dockerfile-audit-mcp logo

dockerfile-audit-mcp

by Tyler FrancisUpdated Oct 1, 2026

Audits Dockerfiles for missing USER instructions, credentials baked into ENV/ARG, curl-pipe-shell patterns, unpinned :latest base images, and remote-URL ADD instructions. Handles multi-stage builds correctly (only the final shipped stage's USER matters).

security
docker
dockerfile
+4
|

How to pay

Subscribe

Monthly billing

$12/month

Predictable monthly cost with included usage. Best for steady, high-volume traffic.

  • Unlimited tools within plan limits
  • One API key, billed once a month
  • Cancel any time

Dockerfile security review in one call

Audits a Dockerfile for the issues that most often ship to production.

What it catches

  • Missing USER: the container runs as root. Multi-stage builds are handled correctly, only the final shipped stage counts.
  • Credentials baked into ENV or ARG, which persist in image layers.
  • curl-pipe-shell installs.
  • Unpinned :latest base images.
  • Remote-URL ADD instructions.

Tool

  • audit_dockerfile: returns findings with line numbers and a concrete fix for each.

Pricing

Free: 10 audits a day. Pro: unlimited. Static, deterministic checks, no LLM calls, no data stored. Your input is analysed in memory and discarded.