Skip to main content
ClaudeWave
tylerscomic-lab avatar
tylerscomic-lab

dockerfile-audit-mcp

View on GitHub
MCP ServersOfficial Registry0 stars0 forks● JavaScriptMITUpdated today
ClaudeWave Trust Score
77/100
✓ Trusted
Passed
  • ✓Open-source license (MIT)
  • ✓Actively maintained (<30d)
  • ✓Topics declared
  • ✓Documented (README)
Flags
  • !No description
  • !Install pipes a remote script into a shell (curl | sh)
Last scanned: 10/2/2026
Install in Claude Code / Claude Desktop
Method: Manual
Claude Code CLI
git clone https://github.com/tylerscomic-lab/dockerfile-audit-mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "dockerfile-audit-mcp": {
      "command": "node",
      "args": ["/path/to/dockerfile-audit-mcp/dist/index.js"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Clone https://github.com/tylerscomic-lab/dockerfile-audit-mcp and follow its README for install instructions.
Use cases

MCP Servers overview

# dockerfile-audit-mcp

[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)
[![Live on MCPize](https://img.shields.io/badge/Live%20on-MCPize-6d28d9)](https://mcpize.com/mcp/dockerfile-audit-mcp)

An MCP server that audits Dockerfiles for real container-security anti-patterns. Parses actual Dockerfile
structure (instructions, backslash line continuations, multi-stage builds) via a hand-written parser, not regex
over the raw text.

## What it catches

**Missing `USER`.** If the final stage that actually ships has no `USER` instruction (or explicitly sets
`USER root`), every process in the running container has root privileges by default. Correctly checks **only the
final stage** — matching real linter convention (hadolint's DL3002), since multi-stage builds exist specifically so
earlier build-only stages' root steps never ship.

**Baked-in secrets.** `ENV`/`ARG` values assigned to secret-shaped names (`API_KEY`, `PASSWORD`, `*_TOKEN`,
`STRIPE_*_KEY`, etc.) land permanently in the image's layer history — visible via `docker history --no-trunc` to
anyone who pulls the image, even after a later layer unsets the variable. Placeholder-looking values
(`<your-key>`, `changeme`) and bare `ARG` declarations with no default are correctly not flagged.

**`curl | sh` / `wget | bash`.** Pipes a remote script directly into a shell at build time with no integrity
check — if the host is compromised or the script changes, every future build silently pulls in whatever it now
serves.

**Unpinned base images.** `:latest` or no tag at all means the base your image builds on can change between builds
with nothing in the Dockerfile to explain why.

**`ADD` with a remote URL.** Same unverified-fetch problem as `curl | sh`, via a different instruction.

## Tools

### `audit_dockerfile`
Full audit. Returns a risk level and every finding with its exact location, why it matters, and a concrete fix.

## Use it

**Hosted (recommended):** [MCPize](https://mcpize.com/mcp/dockerfile-audit-mcp) — free tier, $7/mo Pro.

**Self-host:**
```bash
npm install
node server.js
```

## Part of a small suite

[github-actions-audit-mcp](https://github.com/tylerscomic-lab/github-actions-audit-mcp),
[regex-safety-audit-mcp](https://github.com/tylerscomic-lab/regex-safety-audit-mcp),
[secrets-leak-audit-mcp](https://github.com/tylerscomic-lab/secrets-leak-audit-mcp),
[mcp-trust-audit-mcp](https://github.com/tylerscomic-lab/mcp-trust-audit-mcp).

## License

MIT
dockerdockerfilemcpmcp-servermodel-context-protocolsecurity

What people ask about dockerfile-audit-mcp

What is tylerscomic-lab/dockerfile-audit-mcp?

+

tylerscomic-lab/dockerfile-audit-mcp is mcp servers for the Claude AI ecosystem with 0 GitHub stars.

How do I install dockerfile-audit-mcp?

+

You can install dockerfile-audit-mcp by cloning the repository (https://github.com/tylerscomic-lab/dockerfile-audit-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is tylerscomic-lab/dockerfile-audit-mcp safe to use?

+

Our security agent has analyzed tylerscomic-lab/dockerfile-audit-mcp and assigned a Trust Score of 77/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.

Who maintains tylerscomic-lab/dockerfile-audit-mcp?

+

tylerscomic-lab/dockerfile-audit-mcp is maintained by tylerscomic-lab. The last recorded GitHub activity is dated 2026-10-01, with 0 open issues.

Are there alternatives to dockerfile-audit-mcp?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy dockerfile-audit-mcp to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: tylerscomic-lab/dockerfile-audit-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/tylerscomic-lab-dockerfile-audit-mcp)](https://claudewave.com/repo/tylerscomic-lab-dockerfile-audit-mcp)
<a href="https://claudewave.com/repo/tylerscomic-lab-dockerfile-audit-mcp"><img src="https://claudewave.com/api/badge/tylerscomic-lab-dockerfile-audit-mcp" alt="Featured on ClaudeWave: tylerscomic-lab/dockerfile-audit-mcp" width="320" height="64" /></a>

More MCP Servers

dockerfile-audit-mcp alternatives