dockerfile-audit-mcp
by Tyler FrancisUpdated Oct 1, 2026
Audits Dockerfiles for missing USER instructions, credentials baked into ENV/ARG, curl-pipe-shell patterns, unpinned :latest base images, and remote-URL ADD instructions. Handles multi-stage builds correctly (only the final shipped stage's USER matters).
security
docker
dockerfile
+4
|How to pay
Subscribe
Monthly billing
$12/month
Predictable monthly cost with included usage. Best for steady, high-volume traffic.
- Unlimited tools within plan limits
- One API key, billed once a month
- Cancel any time
Dockerfile security review in one call
Audits a Dockerfile for the issues that most often ship to production.
What it catches
- Missing USER: the container runs as root. Multi-stage builds are handled correctly, only the final shipped stage counts.
- Credentials baked into ENV or ARG, which persist in image layers.
- curl-pipe-shell installs.
- Unpinned :latest base images.
- Remote-URL ADD instructions.
Tool
- audit_dockerfile: returns findings with line numbers and a concrete fix for each.
Pricing
Free: 10 audits a day. Pro: unlimited. Static, deterministic checks, no LLM calls, no data stored. Your input is analysed in memory and discarded.