Dockerfile Security Audit

io.github.tylerscomic-labv1.0.0Updated Oct 2, 2026

Audit Dockerfiles for root users, baked-in secrets, curl-pipe-shell and unpinned base images.

Overview

AI-generated overview

Audits Dockerfiles for container-security anti-patterns such as root users, baked-in secrets, curl-pipe-shell, and unpinned base images.

What it does
Parses Dockerfile structure directly — instructions, backslash line continuations, and multi-stage builds — rather than scanning raw text with regex. Its audit_dockerfile tool returns a risk level plus every finding with its exact location, why it matters, and a concrete fix. It checks for a missing or root USER in the final shipping stage, secret-shaped ENV/ARG values, curl-pipe-shell and wget-pipe-bash patterns, unpinned or latest base images, and ADD with a remote URL.
When to use it
Useful when reviewing or hardening container images, or when an assistant is asked to check a Dockerfile before it is committed or built. It fits teams that want a second opinion on Dockerfile security without running a full linter pipeline.
Requirements
The hosted server is a remote streamable HTTP endpoint, so no local runtime or package install is needed. The README also describes a self-hosted option that requires Node.js and npm. No accounts, API keys, or environment variables are declared.
Before you install
The hosted option is a third-party service with a free tier and a paid Pro plan, so Dockerfile contents are sent to that remote endpoint. The audit is advisory and does not modify files; findings should still be reviewed before acting on them.

Installation

In SourceWeft

  1. Open Dockerfile Security Audit in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "dockerfile-audit-mcp": {
      "type": "http",
      "url": "https://dockerfile-audit-mcp.mcpize.run/mcp"
    }
  }
}

README

dockerfile-audit-mcp

[License: MIT] [Live on MCPize]

An MCP server that audits Dockerfiles for real container-security anti-patterns. Parses actual Dockerfile structure (instructions, backslash line continuations, multi-stage builds) via a hand-written parser, not regex over the raw text.

What it catches

Missing USER. If the final stage that actually ships has no USER instruction (or explicitly sets USER root), every process in the running container has root privileges by default. Correctly checks only the final stage — matching real linter convention (hadolint's DL3002), since multi-stage builds exist specifically so earlier build-only stages' root steps never ship.

Baked-in secrets. ENV/ARG values assigned to secret-shaped names (API_KEY, PASSWORD, *_TOKEN, STRIPE_*_KEY, etc.) land permanently in the image's layer history — visible via docker history --no-trunc to anyone who pulls the image, even after a later layer unsets the variable. Placeholder-looking values (<your-key>, changeme) and bare ARG declarations with no default are correctly not flagged.

curl | sh / wget | bash. Pipes a remote script directly into a shell at build time with no integrity check — if the host is compromised or the script changes, every future build silently pulls in whatever it now serves.

Unpinned base images. :latest or no tag at all means the base your image builds on can change between builds with nothing in the Dockerfile to explain why.

ADD with a remote URL. Same unverified-fetch problem as curl | sh, via a different instruction.

Tools

audit_dockerfile

Full audit. Returns a risk level and every finding with its exact location, why it matters, and a concrete fix.

Use it

Hosted (recommended): MCPize — free tier, $7/mo Pro.

Self-host:

bash
npm installnode server.js

Part of a small suite

github-actions-audit-mcp, regex-safety-audit-mcp, secrets-leak-audit-mcp, mcp-trust-audit-mcp.

License

MIT

Source: README.md at commit f33376b

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.0LatestOct 2, 2026