Dockerfile Audit

io.github.UnbearableDevv1.0.0更新於 Oct 9, 2026

Hadolint-grade Dockerfile audit — 19 checks: secrets, privileges, supply chain, hygiene.

已驗證Streamable HTTP可網頁執行Cloud & InfrastructureDeveloper ToolsSecurity & Monitoring

概覽

AI 產生的概覽

稽核 Dockerfile 的安全性、基礎映像、指令、效率與密鑰問題,回傳依嚴重程度排序的發現與修正建議。

功能
對以貼上內容或 HTTPS URL 提供的 Dockerfile 執行 Hadolint 風格的靜態檢查。工具包括執行全部檢查的 audit_dockerfile,以及 check_base_image、check_instructions、check_security、check_efficiency、check_secrets 和 list_checks。每筆發現都會提供嚴重程度、行號、說明、修正建議與可直接貼上的 Dockerfile 片段。它不會掃描已建置映像的漏洞。
適用情境
適合在建置或發布映像前檢視與強化 Dockerfile,或讓助理說明並修正容器安全與規範問題。它是靜態檢視輔助工具,不能取代映像漏洞掃描器。
執行需求
遠端 streamable HTTP 端點,不需要本機套件或執行環境。需要在 Authorization 標頭中以 'Bearer ' 形式提供 Apify API 權杖。稽核依工具呼叫計費,URL 輸入必須為 HTTPS。
安裝前請注意
Authorization 標頭攜帶 Apify API 權杖,應視為機密。採用以事件計費:audit 與 check_* 呼叫每次 0.02 美元,list_checks 為 0.005 美元。Dockerfile 內容或抓取的 URL 會傳送到遠端服務,請避免貼上含真實憑證的檔案。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Dockerfile Audit,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "dockerfile-audit": {
      "type": "http",
      "url": "https://unbearable-dev--dockerfile-audit.apify.actor/mcp"
    }
  }
}

README

Dockerfile Security & Quality Audit

Hadolint-grade Dockerfile audit as an MCP server. 18+ checks across 5 categories, every finding ships with severity, line number, remediation text, and a copy-paste Dockerfile snippet.

Built by Unbearable Labs. Pay-per-event pricing — only billed when a tool is actually called.


Available on

  • Apify Actor Store — primary, metered usage (PPE)
  • MCPize — pending submission
  • MCP.so — pending submission
  • PulseMCP — pending submission
  • Smithery — pending submission
  • Glama — pending submission

Newsletter: Unbearable TechTips Weekly · All Actors: github.com/UnbearableDev

What it does

Point any MCP-capable client (Claude Desktop, Cursor, n8n, Make, Zapier, custom agents) at this server, hand it a Dockerfile, get back a structured report:

  • Severity — high / medium / low / info
  • Line number — exact location in the file
  • Description — what's wrong and why it matters
  • Remediation — what to do about it
  • Fix snippet — Dockerfile syntax you can paste directly

Tools

ToolPurpose
audit_dockerfile(dockerfile_content? | dockerfile_url?, min_severity='low')Run all checks
check_base_image(...)FROM/tag/digest/registry checks only
check_instructions(...)CMD form, ADD vs COPY, MAINTAINER, etc.
check_security(...)USER, sudo, chmod 777, curl|bash, hardcoded secrets, HEALTHCHECK
check_efficiency(...)apt cache hygiene, pip caching
check_secrets(...)ARG with secret-pattern names
list_checks(category?)Browse the full check catalog

Provide exactly one of dockerfile_content (paste the file) or dockerfile_url (HTTPS URL — e.g. GitHub raw).

Check catalog (v1: 18 checks across 5 categories)

IDCategorySeverityTitle
DFA-001base_imagemediumImage uses :latest tag or no tag
DFA-002base_imageinfoNo SHA256 digest pin on FROM
DFA-003base_imagemediumUntrusted registry
DFA-010instructionslowCMD in shell form
DFA-011instructionslowENTRYPOINT in shell form
DFA-012instructionsinfoMAINTAINER instruction is deprecated
DFA-013instructionsmediumADD used where COPY would suffice
DFA-020securitymediumNo USER directive (runs as root)
DFA-021securityhighUSER root set explicitly
DFA-022securityhighsudo invoked in RUN
DFA-023securityhighchmod 777 in RUN
DFA-024securitymediumcurl|bash pattern in RUN
DFA-025securityhighHardcoded secret in ENV
DFA-027securitylowNo HEALTHCHECK
DFA-030efficiencylowapt-get update without install
DFA-031efficiencylowapt-get install without --no-install-recommends
DFA-032efficiencylowpip install without --no-cache-dir
DFA-040secretsmediumARG with secret-pattern name

Use list_checks to get the canonical, up-to-date catalog.

Pricing

EventUSD
Any audit / check_* tool call$0.02
list_checks discovery$0.005

Example response (truncated)

json
{  "summary": {    "total_findings": 6,    "by_severity": {"high": 2, "medium": 2, "low": 2, "info": 0}  },  "findings": [    {      "id": "DFA-021",      "category": "security",      "severity": "high",      "instruction": "USER",      "line_number": 3,      "title": "USER root set explicitly",      "description": "...",      "remediation": "Switch to a non-root UID after any root-required RUN steps.",      "fix_dockerfile_snippet": "USER 10001:10001",      "references": ["CIS-Docker-4.1"]    }  ]}

Connecting from Claude Desktop

json
{  "mcpServers": {    "dockerfile-audit": {      "transport": "streamable-http",      "url": "https://YOUR-ACTOR-URL.apify.actor/mcp"    }  }}

Limits

  • Dockerfile size: 200 KB cap per audit
  • URL fetch: 5s timeout, max 3 redirects, HTTPS only
  • Session timeout: 5 minutes of inactivity

What's NOT covered (yet)

  • Live image vulnerability scanning (use Trivy / Grype for that)
  • Multi-stage build optimization analysis (DFA-004 / DFA-005 — roadmapped)
  • Compose-file audit (separate MCP: docker-compose-audit)

Sibling MCPs from Unbearable Labs

Source / contact

Issues and ideas: [email protected] or the GitHub org UnbearableDev.

來源:README.md,提交 6a17768

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Sep 16, 2026