Dockerfile Security Audit
Server Details
Audit Dockerfiles for root users, baked-in secrets, curl-pipe-shell and unpinned base images.
Glama couldn't complete the latest health check. If this server requires authentication, missing or expired test credentials may be the cause. A test profile lets Glama authenticate for health checks and discover tools; it is separate from your personal connections.
If you are the author, claim ownership, then add or update a test profile under Admin → Test Profile.
- Status
- Unhealthy
- OAuth
- Works in Glama
- Last Tested
- Transport
- Streamable HTTP
- URL
- Repository
- tylerscomic-lab/dockerfile-audit-mcp
- GitHub Stars
- 0
- Server Listing
- dockerfile-audit-mcp
Related MCP Connectors
Hadolint-grade Dockerfile audit — 19 checks: secrets, privileges, supply chain, hygiene.
Audit GitHub Actions workflows for script injection, unpinned actions and missing permissions.
1Security audit for docker-compose.yml — 25 checks: secrets, privileges, network, volumes, images.
Four IaC audits in one call: Compose, Dockerfile, GitHub Actions, Kubernetes. 131 checks.
Related MCP Servers
- AlicenseAqualityCmaintenanceEnables agents to validate Dockerfiles for build-breaking syntax errors, risky patterns like root users and secrets in ENV/ARG, and cache-order problems, returning every finding with its line and a fix. It also verifies referenced container images against public registries, reporting tag existence, digests to pin, supported platforms, last rebuild time, and end-of-life status with an upgrade tag.2MIT
- FlicenseNot gradedqualityDmaintenanceAudits GitHub Actions workflow files for supply-chain risks like script injection, leaked tokens, unpinned actions, and broad permissions.-
- FlicenseNot gradedqualityDmaintenanceAn MCP server that audits Dockerfiles for security and quality issues, providing structured reports with severity, line numbers, remediation, and fix snippets.-

EVIDIQ Bastionofficial
AlicenseNot gradedqualityBmaintenanceAudits infrastructure configurations (Dockerfiles, GitHub Actions, Kubernetes, Terraform/Compose) against 14 deterministic security rules, returning BLOCK/REVIEW/PASS verdicts and signing attestations. Helps agents verify deployment configs before applying them.1MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.