dockerfile-audit-mcp
Audits Dockerfiles for container-security anti-patterns, including missing USER, baked-in secrets, curl|sh pipelines, unpinned base images, and remote ADD URLs. Parses Dockerfile instructions, multi-stage builds, and line continuations to report findings with locations and fixes.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@dockerfile-audit-mcpaudit my Dockerfile for security issues"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
dockerfile-audit-mcp
An MCP server that audits Dockerfiles for real container-security anti-patterns. Parses actual Dockerfile structure (instructions, backslash line continuations, multi-stage builds) via a hand-written parser, not regex over the raw text.
What it catches
Missing USER. If the final stage that actually ships has no USER instruction (or explicitly sets
USER root), every process in the running container has root privileges by default. Correctly checks only the
final stage — matching real linter convention (hadolint's DL3002), since multi-stage builds exist specifically so
earlier build-only stages' root steps never ship.
Baked-in secrets. ENV/ARG values assigned to secret-shaped names (API_KEY, PASSWORD, *_TOKEN,
STRIPE_*_KEY, etc.) land permanently in the image's layer history — visible via docker history --no-trunc to
anyone who pulls the image, even after a later layer unsets the variable. Placeholder-looking values
(<your-key>, changeme) and bare ARG declarations with no default are correctly not flagged.
curl | sh / wget | bash. Pipes a remote script directly into a shell at build time with no integrity
check — if the host is compromised or the script changes, every future build silently pulls in whatever it now
serves.
Unpinned base images. :latest or no tag at all means the base your image builds on can change between builds
with nothing in the Dockerfile to explain why.
ADD with a remote URL. Same unverified-fetch problem as curl | sh, via a different instruction.
Related MCP server: docker-compose-audit
Tools
audit_dockerfile
Full audit. Returns a risk level and every finding with its exact location, why it matters, and a concrete fix.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
npm install
node server.jsPart of a small suite
github-actions-audit-mcp, regex-safety-audit-mcp, secrets-leak-audit-mcp, mcp-trust-audit-mcp.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Hadolint-grade Dockerfile audit — 19 checks: secrets, privileges, supply chain, hygiene.
Security audit for docker-compose.yml — 25 checks: secrets, privileges, network, volumes, images.
Four IaC audits in one call: Compose, Dockerfile, GitHub Actions, Kubernetes. 131 checks.
Detects database migration table locks, terraform cost leaks, and OWASP API flaws.
Related MCP Servers
- AlicenseAqualityDmaintenanceSecurity auditor for CI ecosystems that detects supply-chain and injection flaws in CI/CD configuration files across seven CI platforms, providing taint analysis, remediation, and compliance scoring.2MIT
- FlicenseNot gradedqualityDmaintenanceAudits docker-compose.yml files for security misconfigurations, providing severity ratings, remediation text, and YAML fix snippets for AI agents.-
- FlicenseNot gradedqualityDmaintenanceAn MCP server that audits Dockerfiles for security and quality issues, providing structured reports with severity, line numbers, remediation, and fix snippets.-
- FlicenseNot gradedqualityDmaintenanceAudits GitHub Actions workflow files for supply-chain risks like script injection, leaked tokens, unpinned actions, and broad permissions.-