Dockerfile Security Audit

io.github.tylerscomic-labv1.0.0更新于 Oct 2, 2026

Audit Dockerfiles for root users, baked-in secrets, curl-pipe-shell and unpinned base images.

已验证Streamable HTTP可网页运行Security & MonitoringDeveloper ToolsCloud & Infrastructure

概览

AI 生成的概览

审计 Dockerfile 中的容器安全反模式,例如 root 用户、内置密钥、curl 管道执行 shell 以及未固定版本的基础镜像。

功能
直接解析 Dockerfile 结构(指令、反斜杠续行、多阶段构建),而不是用正则扫描原始文本。其 audit_dockerfile 工具会返回风险等级以及每条发现的精确位置、原因和具体修复建议。检查项包括最终发布阶段缺少 USER 或使用 root、形似密钥的 ENV/ARG 值、curl 管道 shell 与 wget 管道 bash 模式、未固定或 latest 基础镜像,以及带远程 URL 的 ADD。
适用场景
适合在审查或加固容器镜像时使用,也适合让助手在 Dockerfile 提交或构建前进行检查。对于希望在不搭建完整 linter 流水线的情况下获得 Dockerfile 安全第二意见的团队很有用。
运行要求
托管版本是远程 streamable HTTP 端点,无需本地运行时或安装包。README 还描述了自托管方式,需要 Node.js 和 npm。未声明账户、API 密钥或环境变量。
安装前请注意
托管版本是第三方服务,提供免费套餐和付费 Pro 方案,因此 Dockerfile 内容会发送到该远程端点。审计仅为建议性质,不会修改文件;采取行动前仍应人工复核发现的问题。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Dockerfile Security Audit,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "dockerfile-audit-mcp": {
      "type": "http",
      "url": "https://dockerfile-audit-mcp.mcpize.run/mcp"
    }
  }
}

README

dockerfile-audit-mcp

[License: MIT] [Live on MCPize]

An MCP server that audits Dockerfiles for real container-security anti-patterns. Parses actual Dockerfile structure (instructions, backslash line continuations, multi-stage builds) via a hand-written parser, not regex over the raw text.

What it catches

Missing USER. If the final stage that actually ships has no USER instruction (or explicitly sets USER root), every process in the running container has root privileges by default. Correctly checks only the final stage — matching real linter convention (hadolint's DL3002), since multi-stage builds exist specifically so earlier build-only stages' root steps never ship.

Baked-in secrets. ENV/ARG values assigned to secret-shaped names (API_KEY, PASSWORD, *_TOKEN, STRIPE_*_KEY, etc.) land permanently in the image's layer history — visible via docker history --no-trunc to anyone who pulls the image, even after a later layer unsets the variable. Placeholder-looking values (<your-key>, changeme) and bare ARG declarations with no default are correctly not flagged.

curl | sh / wget | bash. Pipes a remote script directly into a shell at build time with no integrity check — if the host is compromised or the script changes, every future build silently pulls in whatever it now serves.

Unpinned base images. :latest or no tag at all means the base your image builds on can change between builds with nothing in the Dockerfile to explain why.

ADD with a remote URL. Same unverified-fetch problem as curl | sh, via a different instruction.

Tools

audit_dockerfile

Full audit. Returns a risk level and every finding with its exact location, why it matters, and a concrete fix.

Use it

Hosted (recommended): MCPize — free tier, $7/mo Pro.

Self-host:

bash
npm installnode server.js

Part of a small suite

github-actions-audit-mcp, regex-safety-audit-mcp, secrets-leak-audit-mcp, mcp-trust-audit-mcp.

License

MIT

来源:README.md,提交 f33376b

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.0.0最新Oct 2, 2026