, measured 18 September 2026; Docker's documentation, release notes and security announcements (docs/33).
RepoGates also checks what your AI agent installs from the VS Code Marketplace and Claude Code plugins and skills, and GitHub repositories in the browser.