
Dockerfile Security Audit
io.github.tylerscomic-labv1.0.0更新於 Oct 2, 2026
Audit Dockerfiles for root users, baked-in secrets, curl-pipe-shell and unpinned base images.
概覽
稽核 Dockerfile 中的容器安全反模式,例如 root 使用者、內嵌機密、curl 管線執行 shell,以及未固定版本的基礎映像。
- 功能
- 直接解析 Dockerfile 結構(指令、反斜線續行、多階段建置),而非用正規表達式掃描原始文字。其 audit_dockerfile 工具會回傳風險等級,以及每項發現的精确位置、原因和具體修正建議。檢查項目包括最終出貨階段缺少 USER 或使用 root、形似機密的 ENV/ARG 值、curl 管線 shell 與 wget 管線 bash 模式、未固定或 latest 基礎映像,以及帶遠端 URL 的 ADD。
- 適用情境
- 適合在審查或強化容器映像時使用,也適合讓助理在 Dockerfile 提交或建置前先行檢查。對於想在不架設完整 linter 流程的情況下,取得 Dockerfile 安全第二意見的團隊很有用。
- 執行需求
- 託管版本是遠端 streamable HTTP 端點,不需要本機執行環境或安裝套件。README 也說明了自架方式,需要 Node.js 與 npm。未宣告帳號、API 金鑰或環境變數。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Dockerfile Security Audit,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"dockerfile-audit-mcp": {
"type": "http",
"url": "https://dockerfile-audit-mcp.mcpize.run/mcp"
}
}
}README
dockerfile-audit-mcp
[License: MIT] [Live on MCPize]
An MCP server that audits Dockerfiles for real container-security anti-patterns. Parses actual Dockerfile structure (instructions, backslash line continuations, multi-stage builds) via a hand-written parser, not regex over the raw text.
What it catches
Missing USER. If the final stage that actually ships has no USER instruction (or explicitly sets
USER root), every process in the running container has root privileges by default. Correctly checks only the
final stage — matching real linter convention (hadolint's DL3002), since multi-stage builds exist specifically so
earlier build-only stages' root steps never ship.
Baked-in secrets. ENV/ARG values assigned to secret-shaped names (API_KEY, PASSWORD, *_TOKEN,
STRIPE_*_KEY, etc.) land permanently in the image's layer history — visible via docker history --no-trunc to
anyone who pulls the image, even after a later layer unsets the variable. Placeholder-looking values
(<your-key>, changeme) and bare ARG declarations with no default are correctly not flagged.
curl | sh / wget | bash. Pipes a remote script directly into a shell at build time with no integrity
check — if the host is compromised or the script changes, every future build silently pulls in whatever it now
serves.
Unpinned base images. :latest or no tag at all means the base your image builds on can change between builds
with nothing in the Dockerfile to explain why.
ADD with a remote URL. Same unverified-fetch problem as curl | sh, via a different instruction.
Tools
audit_dockerfile
Full audit. Returns a risk level and every finding with its exact location, why it matters, and a concrete fix.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
Part of a small suite
github-actions-audit-mcp, regex-safety-audit-mcp, secrets-leak-audit-mcp, mcp-trust-audit-mcp.
License
MIT
來源:README.md,提交 f33376b
工具
0版本歷史
1- v1.0.0最新Oct 2, 2026
