docker agent Runs YAML-Defined AI Agents From Any OCI Registry. Its README Says Nothing on Sandboxing
Software / explainer
docker agent Runs YAML-Defined AI Agents From Any OCI Registry. Its README Says Nothing on Sandboxing
Docker Engineering's Apache-2.0 plugin ships pre-installed in Docker Desktop 4.63, but the repository shows no tagged release and a telemetry notice.

Docker Engineering's docker-agent repository is a command-line plugin that runs AI agents defined in a YAML file, and it was at 3.8k GitHub stars, 485 forks and 10,709 commits on main on October 8, 2026. It is Apache-2.0 licensed and installs as docker agent, with Docker Desktop 4.63 or later shipping it pre-installed.
The README describes it as an "AI Agent Builder and Runtime by Docker Engineering." What follows is what the README and the docs landing page say, what neither page says, and which questions a team should have answered before pointing it at a real repository.
What docker agent does
The README's pitch is declarative: teams of specialised agents that "delegate tasks automatically", defined in a file that can be versioned and shared. An agent is a YAML entry with a model, a description, an instruction and a list of toolsets. The README's own example is a root agent on openai/gpt-5-mini with the docker:duckduckgo tool attached as an MCP reference.
Tools come from the Model Context Protocol, the open standard for connecting AI applications to external systems. The README says docker agent accepts "any MCP server (local, remote, or Docker-based)", and the docs landing page adds servers from Docker's MCP catalog.
| Command | What it does |
|---|---|
docker agent run | Runs the default agent |
docker agent new | Generates an agent interactively |
docker agent run agent.yaml | Runs your own config |
docker agent run myorg/agent:tag | Pulls and runs an agent from an OCI registry |
Providers listed are OpenAI, Anthropic, Gemini, AWS Bedrock, Mistral, xAI and Docker Model Runner for local models, "and more". At least one provider API key is needed unless the local runner is used.
Sharing agents through a registry
The distinctive move is distribution. Agents can be pushed to "any OCI registry" and pulled with one command, the same registry mechanism that already carries container images. The docs landing page lists the interfaces as a terminal UI, a headless CLI, an HTTP API, an MCP server, A2A and OCI distribution, plus an OpenAI-compatible chat endpoint.
For a team that already runs a private registry, that is a short path from a working agent to a shared one. It also means the thing being pulled is a prompt, a model choice and a set of tool permissions written by someone else.

What the README does not say
The README does not mention sandboxing or execution isolation. The docs landing page does link pages titled "Sandbox Mode" and "Permissions", but their contents were not part of the page we read, so this piece cannot say what they promise.
Three other gaps are worth stating plainly.
- The Releases section on the repository page was empty when we read it, so there is no tagged version number to quote.
- The docs site warns that it tracks the
mainbranch and "may describe unreleased features", and points to docs.docker.com for stable documentation. - The README states "We collect anonymous usage data to improve the tool." The landing page lists a Telemetry page without describing an opt-out.
Who is better off, and who should wait
If your agents are a prompt, one model and two read-only tools, the YAML file is a small, reviewable artefact, and a registry tag is a reasonable way to version it. The project builds itself with the tool: the contributing section runs docker agent run ./golang_developer.yaml.
If an agent can write files or run shell commands, the missing sandbox answer is the sticking point. A pulled agent such as myorg/agent:tag carries instructions you did not write. Read the YAML, read the toolsets, and read the Permissions page before running a tag from outside your organisation.
The next concrete thing to watch is the first tagged release. Until the Releases section has an entry, the version that the docs describe and the version that you install from Homebrew with brew install docker-agent can differ. Related coverage on agent tooling: OpenAI's Decisions API beta and Strands Decider and Cloudflare's security-audit skill.
Sources
More in Software
- 01REA Hits 15.7k Stars as an MCP Toolkit That Lets AI Agents Reverse-Engineer SoftwareThe MIT-licensed project wraps Ghidra, Hopper and IDA in 134 agent tools, and its own README says process capture is not a sandbox.
- 02God of War: Chains of Olympus Runs in a Browser Through Recompilation, Not EmulationThe psp-web-recomp repository translates PSP executables to WebAssembly and reports 60 fps, but only two games from one studio work.
- 03Margaret Hamilton, Who Led Apollo's Flight Software Team, Dies at 90MIT says her team's priority-driven design let the Apollo 11 landing proceed through a 1202 alarm; the code she signed off in 1969 is on GitHub.
- 04PhotoCraft, a Rust Photoshop Clone With 14,600 Stars, Round-Trips 307 of 309 PSD Test FilesThe ArtCraft Team's MIT or Apache-2.0 editor calls itself early alpha and says it is not yet a replacement for daily professional work.