Skip to main content
Glama

docker/prune

DestructiveIdempotent

Reclaim disk space by deleting one kind of unused Docker object per call: stopped containers, dangling images, anonymous volumes, unused networks, or build-cache.

Instructions

Deletes ONE kind of unused Docker object per call: target is containers (stopped), images (dangling only), volumes (anonymous, unused only; named volumes are never touched), networks (unused) or build-cache. Mutating and irreversible, and it deletes objects you did not name; call again for the next kind (pruning containers is what makes images dangling). The user's grant needs a prune: list containing the target, otherwise the call is refused before anything is deleted. Always runs as root: no privileged argument, refused unless the grant has allowed: true. The 30 s worker limit can end the call while the Engine keeps pruning. Text is TARGET: N removed, X MiB reclaimed plus the removed IDs (networks report no size); output_format: json returns target, deleted, count, space_reclaimed_bytes. To remove one named container use docker/manage (remove); to see what exists first docker/containers, docker/images, docker/volumes, docker/networks.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
targetYesThe one kind to reclaim: containers (stopped), images (dangling), volumes (anonymous, unused), networks (unused) or build-cache
output_formatNojson returns target, deleted, count, space_reclaimed_bytes; default is text

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.4.1

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true and readOnlyHint=false, but the description goes well beyond them: needed grant (`prune:` list containing the target, else refused before deletion), root execution with no `privileged` argument, `allowed: true` requirement, and the 30 s worker timeout that can end the call while the Engine keeps pruning. It also describes the exact return text and the JSON shape, which the annotations cannot convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

One dense paragraph, front-loaded with the target enumeration and the irreversibility warning before the routing and output detail. Every sentence carries information, though the return-format sentence is long enough that a human reader would benefit from splitting it out.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, and the description compensates by describing both text and json return shapes. Combined with grant/permission requirements, timeout caveats, irreversibility, and sibling alternatives, an agent has everything needed to call this correctly on the first try.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds genuine semantics beyond the schema: the volume distinction (anonymous/unused only; named volumes never touched) and the concrete json fields (target, deleted, count, space_reclaimed_bytes) plus the fact that networks report no size. That is more than restating the enum.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (deletes) and resource (unused Docker objects), then enumerates the exact five targets and each one's scope (stopped containers, dangling images, anonymous unused volumes, unused networks, build-cache). It explicitly separates itself from docker/manage (`remove`) and the listing tools, so an agent can disambiguate without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives explicit when-to-use routing (prune for bulk unused objects; `docker/manage` with `remove` for one named container) and when-not (named volumes are never touched). It also explains the ordering prerequisite that pruning containers is what makes images dangling, which is real operational guidance, not filler.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.