{
  "data": {
    "similar": [
      {
        "grade": "AA",
        "json": "https://www.anchorterminal.com/tools/openai-agents-sdk.json",
        "name": "OpenAI Agents SDK",
        "score": 86.2,
        "shared": [
          "agent.framework",
          "agent.multi-agent",
          "agent.durable",
          "agent.mcp-client"
        ],
        "slug": "openai-agents-sdk"
      },
      {
        "grade": "A",
        "json": "https://www.anchorterminal.com/tools/pydantic-ai.json",
        "name": "Pydantic AI",
        "score": 83.7,
        "shared": [
          "agent.framework",
          "agent.multi-agent",
          "agent.durable",
          "agent.mcp-client"
        ],
        "slug": "pydantic-ai"
      },
      {
        "grade": "A",
        "json": "https://www.anchorterminal.com/tools/microsoft-agent-framework.json",
        "name": "Microsoft Agent Framework",
        "score": 82.2,
        "shared": [
          "agent.framework",
          "agent.multi-agent",
          "agent.durable",
          "agent.mcp-client"
        ],
        "slug": "microsoft-agent-framework"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/google-adk.json",
        "name": "Agent Development Kit (ADK)",
        "score": 74.7,
        "shared": [
          "agent.framework",
          "agent.multi-agent",
          "agent.durable",
          "agent.mcp-client"
        ],
        "slug": "google-adk"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/agno.json",
        "name": "Agno",
        "score": 72.8,
        "shared": [
          "agent.framework",
          "agent.multi-agent",
          "agent.durable",
          "agent.mcp-client"
        ],
        "slug": "agno"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/langgraph.json",
        "name": "LangGraph",
        "score": 70.6,
        "shared": [
          "agent.framework",
          "agent.multi-agent",
          "agent.durable",
          "agent.mcp-client"
        ],
        "slug": "langgraph"
      }
    ],
    "tool": {
      "slug": "docker-agent",
      "name": "Docker Agent",
      "vendor": "Docker",
      "vendorUrl": "https://docker.github.io/docker-agent/",
      "kind": "framework",
      "category": "frameworks",
      "summary": "Docker's open-source runtime for building and running AI agents from YAML or HCL files, formerly cagent. It runs as a `docker agent` CLI plugin with a terminal UI, headless mode, HTTP, MCP and A2A servers, and a Go library.",
      "url": "https://www.anchorterminal.com/tools/docker-agent",
      "markdownUrl": "https://www.anchorterminal.com/tools/docker-agent.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/docker-agent.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/docker-agent.json",
      "repo": "https://github.com/docker/docker-agent",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "oci",
          "name": "docker/docker-agent"
        },
        {
          "registry": "go",
          "name": "github.com/docker/docker-agent"
        }
      ],
      "auth": "none",
      "authNotes": "No account of its own. Model keys come from provider environment variables, `--env-from-file`, an account login or Docker Model Runner for local models. The servers it starts take an optional Bearer token (`--auth-token`), which HTTP MCP requires on a non-loopback address.",
      "pricing": "free",
      "pricingNotes": "Free and Apache-2.0, with nothing to buy for the CLI. You pay your model provider, or nothing with a local model through Docker Model Runner. Cloud sandboxes need a Docker login and weren't priced in this check.",
      "priceSummary": "Free · OSS",
      "where": "library",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the README (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4029,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docker.github.io/docker-agent/",
      "llmsTxt": "https://docker.github.io/docker-agent/llms.txt",
      "capabilities": [
        "agent.framework",
        "agent.multi-agent",
        "agent.mcp-client",
        "agent.durable"
      ],
      "tags": [
        "framework",
        "open-source",
        "go",
        "local",
        "free",
        "no-card",
        "llms-txt",
        "docker"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 76.5,
        "grade": "BB",
        "agentReady": true,
        "rank": 30,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 81,
          "maintenance": 96,
          "payments": 60,
          "reliability": 88,
          "schema": 90,
          "security": 70,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 88,
            "points": 17.6,
            "reason": "Read with the local-software lines, because the owner runs it. Binaries for macOS, Linux and Windows on amd64 and arm64 on every GitHub release, a Homebrew formula at 1.149.0, a Docker Hub image, and Docker Desktop 4.63 and later bundle it. Go 1.27 is the stated minimum for source builds (20). The ci workflow runs on every push to main with about 1,350 test files and an e2e directory. Nine of the last ten push runs passed, including the newest on 8 October, with one failure that morning (25). 25 open issues and 17 open pull requests, most labelled and answered, with 27 issues closed and 32 opened in the 30 days to 8 October. Open reports include a race in `transfer_task` (#4156), a hand-off dropped silently (#4242) and `edit_file` editing the first of several matches (#3929) (20). The changelog has Breaking Changes sections, but those changes ship in minor releases (1.114.0, 1.133.0 and 1.137.0 since July) and the major version has never moved (8). 1.149.0, past 1.0 (15)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 90,
            "points": 14.63,
            "reason": "Framework reading. agent-schema.json in the repository is a JSON Schema for the whole config, and the chat server serves its OpenAPI document at /openapi.json. We found no OpenAPI document for the native /api server and didn't check the Go package reference (22). llms.txt on docker.github.io/docker-agent and on docs.docker.com (10). The docs say when to use the API server and when the chat server, compare six ways to pass large input, and state that permissions aren't a security boundary (17). Configs are parsed strictly, unknown fields fail to load with a hint, and safety fields accept four named modes only (13). An examples directory, a troubleshooting page of common errors and documented HTTP status codes for the API. We found no exit-code reference for `run --exec` (13). A dated CHANGELOG.md and a numbered config schema, now version 16, with migration on load (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 81,
            "points": 13.16,
            "reason": "Framework reading, scored on what an agent with MCP needs. The README's agent with one MCP server is eight lines of YAML and no code, with deferred toolsets and a code mode (23). Budgets cap cost, tokens and time, tool results are bounded to 50 KiB since 1.148.0, and context is compacted, but `max_iterations` is unlimited and no budget applies unless declared (16). `--json` writes one NDJSON event per message, tool call and error, and the API documents 404, 409, 413 and 502 responses. No exit-code reference found for `run --exec` (14). Sessions resume from SQLite, the event stream replays from a sequence number, follow-ups accept an `Idempotency-Key`, and read-only and destructive tool annotations drive the safety modes (18). One binary and a model key or a local model are enough to start. The library is Go only (10)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 70,
            "points": 12.25,
            "reason": "Framework reading. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. Usage telemetry is on by default, with a notice on first start and `TELEMETRY_ENABLED=false` to stop it. The docs say command events include positional arguments, which for `run` and `exec` can include prompts, and error text (12). Four safety modes with allow, ask and deny rules, a default that asks for anything not read-only, `--exec` rejecting unapproved calls, `--sandbox` for a Docker Sandboxes VM, and HTTP MCP defaulting to loopback and `restricted`. A run's `--listen` control plane has no built-in authentication (19). The docs treat skill files and third-party configs as untrusted and restrict URI schemes against prompt injection, with no dedicated guidance page (10). Hooks for audit logging and approval decisions, opt-in OpenTelemetry traces, NDJSON transcripts and a session database (14). SECURITY.md with a 72-hour acknowledgement, a valid security.txt on docker.com, two advisories published on GitHub with fixed versions, and CodeQL and zizmor in CI. No paid bounty, and we saw no CVE identifiers on the advisories (15). SOC 2 isn't scored for a framework."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 60,
            "points": 7.5,
            "reason": "No payment protocol (0). Read with the self-hosted rule. The CLI is free and Apache-2.0 with nothing to buy, so 20, 20 and 20 on the last three lines. It installs without an account and runs local models through Docker Model Runner. Cloud sandboxes need a Docker login and weren't priced in this check."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 96,
            "points": 8.4,
            "reason": "v1.149.0 published on 2026-10-07 (30). 45 tagged releases in the 90 days to 8 October, v1.111.0 to v1.149.0 (20). 25 open issues, most labelled by area and answered, 27 closed in the last 30 days and 17 open pull requests. We didn't measure reply times (21). The Homebrew formula was at 1.149.0 and the Docker Hub image was updated on 8 October, and the Go module ships from the same tags (15). Dependabot, CodeQL, zizmor and actions pinned to commit SHAs, with CI passing on main (10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 80,
            "points": 7,
            "note": "editorial 75, provenance 84",
            "reason": "Apache-2.0 (30). The telemetry page lists what's collected and warns that arguments and error text can carry secrets or personal data. It doesn't name the endpoint (api.docker.com, per the source), link Docker's privacy policy or give a retention period (15). Breaking changes are dated in the changelog and one renamed variable kept a fallback for one release, with no written deprecation policy, and the changelog says frozen config schema versions aren't maintained long-term (10). Telemetry is disclosed in the README, the docs and a first-start notice, with an opt-out variable (20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Framework reading, scored on what an agent with MCP needs. The README's agent with one MCP server is eight lines of YAML and no code, with deferred toolsets and a code mode (23). Budgets cap cost, tokens and time, tool results are bounded to 50 KiB since 1.148.0, and context is compacted, but `max_iterations` is unlimited and no budget applies unless declared (16). `--json` writes one NDJSON event per message, tool call and error, and the API documents 404, 409, 413 and 502 responses. No exit-code reference found for `run --exec` (14). Sessions resume from SQLite, the event stream replays from a sequence number, follow-ups accept an `Idempotency-Key`, and read-only and destructive tool annotations drive the safety modes (18). One binary and a model key or a local model are enough to start. The library is Go only (10).",
            "maintenance": "v1.149.0 published on 2026-10-07 (30). 45 tagged releases in the 90 days to 8 October, v1.111.0 to v1.149.0 (20). 25 open issues, most labelled by area and answered, 27 closed in the last 30 days and 17 open pull requests. We didn't measure reply times (21). The Homebrew formula was at 1.149.0 and the Docker Hub image was updated on 8 October, and the Go module ships from the same tags (15). Dependabot, CodeQL, zizmor and actions pinned to commit SHAs, with CI passing on main (10).",
            "payments": "No payment protocol (0). Read with the self-hosted rule. The CLI is free and Apache-2.0 with nothing to buy, so 20, 20 and 20 on the last three lines. It installs without an account and runs local models through Docker Model Runner. Cloud sandboxes need a Docker login and weren't priced in this check.",
            "reliability": "Read with the local-software lines, because the owner runs it. Binaries for macOS, Linux and Windows on amd64 and arm64 on every GitHub release, a Homebrew formula at 1.149.0, a Docker Hub image, and Docker Desktop 4.63 and later bundle it. Go 1.27 is the stated minimum for source builds (20). The ci workflow runs on every push to main with about 1,350 test files and an e2e directory. Nine of the last ten push runs passed, including the newest on 8 October, with one failure that morning (25). 25 open issues and 17 open pull requests, most labelled and answered, with 27 issues closed and 32 opened in the 30 days to 8 October. Open reports include a race in `transfer_task` (#4156), a hand-off dropped silently (#4242) and `edit_file` editing the first of several matches (#3929) (20). The changelog has Breaking Changes sections, but those changes ship in minor releases (1.114.0, 1.133.0 and 1.137.0 since July) and the major version has never moved (8). 1.149.0, past 1.0 (15).",
            "schema": "Framework reading. agent-schema.json in the repository is a JSON Schema for the whole config, and the chat server serves its OpenAPI document at /openapi.json. We found no OpenAPI document for the native /api server and didn't check the Go package reference (22). llms.txt on docker.github.io/docker-agent and on docs.docker.com (10). The docs say when to use the API server and when the chat server, compare six ways to pass large input, and state that permissions aren't a security boundary (17). Configs are parsed strictly, unknown fields fail to load with a hint, and safety fields accept four named modes only (13). An examples directory, a troubleshooting page of common errors and documented HTTP status codes for the API. We found no exit-code reference for `run --exec` (13). A dated CHANGELOG.md and a numbered config schema, now version 16, with migration on load (15).",
            "security": "Framework reading. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. Usage telemetry is on by default, with a notice on first start and `TELEMETRY_ENABLED=false` to stop it. The docs say command events include positional arguments, which for `run` and `exec` can include prompts, and error text (12). Four safety modes with allow, ask and deny rules, a default that asks for anything not read-only, `--exec` rejecting unapproved calls, `--sandbox` for a Docker Sandboxes VM, and HTTP MCP defaulting to loopback and `restricted`. A run's `--listen` control plane has no built-in authentication (19). The docs treat skill files and third-party configs as untrusted and restrict URI schemes against prompt injection, with no dedicated guidance page (10). Hooks for audit logging and approval decisions, opt-in OpenTelemetry traces, NDJSON transcripts and a session database (14). SECURITY.md with a 72-hour acknowledgement, a valid security.txt on docker.com, two advisories published on GitHub with fixed versions, and CodeQL and zizmor in CI. No paid bounty, and we saw no CVE identifiers on the advisories (15). SOC 2 isn't scored for a framework.",
            "transparency": "Apache-2.0 (30). The telemetry page lists what's collected and warns that arguments and error text can carry secrets or personal data. It doesn't name the endpoint (api.docker.com, per the source), link Docker's privacy policy or give a retention period (15). Breaking changes are dated in the changelog and one renamed variable kept a fallback for one release, with no written deprecation policy, and the changelog says frozen config schema versions aren't maintained long-term (10). Telemetry is disclosed in the README, the docs and a first-start notice, with an opt-out variable (20)."
          },
          "sources": [
            {
              "what": "repository main branch (cloned), README, LICENSE, go.mod, agent-schema.json",
              "url": "https://github.com/docker/docker-agent",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog",
              "url": "https://github.com/docker/docker-agent/blob/main/CHANGELOG.md",
              "seen": "2026-10-08"
            },
            {
              "what": "security policy",
              "url": "https://github.com/docker/docker-agent/blob/main/SECURITY.md",
              "seen": "2026-10-08"
            },
            {
              "what": "repository statistics, releases and CI runs on main (GitHub API)",
              "url": "https://api.github.com/repos/docker/docker-agent",
              "seen": "2026-10-08"
            },
            {
              "what": "security advisories",
              "url": "https://github.com/docker/docker-agent/security/advisories",
              "seen": "2026-10-08"
            },
            {
              "what": "advisory, shell commands in local skills",
              "url": "https://github.com/docker/docker-agent/security/advisories/GHSA-8f6v-26r8-3r4h",
              "seen": "2026-10-08"
            },
            {
              "what": "advisory, A2A tool calls without approval",
              "url": "https://github.com/docker/docker-agent/security/advisories/GHSA-f2g7-cxrq-x54m",
              "seen": "2026-10-08"
            },
            {
              "what": "open issues",
              "url": "https://github.com/docker/docker-agent/issues",
              "seen": "2026-10-08"
            },
            {
              "what": "telemetry (docs source)",
              "url": "https://docker.github.io/docker-agent/community/telemetry/",
              "seen": "2026-10-08"
            },
            {
              "what": "telemetry endpoint in source",
              "url": "https://github.com/docker/docker-agent/blob/main/pkg/telemetry/client.go",
              "seen": "2026-10-08"
            },
            {
              "what": "permissions and safety modes (docs source)",
              "url": "https://docker.github.io/docker-agent/configuration/permissions/",
              "seen": "2026-10-08"
            },
            {
              "what": "sandbox mode (docs source)",
              "url": "https://docker.github.io/docker-agent/configuration/sandbox/",
              "seen": "2026-10-08"
            },
            {
              "what": "headless and CI guide (docs source)",
              "url": "https://docker.github.io/docker-agent/guides/headless/",
              "seen": "2026-10-08"
            },
            {
              "what": "API server (docs source)",
              "url": "https://docker.github.io/docker-agent/features/api-server/",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP mode (docs source)",
              "url": "https://docker.github.io/docker-agent/features/mcp-mode/",
              "seen": "2026-10-08"
            },
            {
              "what": "A2A server (docs source)",
              "url": "https://docker.github.io/docker-agent/features/a2a/",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenTelemetry (docs source)",
              "url": "https://docker.github.io/docker-agent/community/opentelemetry/",
              "seen": "2026-10-08"
            },
            {
              "what": "installation (docs source)",
              "url": "https://docker.github.io/docker-agent/getting-started/installation/",
              "seen": "2026-10-08"
            },
            {
              "what": "llms.txt",
              "url": "https://docker.github.io/docker-agent/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "stable docs",
              "url": "https://docs.docker.com/ai/docker-agent/",
              "seen": "2026-10-08"
            },
            {
              "what": "Homebrew formula",
              "url": "https://formulae.brew.sh/api/formula/docker-agent.json",
              "seen": "2026-10-08"
            },
            {
              "what": "Docker Hub image",
              "url": "https://hub.docker.com/v2/repositories/docker/docker-agent/",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://www.docker.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.docker.com/legal/privacy/",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "Unchecked: CVSS scores and CVE identifiers for the two advisories. The GitHub API rate limit stopped the detail requests, and the advisory pages we loaded showed no CVE identifier",
            "Unchecked: reply times on issues and pull requests. Only counts, labels and comment numbers were read",
            "Unchecked: the Go package reference on pkg.go.dev",
            "Unchecked: pricing and terms for cloud sandboxes (`--cloud`), which need a Docker login",
            "The first release date isn't established. The clone was shallow, and the oldest tags date from July 2025 under the cagent name",
            "Neither the README nor the telemetry page says which Docker terms govern the open-source CLI, or how long telemetry is kept",
            "The category is arguable. Docker Agent is a finished CLI with a terminal UI as well as a Go library, so agent-harnesses would also fit. We kept the scout's frameworks",
            "No OpenAPI document was found for the native /api server, and no exit-code reference for `run --exec`"
          ]
        },
        "negative": -4,
        "negativeNotes": [
          "2026-09-01. GHSA-8f6v-26r8-3r4h (high). `read_skill` was treated as read-only and could be auto-approved, yet it ran shell commands embedded in local skill files, so opening a repository that ships skills could run commands without a prompt. Affects 1.32.5 up to 1.130.0. Fixed in 1.130.0 and published, inside six months, -2. https://github.com/docker/docker-agent/security/advisories/GHSA-8f6v-26r8-3r4h",
          "2026-08-20. GHSA-f2g7-cxrq-x54m (high). `docker agent serve a2a` created unattended sessions with tool approval disabled, so a client that could reach the endpoint could run tools without approval. The listener binds to loopback by default. Affects 1.8.2 up to 1.126.0. Fixed in 1.126.0 and published, inside six months, -2. https://github.com/docker/docker-agent/security/advisories/GHSA-f2g7-cxrq-x54m"
        ],
        "verdict": "An agent with an MCP server is eight lines of YAML, and the same file runs in a terminal, headless, or as an HTTP, MCP or A2A server. Usage telemetry is on by default and can carry prompts passed as command arguments, and two high-severity approval bypasses were fixed in August and September 2026.",
        "bestFor": "Teams already on Docker who want agents defined in a file, shared through an OCI registry and run the same way in a terminal, in CI or behind an HTTP, MCP or A2A server.",
        "strengths": [
          "An agent with one MCP server is eight lines of YAML, with a published JSON Schema for the config",
          "Four safety modes, allow, ask and deny rules, and a `--sandbox` flag that runs the agent in a Docker Sandboxes VM",
          "Headless `run --exec` with NDJSON events, structured output, and budgets for cost, tokens and time",
          "The same config runs as an HTTP API, an OpenAI-compatible chat server, an MCP server or an A2A server",
          "v1.149.0 on 7 October 2026, with 45 tagged releases in 90 days and a dated changelog"
        ],
        "weaknesses": [
          "Usage telemetry is on by default and command events can include prompts passed as arguments",
          "Two high-severity advisories in 2026, each letting tools or shell commands run without approval, both fixed",
          "Breaking changes ship in minor releases, three of them between July and September 2026",
          "`max_iterations` is unlimited and no budget is set unless the config declares one",
          "The `--listen` control plane has no built-in authentication, and A2A support is described as early"
        ],
        "agentNotes": [
          "Set `TELEMETRY_ENABLED=false` before `run` or `exec` with a prompt on the command line. Telemetry is on by default and sends positional arguments",
          "For unattended runs pass `--safety restricted` with an allow-list, or `--sandbox`. Without a policy, `--exec` rejects every tool call that needs approval",
          "Set `max_iterations` and a `budget` block in the config. Both are unlimited by default",
          "Run 1.130.0 or later. Earlier versions ran shell commands embedded in local skills, and A2A sessions before 1.126.0 skipped tool approval",
          "Review `runtime.safety` in any config pulled from a registry or URL. An author default of `autonomous` runs every tool call unprompted"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 76.5
          }
        ],
        "editorialScores": {
          "ergonomics": 81,
          "maintenance": 96,
          "payments": 60,
          "reliability": 88,
          "schema": 90,
          "security": 70,
          "transparency": 75
        },
        "provenanceScore": 84
      },
      "connect": {
        "install": "brew install docker-agent   # bundled with Docker Desktop 4.63 and later as `docker agent`",
        "claudeCode": "claude mcp add --transport stdio myagent --env OPENAI_API_KEY=$OPENAI_API_KEY --env ANTHROPIC_API_KEY=$ANTHROPIC_API_KEY -- docker agent serve mcp myorg/agent:tag --working-dir $(pwd)",
        "headless": {
          "command": "docker agent run --exec --safety restricted agent.yaml --json \"$TASK\"",
          "env": {
            "OPENAI_API_KEY": "\u003ckey\u003e",
            "TELEMETRY_ENABLED": "false"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.framework",
        "tool": "https://letme.dev/docker-agent"
      },
      "sameCompany": [
        "docker-model-runner"
      ],
      "notable": [
        "Usage telemetry is on by default and command events include positional arguments, which for `run` and `exec` can include prompts. `TELEMETRY_ENABLED=false` turns it off (https://docker.github.io/docker-agent/community/telemetry/)",
        "Renamed from cagent. github.com/docker/cagent redirects to the repository, and the default config and data directories are still `~/.config/cagent` and `~/.cagent` (https://docker.github.io/docker-agent/features/sessions/)",
        "Two high-severity advisories in 2026, both fixed. Tool calls without approval on the A2A server before 1.126.0, and shell commands run from local skills through `read_skill` before 1.130.0 (https://github.com/docker/docker-agent/security/advisories)",
        "Four safety modes (strict, balanced, restricted, autonomous) plus allow, ask and deny rules. The docs call them defence in depth and name `--sandbox` as the only isolation boundary (https://docker.github.io/docker-agent/configuration/permissions/)",
        "A run attached with `--listen` exposes a control plane with no built-in authentication (https://docker.github.io/docker-agent/features/api-server/)",
        "45 tagged releases in the 90 days to 8 October 2026, v1.111.0 to v1.149.0, with breaking changes shipped in minor versions (https://github.com/docker/docker-agent/blob/main/CHANGELOG.md)"
      ],
      "area": "frameworks",
      "details": [
        {
          "label": "Interfaces",
          "value": "`docker agent` CLI plugin and `docker-agent` binary, terminal UI, headless `run --exec`, HTTP API server, OpenAI-compatible chat server, MCP server, A2A server, ACP, Go library"
        },
        {
          "label": "Agent definition",
          "value": "YAML or HCL, config schema version 16, with a JSON Schema in the repository (agent-schema.json). Older configs are migrated on load"
        },
        {
          "label": "Languages",
          "value": "Go library only. No code is needed for a YAML agent"
        },
        {
          "label": "Models",
          "value": "About 30 provider pages, including OpenAI, Anthropic, Google, Bedrock, Mistral, xAI and OpenRouter, plus local models through Docker Model Runner"
        },
        {
          "label": "MCP client",
          "value": "stdio, streamable HTTP and SSE, with OAuth and dynamic client registration. `ref: docker:\u003cname\u003e` pulls from Docker's MCP catalogue"
        },
        {
          "label": "Multi-agent",
          "value": "Sub-agents, hand-offs, background agents and `transfer_task`"
        },
        {
          "label": "Durable state",
          "value": "Sessions in SQLite, resumable with `--session`, and an API event stream with sequence numbers and replay"
        },
        {
          "label": "Approvals",
          "value": "Safety modes strict, balanced, restricted and autonomous, plus allow, ask and deny rules. The default asks for anything that isn't read-only"
        },
        {
          "label": "Sandbox",
          "value": "`--sandbox` runs the agent in a Docker Sandboxes VM. Off by default"
        },
        {
          "label": "Tracing",
          "value": "OpenTelemetry over OTLP/HTTP with `--otel`. Message content capture is off by default"
        },
        {
          "label": "Telemetry",
          "value": "On by default, sent to api.docker.com. `TELEMETRY_ENABLED=false` turns it off"
        },
        {
          "label": "Distribution",
          "value": "Agents push and pull as OCI artefacts. Binaries for macOS, Linux and Windows on amd64 and arm64, Homebrew, Docker Desktop 4.63 and later"
        },
        {
          "label": "Releases in 90 days",
          "value": "45 (v1.111.0 to v1.149.0)"
        }
      ],
      "provenance": {
        "legalEntity": "Docker, Inc.",
        "domain": "docker.com",
        "domainRegistered": "1995-01-25",
        "endpointOnVendorDomain": null,
        "terms": "https://www.docker.com/legal/docker-terms-use/",
        "privacy": "https://www.docker.com/legal/privacy/",
        "statusPage": "",
        "changelog": "https://github.com/docker/docker-agent/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The repository is under GitHub's docker organisation and SECURITY.md sends reports to security@docker.com. Docker's privacy policy names Docker, Inc.",
          "www.docker.com/.well-known/security.txt gives security@docker.com, a policy URL and an expiry of 1 January 2030.",
          "Main-branch docs are on docker.github.io/docker-agent and the stable docs on docs.docker.com/ai/docker-agent. Both loaded on 8 October 2026.",
          "Docker's general terms and privacy policy are listed. Neither the README nor the telemetry page says which terms govern the open-source CLI.",
          "No status page is listed because the software runs on the owner's machine. Usage telemetry goes to api.docker.com/events/v1/track per pkg/telemetry/client.go.",
          "RDAP for docker.com gives a registration date of 1995-01-25."
        ],
        "score": 84,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Docker, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "docker.com, registered 1995-01-25 (31 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "no hosted endpoint",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Terms of service",
            "value": "read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 6,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "valid",
            "points": 10,
            "max": 10,
            "state": "ok"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.docker.com/legal/docker-terms-use/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-08-26",
            "words": 5584,
            "points": 6,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective as of: August 26, 2026",
                "says": "Last updated 2026-08-26"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "Except as provided in the SSA or another controlling written agreement, these Terms are governed by the laws of the State of California, without regard to conflict of laws rules.",
                "says": "The law of the State of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…PERMITTED BY LAW, DOCKER’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS WILL NOT EXCEED THE AMOUNTS PAID BY YOU TO DOCKER FOR THE SERVICES GIVING RISE TO THE CLAIM DURING THE SIX (6) MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY OR ONE HUNDRED DOLLARS ($100), WHICHEVER IS GREATER.",
                "says": "Capped at the fees paid in the 6 months before the claim or $100"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Docker may reclaim Account names or usernames (including on behalf of businesses or individuals that hold legal claims or trademarks to those usernames) and may suspend Accounts that use misleading business names or logos."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Docker may update these Terms from time to time by posting the updated version on the Website and, where required by law or where appropriate, providing additional notice.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "You may not use the Services if you are listed on any U.S."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "Docker Extensions Marketplace Developer Agreement (if you publish extensions): https://www.docker.com/legal/extensions_marketplace_developer_agreement/"
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "Use automated means (agents, robots, spiders, scrapers, or similar) to access the Website or Services except as permitted by Docker (for example, through documented APIs and within published limits).",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "Use the Services to build, operate, or offer a product or service intended to compete with Docker’s Services, or to mirror or replicate content for an unauthorized commercial service.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "Docker reserves the right to modify, restrict, or discontinue Free Hub Access at any time with or without notice, subject to the change-notice obligations in Section 18."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "You and Docker agree that the U.S. Federal Arbitration Act governs the interpretation and enforcement of these Terms, and that you and Docker are each waiving the right to a trial by jury or to participate in a class action."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Docker's total liability is capped at the greater of the amounts paid in the six months before the event and 100 US dollars.",
                "quote": "DOCKER’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS WILL NOT EXCEED THE AMOUNTS PAID BY YOU TO DOCKER FOR THE SERVICES GIVING RISE TO THE CLAIM DURING THE SIX (6) MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY OR ONE HUNDRED DOLLARS ($100), WHICHEVER IS GREATER."
              },
              {
                "date": "2026-10-08",
                "text": "By using the Services the user lets Docker use its trade names, trademarks, logos and domain names in marketing materials and customer lists to publicise that use.",
                "quote": "By using the Services, you grant Docker permission to use your trade names, trademarks, service marks, logos, and domain names in Docker’s marketing materials, customer lists, financial reports, and website listings for the purpose of publicizing your use of the Services."
              },
              {
                "date": "2026-10-08",
                "text": "Users may not state that Output from the AI Functions is human generated, or that Docker or its subcontractors approved or endorsed it.",
                "quote": "You will not represent that Output is human generated or approved or endorsed by Docker or its subcontractors."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.docker.com/legal/privacy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-08-26",
            "words": 7523,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Update: August 26, 2026",
                "says": "Last updated 2026-08-26"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "Where you subscribe to Docker’s self-service AI services as an individual, this Privacy Policy applies to the personal data we collect from you as described below;"
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "earlier snapshots and images are deleted within 7 days.",
                "says": "Names a period of 7 days"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "(iv) credentials you choose to store — API keys and access tokens for third-party AI model providers and MCP-connected tools, which we store securely on your behalf in order to provide the Services;"
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "In the preceding 12 months we did not sell or share for cross context behavioral advertising, the personal information of California residents.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "This includes the right to object to our processing of your personal data for direct marketing and the right to object to our processing of your personal data where we are performing a task in the public interest or pursuing our legitimate interests or those of a third party."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "You may also contact Docker by emailing privacy@docker.com or by sending postal mail to: Docker, Inc., 3790 El Camino Real # 1052, Palo Alto, CA 94306, (415) 941-0376",
                "says": "privacy@docker.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "Data Privacy Framework, Docker is responsible for the processing of personal data received from Customers from the EU, the UK, and Switzerland and onward transfers to a third party acting as an agent on our behalf.",
                "says": "Relies on the Data Privacy Framework"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "A saved sandbox image or snapshot may contain the prompts and responses from the session.",
                "quote": "If you save a sandbox image or snapshot, it may contain prompts and responses from your session."
              },
              {
                "date": "2026-10-08",
                "text": "Docker stores the API keys and access tokens for third-party AI model providers and MCP-connected tools that a user chooses to store.",
                "quote": "API keys and access tokens for third-party AI model providers and MCP-connected tools, which we store securely on your behalf in order to provide the Services"
              },
              {
                "date": "2026-10-08",
                "text": "Docker gives its customers information on how particular domains access and use the Website, Services and particular functions or uploads.",
                "quote": "Docker also provides information on how particular domains (e.g., www.companyx.com ) access and use our Website, Services, and particular features or uploads to customers for their business purposes, for example, so they can improve or target their software and other offerings."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/docker-agent.json",
      "live": {
        "slug": "docker-agent",
        "versions": [
          {
            "registry": "github",
            "name": "docker/docker-agent",
            "version": "v1.149.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:08:47.905263699Z"
          }
        ],
        "githubStars": 4162,
        "securityTxt": {
          "url": "https://docker.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2030-01-01T05:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:30.592404975Z"
        },
        "updatedAt": "2026-10-08T16:08:47.905263699Z"
      }
    },
    "verify": {
      "accepts": "a page on docker.com or docker.github.io or one of their subdomains, or the README of github.com/docker/docker-agent",
      "badgeUrl": "https://www.anchorterminal.com/badges/docker-agent.svg",
      "body": {
        "slug": "docker-agent",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/docker-agent",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/docker-agent\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/docker-agent.svg\" alt=\"Docker Agent on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Docker Agent on Anchor Terminal](https://www.anchorterminal.com/badges/docker-agent.svg)](https://www.anchorterminal.com/tools/docker-agent)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/docker-agent\"\u003eDocker Agent on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/docker-agent",
    "json": "https://www.anchorterminal.com/tools/docker-agent.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/docker-agent.md",
    "slim": "https://www.anchorterminal.com/tools/docker-agent.min.md"
  },
  "markdown": "## Overview\n\n**Grade BB · 76.5/100 · rank #30 of 629 · #4 in Agent frameworks \u0026 SDKs · agent-ready · confidence medium**\n\n\nMore from Docker, listed separately because each is its own product: [Docker Model Runner](https://www.anchorterminal.com/tools/docker-model-runner.md) (Local AI).\n\n## Assessment\n\nAn agent with an MCP server is eight lines of YAML, and the same file runs in a terminal, headless, or as an HTTP, MCP or A2A server. Usage telemetry is on by default and can carry prompts passed as command arguments, and two high-severity approval bypasses were fixed in August and September 2026.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Docker (https://docker.github.io/docker-agent/) |\n| Kind | Agent framework |\n| Category | Agent frameworks \u0026 SDKs (https://www.anchorterminal.com/categories/frameworks) |\n| Auth | None · No account of its own. Model keys come from provider environment variables, `--env-from-file`, an account login or Docker Model Runner for local models. The servers it starts take an optional Bearer token (`--auth-token`), which HTTP MCP requires on a non-loopback address. |\n| Pricing | Free (Free · OSS) · Free and Apache-2.0, with nothing to buy for the CLI. You pay your model provider, or nothing with a local model through Docker Model Runner. Cloud sandboxes need a Docker login and weren't priced in this check. |\n| x402 | No · No x402, MPP or L402 in the docs or the README (checked 2026-10-08). |\n| Licence | Apache-2.0 |\n| Packages | oci: `docker/docker-agent`; go: `github.com/docker/docker-agent` |\n| Source | https://github.com/docker/docker-agent |\n| Docs | https://docker.github.io/docker-agent/ |\n| llms.txt | https://docker.github.io/docker-agent/llms.txt |\n| Last release | 2026-10-07 |\n| GitHub stars | 4,029 (as of 2026-10-08) |\n| Interfaces | `docker agent` CLI plugin and `docker-agent` binary, terminal UI, headless `run --exec`, HTTP API server, OpenAI-compatible chat server, MCP server, A2A server, ACP, Go library |\n| Agent definition | YAML or HCL, config schema version 16, with a JSON Schema in the repository (agent-schema.json). Older configs are migrated on load |\n| Languages | Go library only. No code is needed for a YAML agent |\n| Models | About 30 provider pages, including OpenAI, Anthropic, Google, Bedrock, Mistral, xAI and OpenRouter, plus local models through Docker Model Runner |\n| MCP client | stdio, streamable HTTP and SSE, with OAuth and dynamic client registration. `ref: docker:\u003cname\u003e` pulls from Docker's MCP catalogue |\n| Multi-agent | Sub-agents, hand-offs, background agents and `transfer_task` |\n| Durable state | Sessions in SQLite, resumable with `--session`, and an API event stream with sequence numbers and replay |\n| Approvals | Safety modes strict, balanced, restricted and autonomous, plus allow, ask and deny rules. The default asks for anything that isn't read-only |\n| Sandbox | `--sandbox` runs the agent in a Docker Sandboxes VM. Off by default |\n| Tracing | OpenTelemetry over OTLP/HTTP with `--otel`. Message content capture is off by default |\n| Telemetry | On by default, sent to api.docker.com. `TELEMETRY_ENABLED=false` turns it off |\n| Distribution | Agents push and pull as OCI artefacts. Binaries for macOS, Linux and Windows on amd64 and arm64, Homebrew, Docker Desktop 4.63 and later |\n| Releases in 90 days | 45 (v1.111.0 to v1.149.0) |\n| Capabilities | agent.framework, agent.multi-agent, agent.mcp-client, agent.durable |\n| Tags | framework, open-source, go, local, free, no-card, llms-txt, docker |\n| JSON | https://www.anchorterminal.com/api/v1/tools/docker-agent.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 88 | 17.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 90 | 14.6 |\n| Agent ergonomics | 13% | 16.2 | 81 | 13.2 |\n| Security \u0026 auth | 14% | 17.5 | 70 | 12.2 |\n| Payments \u0026 pricing | 10% | 12.5 | 60 | 7.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 96 | 8.4 |\n| Transparency \u0026 trust (editorial 75, provenance 84) | 7% | 8.8 | 80 | 7.0 |\n| Negative events | up to −15 | up to −15 | 2026-09-01. GHSA-8f6v-26r8-3r4h (high). `read_skill` was treated as read-only and could be auto-approved, yet it ran shell commands embedded in local skill files, so opening a repository that ships skills could run commands without a prompt. Affects 1.32.5 up to 1.130.0. Fixed in 1.130.0 and published, inside six months, -2. https://github.com/docker/docker-agent/security/advisories/GHSA-8f6v-26r8-3r4h 2026-08-20. GHSA-f2g7-cxrq-x54m (high). `docker agent serve a2a` created unattended sessions with tool approval disabled, so a client that could reach the endpoint could run tools without approval. The listener binds to loopback by default. Affects 1.8.2 up to 1.126.0. Fixed in 1.126.0 and published, inside six months, -2. https://github.com/docker/docker-agent/security/advisories/GHSA-f2g7-cxrq-x54m  | -4 |\n| **Total** | | | | **76.5 → BB** |\n\n### Why each score\n\n- Reliability 88: Read with the local-software lines, because the owner runs it. Binaries for macOS, Linux and Windows on amd64 and arm64 on every GitHub release, a Homebrew formula at 1.149.0, a Docker Hub image, and Docker Desktop 4.63 and later bundle it. Go 1.27 is the stated minimum for source builds (20). The ci workflow runs on every push to main with about 1,350 test files and an e2e directory. Nine of the last ten push runs passed, including the newest on 8 October, with one failure that morning (25). 25 open issues and 17 open pull requests, most labelled and answered, with 27 issues closed and 32 opened in the 30 days to 8 October. Open reports include a race in `transfer_task` (#4156), a hand-off dropped silently (#4242) and `edit_file` editing the first of several matches (#3929) (20). The changelog has Breaking Changes sections, but those changes ship in minor releases (1.114.0, 1.133.0 and 1.137.0 since July) and the major version has never moved (8). 1.149.0, past 1.0 (15).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 90: Framework reading. agent-schema.json in the repository is a JSON Schema for the whole config, and the chat server serves its OpenAPI document at /openapi.json. We found no OpenAPI document for the native /api server and didn't check the Go package reference (22). llms.txt on docker.github.io/docker-agent and on docs.docker.com (10). The docs say when to use the API server and when the chat server, compare six ways to pass large input, and state that permissions aren't a security boundary (17). Configs are parsed strictly, unknown fields fail to load with a hint, and safety fields accept four named modes only (13). An examples directory, a troubleshooting page of common errors and documented HTTP status codes for the API. We found no exit-code reference for `run --exec` (13). A dated CHANGELOG.md and a numbered config schema, now version 16, with migration on load (15).\n- Agent ergonomics 81: Framework reading, scored on what an agent with MCP needs. The README's agent with one MCP server is eight lines of YAML and no code, with deferred toolsets and a code mode (23). Budgets cap cost, tokens and time, tool results are bounded to 50 KiB since 1.148.0, and context is compacted, but `max_iterations` is unlimited and no budget applies unless declared (16). `--json` writes one NDJSON event per message, tool call and error, and the API documents 404, 409, 413 and 502 responses. No exit-code reference found for `run --exec` (14). Sessions resume from SQLite, the event stream replays from a sequence number, follow-ups accept an `Idempotency-Key`, and read-only and destructive tool annotations drive the safety modes (18). One binary and a model key or a local model are enough to start. The library is Go only (10).\n- Security \u0026 auth 70: Framework reading. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. Usage telemetry is on by default, with a notice on first start and `TELEMETRY_ENABLED=false` to stop it. The docs say command events include positional arguments, which for `run` and `exec` can include prompts, and error text (12). Four safety modes with allow, ask and deny rules, a default that asks for anything not read-only, `--exec` rejecting unapproved calls, `--sandbox` for a Docker Sandboxes VM, and HTTP MCP defaulting to loopback and `restricted`. A run's `--listen` control plane has no built-in authentication (19). The docs treat skill files and third-party configs as untrusted and restrict URI schemes against prompt injection, with no dedicated guidance page (10). Hooks for audit logging and approval decisions, opt-in OpenTelemetry traces, NDJSON transcripts and a session database (14). SECURITY.md with a 72-hour acknowledgement, a valid security.txt on docker.com, two advisories published on GitHub with fixed versions, and CodeQL and zizmor in CI. No paid bounty, and we saw no CVE identifiers on the advisories (15). SOC 2 isn't scored for a framework.\n- Payments \u0026 pricing 60: No payment protocol (0). Read with the self-hosted rule. The CLI is free and Apache-2.0 with nothing to buy, so 20, 20 and 20 on the last three lines. It installs without an account and runs local models through Docker Model Runner. Cloud sandboxes need a Docker login and weren't priced in this check.\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 96: v1.149.0 published on 2026-10-07 (30). 45 tagged releases in the 90 days to 8 October, v1.111.0 to v1.149.0 (20). 25 open issues, most labelled by area and answered, 27 closed in the last 30 days and 17 open pull requests. We didn't measure reply times (21). The Homebrew formula was at 1.149.0 and the Docker Hub image was updated on 8 October, and the Go module ships from the same tags (15). Dependabot, CodeQL, zizmor and actions pinned to commit SHAs, with CI passing on main (10).\n- Transparency \u0026 trust 80: Apache-2.0 (30). The telemetry page lists what's collected and warns that arguments and error text can carry secrets or personal data. It doesn't name the endpoint (api.docker.com, per the source), link Docker's privacy policy or give a retention period (15). Breaking changes are dated in the changelog and one renamed variable kept a fallback for one release, with no written deprecation policy, and the changelog says frozen config schema versions aren't maintained long-term (10). Telemetry is disclosed in the README, the docs and a first-start notice, with an opt-out variable (20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/docker-agent.md (JSON https://www.anchorterminal.com/fixes/docker-agent.json)\n\n### What we couldn't check\n\n- Unchecked: CVSS scores and CVE identifiers for the two advisories. The GitHub API rate limit stopped the detail requests, and the advisory pages we loaded showed no CVE identifier\n- Unchecked: reply times on issues and pull requests. Only counts, labels and comment numbers were read\n- Unchecked: the Go package reference on pkg.go.dev\n- Unchecked: pricing and terms for cloud sandboxes (`--cloud`), which need a Docker login\n- The first release date isn't established. The clone was shallow, and the oldest tags date from July 2025 under the cagent name\n- Neither the README nor the telemetry page says which Docker terms govern the open-source CLI, or how long telemetry is kept\n- The category is arguable. Docker Agent is a finished CLI with a terminal UI as well as a Go library, so agent-harnesses would also fit. We kept the scout's frameworks\n- No OpenAPI document was found for the native /api server, and no exit-code reference for `run --exec`\n\n### Sources\n\n- repository main branch (cloned), README, LICENSE, go.mod, agent-schema.json: \u003chttps://github.com/docker/docker-agent\u003e (seen 2026-10-08)\n- changelog: \u003chttps://github.com/docker/docker-agent/blob/main/CHANGELOG.md\u003e (seen 2026-10-08)\n- security policy: \u003chttps://github.com/docker/docker-agent/blob/main/SECURITY.md\u003e (seen 2026-10-08)\n- repository statistics, releases and CI runs on main (GitHub API): \u003chttps://api.github.com/repos/docker/docker-agent\u003e (seen 2026-10-08)\n- security advisories: \u003chttps://github.com/docker/docker-agent/security/advisories\u003e (seen 2026-10-08)\n- advisory, shell commands in local skills: \u003chttps://github.com/docker/docker-agent/security/advisories/GHSA-8f6v-26r8-3r4h\u003e (seen 2026-10-08)\n- advisory, A2A tool calls without approval: \u003chttps://github.com/docker/docker-agent/security/advisories/GHSA-f2g7-cxrq-x54m\u003e (seen 2026-10-08)\n- open issues: \u003chttps://github.com/docker/docker-agent/issues\u003e (seen 2026-10-08)\n- telemetry (docs source): \u003chttps://docker.github.io/docker-agent/community/telemetry/\u003e (seen 2026-10-08)\n- telemetry endpoint in source: \u003chttps://github.com/docker/docker-agent/blob/main/pkg/telemetry/client.go\u003e (seen 2026-10-08)\n- permissions and safety modes (docs source): \u003chttps://docker.github.io/docker-agent/configuration/permissions/\u003e (seen 2026-10-08)\n- sandbox mode (docs source): \u003chttps://docker.github.io/docker-agent/configuration/sandbox/\u003e (seen 2026-10-08)\n- headless and CI guide (docs source): \u003chttps://docker.github.io/docker-agent/guides/headless/\u003e (seen 2026-10-08)\n- API server (docs source): \u003chttps://docker.github.io/docker-agent/features/api-server/\u003e (seen 2026-10-08)\n- MCP mode (docs source): \u003chttps://docker.github.io/docker-agent/features/mcp-mode/\u003e (seen 2026-10-08)\n- A2A server (docs source): \u003chttps://docker.github.io/docker-agent/features/a2a/\u003e (seen 2026-10-08)\n- OpenTelemetry (docs source): \u003chttps://docker.github.io/docker-agent/community/opentelemetry/\u003e (seen 2026-10-08)\n- installation (docs source): \u003chttps://docker.github.io/docker-agent/getting-started/installation/\u003e (seen 2026-10-08)\n- llms.txt: \u003chttps://docker.github.io/docker-agent/llms.txt\u003e (seen 2026-10-08)\n- stable docs: \u003chttps://docs.docker.com/ai/docker-agent/\u003e (seen 2026-10-08)\n- Homebrew formula: \u003chttps://formulae.brew.sh/api/formula/docker-agent.json\u003e (seen 2026-10-08)\n- Docker Hub image: \u003chttps://hub.docker.com/v2/repositories/docker/docker-agent/\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://www.docker.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.docker.com/legal/privacy/\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 84/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Docker, Inc. | 20/20 |\n| Domain age | docker.com, registered 1995-01-25 (31 years) | 15/15 |\n| Endpoint on the vendor's domain | no hosted endpoint | n/a |\n| Terms of service | read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points | 6/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | not found | 0/10 |\n| Changelog | published | 10/10 |\n| security.txt | valid | 10/10 |\n\nThe repository is under GitHub's docker organisation and SECURITY.md sends reports to security@docker.com. Docker's privacy policy names Docker, Inc.\n\nwww.docker.com/.well-known/security.txt gives security@docker.com, a policy URL and an expiry of 1 January 2030.\n\nMain-branch docs are on docker.github.io/docker-agent and the stable docs on docs.docker.com/ai/docker-agent. Both loaded on 8 October 2026.\n\nDocker's general terms and privacy policy are listed. Neither the README nor the telemetry page says which terms govern the open-source CLI.\n\nNo status page is listed because the software runs on the owner's machine. Usage telemetry goes to api.docker.com/events/v1/track per pkg/telemetry/client.go.\n\nRDAP for docker.com gives a registration date of 1995-01-25.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.docker.com/legal/docker-terms-use/), read 2026-10-08, dated 2026-08-26, states 7 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"Use automated means (agents, robots, spiders, scrapers, or similar) to access the Website or Services except as permitted by Docker (for example, through documented APIs and within published limits).\"\n- To know. Restricts benchmarking or competitive use (costs points). \"Use the Services to build, operate, or offer a product or service intended to compete with Docker’s Services, or to mirror or replicate content for an unauthorized commercial service.\"\n- To know. Says access can be ended without notice or for any reason. \"Docker reserves the right to modify, restrict, or discontinue Free Hub Access at any time with or without notice, subject to the change-notice obligations in Section 18.\"\n- To know. Requires arbitration or waives class actions. \"You and Docker agree that the U.S. Federal Arbitration Act governs the interpretation and enforcement of these Terms, and that you and Docker are each waiving the right to a trial by jury or to participate in a class action.\"\n- Gives the date it was last updated. Last updated 2026-08-26.\n- Names the governing law or courts. The law of the State of California.\n- States a limit on its liability. Capped at the fees paid in the 6 months before the claim or $100.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Also in the text (2026-10-08). Docker's total liability is capped at the greater of the amounts paid in the six months before the event and 100 US dollars. \"DOCKER’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS WILL NOT EXCEED THE AMOUNTS PAID BY YOU TO DOCKER FOR THE SERVICES GIVING RISE TO THE CLAIM DURING THE SIX (6) MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY OR ONE HUNDRED DOLLARS ($100), WHICHEVER IS GREATER.\"\n- Also in the text (2026-10-08). By using the Services the user lets Docker use its trade names, trademarks, logos and domain names in marketing materials and customer lists to publicise that use. \"By using the Services, you grant Docker permission to use your trade names, trademarks, service marks, logos, and domain names in Docker’s marketing materials, customer lists, financial reports, and website listings for the purpose of publicizing your use of the Services.\"\n- Also in the text (2026-10-08). Users may not state that Output from the AI Functions is human generated, or that Docker or its subcontractors approved or endorsed it. \"You will not represent that Output is human generated or approved or endorsed by Docker or its subcontractors.\"\n\n**Privacy policy** (https://www.docker.com/legal/privacy/), read 2026-10-08, dated 2026-08-26, states 8 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2026-08-26.\n- Says how long data is kept. Names a period of 7 days.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@docker.com.\n- Says where data is transferred or stored. Relies on the Data Privacy Framework.\n- Also in the text (2026-10-08). A saved sandbox image or snapshot may contain the prompts and responses from the session. \"If you save a sandbox image or snapshot, it may contain prompts and responses from your session.\"\n- Also in the text (2026-10-08). Docker stores the API keys and access tokens for third-party AI model providers and MCP-connected tools that a user chooses to store. \"API keys and access tokens for third-party AI model providers and MCP-connected tools, which we store securely on your behalf in order to provide the Services\"\n- Also in the text (2026-10-08). Docker gives its customers information on how particular domains access and use the Website, Services and particular functions or uploads. \"Docker also provides information on how particular domains (e.g., www.companyx.com ) access and use our Website, Services, and particular features or uploads to customers for their business purposes, for example, so they can improve or target their software and other offerings.\"\n\n## Live (updated 2026-10-08 16:08 UTC)\n\n- github `docker/docker-agent` v1.149.0, released 2026-10-07\n- security.txt: valid, expires 2030-01-01T05:00:00.000Z\n- Always current: https://www.anchorterminal.com/api/v1/live/docker-agent.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- An agent with one MCP server is eight lines of YAML, with a published JSON Schema for the config\n- Four safety modes, allow, ask and deny rules, and a `--sandbox` flag that runs the agent in a Docker Sandboxes VM\n- Headless `run --exec` with NDJSON events, structured output, and budgets for cost, tokens and time\n- The same config runs as an HTTP API, an OpenAI-compatible chat server, an MCP server or an A2A server\n- v1.149.0 on 7 October 2026, with 45 tagged releases in 90 days and a dated changelog\n\n## Weaknesses\n\n- Usage telemetry is on by default and command events can include prompts passed as arguments\n- Two high-severity advisories in 2026, each letting tools or shell commands run without approval, both fixed\n- Breaking changes ship in minor releases, three of them between July and September 2026\n- `max_iterations` is unlimited and no budget is set unless the config declares one\n- The `--listen` control plane has no built-in authentication, and A2A support is described as early\n\n## Before you call it (notes for agents)\n\n1. Set `TELEMETRY_ENABLED=false` before `run` or `exec` with a prompt on the command line. Telemetry is on by default and sends positional arguments\n2. For unattended runs pass `--safety restricted` with an allow-list, or `--sandbox`. Without a policy, `--exec` rejects every tool call that needs approval\n3. Set `max_iterations` and a `budget` block in the config. Both are unlimited by default\n4. Run 1.130.0 or later. Earlier versions ran shell commands embedded in local skills, and A2A sessions before 1.126.0 skipped tool approval\n5. Review `runtime.safety` in any config pulled from a registry or URL. An author default of `autonomous` runs every tool call unprompted\n\n## Get started\n\nInstall:\n\n```bash\nbrew install docker-agent   # bundled with Docker Desktop 4.63 and later as `docker agent`\n```\n\nClaude Code:\n\n```bash\nclaude mcp add --transport stdio myagent --env OPENAI_API_KEY=$OPENAI_API_KEY --env ANTHROPIC_API_KEY=$ANTHROPIC_API_KEY -- docker agent serve mcp myorg/agent:tag --working-dir $(pwd)\n```\n\nHeadless / CI:\n\n```json\n{\n  \"command\": \"docker agent run --exec --safety restricted agent.yaml --json \\\"$TASK\\\"\",\n  \"env\": {\n    \"OPENAI_API_KEY\": \"\\u003ckey\\u003e\",\n    \"TELEMETRY_ENABLED\": \"false\"\n  }\n}\n```\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| OpenAI Agents SDK | AA | 86.2 | 1 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | no | https://www.anchorterminal.com/tools/openai-agents-sdk.md |\n| Pydantic AI | A | 83.7 | 3 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | no | https://www.anchorterminal.com/tools/pydantic-ai.md |\n| Microsoft Agent Framework | A | 82.2 | 6 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | no | https://www.anchorterminal.com/tools/microsoft-agent-framework.md |\n| Agent Development Kit (ADK) | BB | 74.7 | 57 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | no | https://www.anchorterminal.com/tools/google-adk.md |\n| Agno | BB | 72.8 | 81 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | no | https://www.anchorterminal.com/tools/agno.md |\n| LangGraph | BB | 70.6 | 124 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | no | https://www.anchorterminal.com/tools/langgraph.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Usage telemetry is on by default and command events include positional arguments, which for `run` and `exec` can include prompts. `TELEMETRY_ENABLED=false` turns it off (source: \u003chttps://docker.github.io/docker-agent/community/telemetry/\u003e)\n- Renamed from cagent. github.com/docker/cagent redirects to the repository, and the default config and data directories are still `~/.config/cagent` and `~/.cagent` (source: \u003chttps://docker.github.io/docker-agent/features/sessions/\u003e)\n- Two high-severity advisories in 2026, both fixed. Tool calls without approval on the A2A server before 1.126.0, and shell commands run from local skills through `read_skill` before 1.130.0 (source: \u003chttps://github.com/docker/docker-agent/security/advisories\u003e)\n- Four safety modes (strict, balanced, restricted, autonomous) plus allow, ask and deny rules. The docs call them defence in depth and name `--sandbox` as the only isolation boundary (source: \u003chttps://docker.github.io/docker-agent/configuration/permissions/\u003e)\n- A run attached with `--listen` exposes a control plane with no built-in authentication (source: \u003chttps://docker.github.io/docker-agent/features/api-server/\u003e)\n- 45 tagged releases in the 90 days to 8 October 2026, v1.111.0 to v1.149.0, with breaking changes shipped in minor versions (source: \u003chttps://github.com/docker/docker-agent/blob/main/CHANGELOG.md\u003e)\n\n## Compare\n\n- [AgentOS vs Docker Agent](https://www.anchorterminal.com/compare/agentos-vs-docker-agent.md): BB 75.3 vs BB 76.5\n- [Agno vs Docker Agent](https://www.anchorterminal.com/compare/agno-vs-docker-agent.md): BB 72.8 vs BB 76.5\n- [Claude Agent SDK vs Docker Agent](https://www.anchorterminal.com/compare/claude-agent-sdk-vs-docker-agent.md): BB 72.1 vs BB 76.5\n- [CrewAI vs Docker Agent](https://www.anchorterminal.com/compare/crewai-vs-docker-agent.md): B 67 vs BB 76.5\n- [Docker Agent vs Agent Development Kit (ADK)](https://www.anchorterminal.com/compare/docker-agent-vs-google-adk.md): BB 76.5 vs BB 74.7\n- [Docker Agent vs LangGraph](https://www.anchorterminal.com/compare/docker-agent-vs-langgraph.md): BB 76.5 vs BB 70.6\n- [Docker Agent vs Microsoft Agent Framework](https://www.anchorterminal.com/compare/docker-agent-vs-microsoft-agent-framework.md): BB 76.5 vs A 82.2\n- [Docker Agent vs OpenAI Agents SDK](https://www.anchorterminal.com/compare/docker-agent-vs-openai-agents-sdk.md): BB 76.5 vs AA 86.2\n- [Docker Agent vs Pydantic AI](https://www.anchorterminal.com/compare/docker-agent-vs-pydantic-ai.md): BB 76.5 vs A 83.7\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on docker.com or docker.github.io or one of their subdomains, or the README of github.com/docker/docker-agent. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"docker-agent\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/docker-agent\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/docker-agent.svg\" alt=\"Docker Agent on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Docker Agent on Anchor Terminal](https://www.anchorterminal.com/badges/docker-agent.svg)](https://www.anchorterminal.com/tools/docker-agent)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/docker-agent\"\u003eDocker Agent on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Docker Agent is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/docker-agent-dark.png\n- Light: https://www.anchorterminal.com/assets/share/docker-agent-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Agent frameworks \u0026 SDKs",
        "url": "https://www.anchorterminal.com/categories/frameworks"
      },
      {
        "name": "Docker Agent",
        "url": ""
      }
    ],
    "description": "Docker's open-source runtime for building and running AI agents from YAML or HCL files, formerly cagent. It runs as a docker agent CLI plugin with a terminal UI, headless mode, HTTP, MCP and A2A servers, and a Go library.",
    "facts": [
      "rank #30 of 629",
      "None auth",
      "0 desk reviews"
    ],
    "h1": "Docker Agent",
    "image": "https://www.anchorterminal.com/assets/og/tools-docker-agent.png",
    "path": "/tools/docker-agent",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Docker Agent review for AI agents, grade BB (76.5/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/docker-agent"
  },
  "tokens": {
    "markdown": 7600,
    "slim": 1530
  },
  "version": 1
}
