
Dockerfile Security Audit
io.github.tylerscomic-labv1.0.0Updated Oct 2, 2026
Audit Dockerfiles for root users, baked-in secrets, curl-pipe-shell and unpinned base images.
Overview
Audits Dockerfiles for container-security anti-patterns such as root users, baked-in secrets, curl-pipe-shell, and unpinned base images.
- What it does
- Parses Dockerfile structure directly — instructions, backslash line continuations, and multi-stage builds — rather than scanning raw text with regex. Its audit_dockerfile tool returns a risk level plus every finding with its exact location, why it matters, and a concrete fix. It checks for a missing or root USER in the final shipping stage, secret-shaped ENV/ARG values, curl-pipe-shell and wget-pipe-bash patterns, unpinned or latest base images, and ADD with a remote URL.
- When to use it
- Useful when reviewing or hardening container images, or when an assistant is asked to check a Dockerfile before it is committed or built. It fits teams that want a second opinion on Dockerfile security without running a full linter pipeline.
- Requirements
- The hosted server is a remote streamable HTTP endpoint, so no local runtime or package install is needed. The README also describes a self-hosted option that requires Node.js and npm. No accounts, API keys, or environment variables are declared.
Installation
In SourceWeft
- Open Dockerfile Security Audit in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"dockerfile-audit-mcp": {
"type": "http",
"url": "https://dockerfile-audit-mcp.mcpize.run/mcp"
}
}
}README
dockerfile-audit-mcp
[License: MIT] [Live on MCPize]
An MCP server that audits Dockerfiles for real container-security anti-patterns. Parses actual Dockerfile structure (instructions, backslash line continuations, multi-stage builds) via a hand-written parser, not regex over the raw text.
What it catches
Missing USER. If the final stage that actually ships has no USER instruction (or explicitly sets
USER root), every process in the running container has root privileges by default. Correctly checks only the
final stage — matching real linter convention (hadolint's DL3002), since multi-stage builds exist specifically so
earlier build-only stages' root steps never ship.
Baked-in secrets. ENV/ARG values assigned to secret-shaped names (API_KEY, PASSWORD, *_TOKEN,
STRIPE_*_KEY, etc.) land permanently in the image's layer history — visible via docker history --no-trunc to
anyone who pulls the image, even after a later layer unsets the variable. Placeholder-looking values
(<your-key>, changeme) and bare ARG declarations with no default are correctly not flagged.
curl | sh / wget | bash. Pipes a remote script directly into a shell at build time with no integrity
check — if the host is compromised or the script changes, every future build silently pulls in whatever it now
serves.
Unpinned base images. :latest or no tag at all means the base your image builds on can change between builds
with nothing in the Dockerfile to explain why.
ADD with a remote URL. Same unverified-fetch problem as curl | sh, via a different instruction.
Tools
audit_dockerfile
Full audit. Returns a risk level and every finding with its exact location, why it matters, and a concrete fix.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
Part of a small suite
github-actions-audit-mcp, regex-safety-audit-mcp, secrets-leak-audit-mcp, mcp-trust-audit-mcp.
License
MIT
Source: README.md at commit f33376b
Tools
0Version history
1- v1.0.0LatestOct 2, 2026