Server data from the Official MCP Registry
Audit Dockerfiles for root users, baked-in secrets, curl-pipe-shell and unpinned base images.
About
Audit Dockerfiles for root users, baked-in secrets, curl-pipe-shell and unpinned base images.
Remote endpoints: streamable-http: https://dockerfile-audit-mcp.mcpize.run/mcp
Security Report
Valid MCP server (3 strong, 3 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry. Trust signals: trusted author (4/4 approved).
Endpoint verified · Requires authentication · 1 issue found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Found in Source Code
Found by scanning the linked source code. This listing connects to a hosted endpoint, so none of this runs on your machine: it describes what the server software does where it is hosted.
How to Connect
Remote Plugin
No local installation needed. Your AI client connects to the remote endpoint directly.
Add this to your MCP configuration to connect:
{
"mcpServers": {
"io-github-tylerscomic-lab-dockerfile-audit-mcp": {
"url": "https://dockerfile-audit-mcp.mcpize.run/mcp"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
dockerfile-audit-mcp
An MCP server that audits Dockerfiles for real container-security anti-patterns. Parses actual Dockerfile structure (instructions, backslash line continuations, multi-stage builds) via a hand-written parser, not regex over the raw text.
What it catches
Missing USER. If the final stage that actually ships has no USER instruction (or explicitly sets
USER root), every process in the running container has root privileges by default. Correctly checks only the
final stage — matching real linter convention (hadolint's DL3002), since multi-stage builds exist specifically so
earlier build-only stages' root steps never ship.
Baked-in secrets. ENV/ARG values assigned to secret-shaped names (API_KEY, PASSWORD, *_TOKEN,
STRIPE_*_KEY, etc.) land permanently in the image's layer history — visible via docker history --no-trunc to
anyone who pulls the image, even after a later layer unsets the variable. Placeholder-looking values
(<your-key>, changeme) and bare ARG declarations with no default are correctly not flagged.
curl | sh / wget | bash. Pipes a remote script directly into a shell at build time with no integrity
check — if the host is compromised or the script changes, every future build silently pulls in whatever it now
serves.
Unpinned base images. :latest or no tag at all means the base your image builds on can change between builds
with nothing in the Dockerfile to explain why.
ADD with a remote URL. Same unverified-fetch problem as curl | sh, via a different instruction.
Tools
audit_dockerfile
Full audit. Returns a risk level and every finding with its exact location, why it matters, and a concrete fix.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
npm install
node server.js
Part of a small suite
github-actions-audit-mcp, regex-safety-audit-mcp, secrets-leak-audit-mcp, mcp-trust-audit-mcp.
License
MIT
Reviews
No reviews yet
Be the first to review this server!
More Cloud & DevOps MCP Servers
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
by Lharries · Communication
Read, search, and send WhatsApp messages through your AI assistant
Google Workspace MCP
Freeby Taylorwilsdon · Productivity
Control Gmail, Calendar, Docs, Sheets, Drive, and more from your AI
