Audit Installed Extensions with gh extension list
Before you trust an unfamiliar workstation, run gh extension list for a straight inventory of what is actually installed for your user. It is read-only: it does not install, update, remove or execute anything.
The route
Jump straight to the step you need, or tick off Done means at the end.
Before you start
You need the gh package and a shell. Authentication is not required for the inventory itself, and the command should run as your ordinary user, not with sudo: elevated privileges can show a different user's extension directory and mislead you.
This guide was checked with GitHub CLI 2.87.3, installed on 23 September 2026. The installed manpage describes gh extension list [flags] as "List installed extension commands" and documents no options for this subcommand. The current upstream manual gives the same command and lists its aliases.
1. Confirm the CLI
Check the expected executable is available:
gh --version
On the machine used for this guide, the first line is:
gh version 2.87.3 (2026-02-23)
If the command is missing, stop and install GitHub CLI through your normal distribution or vendor process. Do not treat a failed inventory as proof that no extensions are installed: it may simply mean gh is absent or not on PATH.
2. List the local extensions
Run it without elevation:
gh extension list
- No installed extensions: the command completes without listing any rows.
- Extensions present: expect one line per installed command, with details that vary by GitHub CLI version and installation type.
- No stable format promised: there is no documented JSON mode, filter option or fixed custom-column layout, so do not build a parser around undocumented spacing.
The command exits successfully when the inventory is available, so capture the status in a script:
if gh extension list; then
echo "Extension inventory completed"
else
status=$?
printf 'Could not list extensions (exit %s)\n' "$status" &2
exit "$status"
fi
Checkpoint
A successful command with no rows means nothing was found in this user's local extension installation, not that GitHub has no extensions at all.
3. Use the short aliases when it helps
Pick one documented alias if it is easier to remember:
gh extension ls
gh extensions ls
gh ext ls
These all do the same thing. Pick one form for scripts and stick with it. The full spelling, gh extension list, tends to read clearest in runbooks because it explains its own purpose without needing an alias table.
What the result does and does not tell you
GitHub CLI extensions are commands supplied by repositories named with the gh- convention. This command answers one narrow question: which extension commands are installed for the current CLI environment? It is not a catalogue of what exists, a health check, or a security review.
For discovery, use the separate search command instead:
gh extension search <term>
Replace <term> with a real word, such as issue. Search results come from GitHub and may need network access. Keep that separate in your head from an inventory check: an extension can be installed locally without appearing in a search result, and a search result is not installed just because it is displayed.
For more detail on a particular installed extension, use its own documentation or inspect the installation with your normal package and filesystem tools. Do not execute an unfamiliar extension just to identify it.
Security boundary
GitHub states plainly that extensions are not verified, signed or endorsed by GitHub. Installing or upgrading one means trusting its publisher. Listing is comparatively low risk since it is only an inventory operation, but the presence of a command is not evidence that its code is safe. Review a repository's source, release process and requested behaviour before installing anything a search turns up. Treat gh extension install, gh extension upgrade and gh extension remove as separate state-changing operations; this guide runs none of them, and no undo step is needed for gh extension list because it changes nothing.
Common traps
- Using
sudo. Root can have a different configuration and extension directory. Re-run as the user who actually runsgh. - Confusing list and search.
gh extension listis local inventory;gh extension searchqueries available repositories. - Expecting flags. Neither the installed manpage nor the upstream command page documents list-specific flags. Do not assume options from other
gh ... listcommands apply here. - Reading an empty result as an error. No output can be the correct result when this user has no installed extensions. Check the exit status rather than trusting visible text.
- Running from the wrong account or environment. Containers, remote shells and automation users can each have different
ghconfiguration and extension state.
Done means
- Installation identified:
gh --versionconfirms the intended GitHub CLI installation. - Inventory run correctly:
gh extension listcompletes under the intended ordinary user account. - Result recorded: you noted the displayed extensions, or confirmed the list is empty.
- List and search kept separate: you did not confuse local inventory with remote search.
- Nothing changed: no extension was installed, upgraded, removed or executed during the check.