Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
UnbearableDev avatar

Dockerfile Audit

  • Updated June 1, 2026
  • UnbearableDev/dockerfile-audit

io.github.UnbearableDev/dockerfile-audit is a MCP server that runs nineteen Hadolint-grade Dockerfile checks for secrets, privileges, supply chain, and hygiene.

About

io.github.UnbearableDev/dockerfile-audit is a Model Context Protocol server that audits Dockerfiles with nineteen checks in the spirit of Hadolint, spanning leaked credentials, excessive privileges, supply-chain choices, and everyday Dockerfile hygiene. Developers who containerize backends, agents, or side projects can point Claude Code, Cursor, or similar clients at the remote endpoint instead of wiring a separate lint job on every machine. The server is suited to the Ship phase when you are validating images before registry push or production deploy, though you can also run it right after editing a Dockerfile during Build. You register an Apify API token as a Bearer secret on the MCP remote URL, then invoke audit tools from the agent against Dockerfile content you paste or attach. It is an integration-style MCP tool, not a planning skill: it returns structured findings your agent can turn into fix commits or PR comments. Pair it with your existing build scripts or GitHub Actions once issues are flagged.

  • 19 Hadolint-grade checks covering secrets, privileges, supply chain, and general hygiene
  • Remote streamable-http MCP endpoint hosted on Apify with Bearer token auth
  • Targets solo builders shipping Dockerized apps without running local lint pipelines
  • Findings align with common CI gate categories for image build pipelines
  • Version 1.0.0 server from UnbearableDev on GitHub

Dockerfile Audit by the numbers

  • Data as of Jul 7, 2026 (Skillselion catalog sync)
terminal
claude mcp add --transport http dockerfile-audit https://unbearable-dev--dockerfile-audit.apify.actor/mcp --header "Authorization: Bearer YOUR_TOKEN"

Add your badge

Show developers this MCP server is listed on Skillselion. Paste this into your README.

Listed on Skillselion
TransportHTTP
AuthRequired
Last updatedJune 1, 2026
RepositoryUnbearableDev/dockerfile-audit

What it does

Run Hadolint-style Dockerfile reviews from your agent before you build or push images to catch secrets, root users, and supply-chain risks.

Who is it for?

Best when you maintain one or more Dockerfiles and want agent-driven audits without installing Hadolint locally on every laptop.

Skip if: Skip if you already enforce comprehensive image scanning and policy-as-code in CI and do not need an extra MCP audit path.

What you get

After you connect the server, your agent can audit Dockerfiles on demand and surface prioritized fixes before images reach your registry or cluster.

  • Structured audit results across nineteen Dockerfile check categories
  • Actionable findings on secrets, privileges, supply chain, and hygiene
  • Agent-ready summary you can paste into PRs or fix tickets

By the numbers

  • 19 Dockerfile audit checks documented in the server description
  • Remote MCP version 1.0.0 via Apify actor unbearable-dev--dockerfile-audit
README.md

Dockerfile Security & Quality Audit

Hadolint-grade Dockerfile audit as an MCP server. 18+ checks across 5 categories, every finding ships with severity, line number, remediation text, and a copy-paste Dockerfile snippet.

Built by Unbearable Labs. Pay-per-event pricing — only billed when a tool is actually called.


Available on

  • Apify Actor Store — primary, metered usage (PPE)
  • MCPize — pending submission
  • MCP.so — pending submission
  • PulseMCP — pending submission
  • Smithery — pending submission
  • Glama — pending submission

Newsletter: Unbearable TechTips Weekly · All Actors: github.com/UnbearableDev

What it does

Point any MCP-capable client (Claude Desktop, Cursor, n8n, Make, Zapier, custom agents) at this server, hand it a Dockerfile, get back a structured report:

  • Severity — high / medium / low / info
  • Line number — exact location in the file
  • Description — what's wrong and why it matters
  • Remediation — what to do about it
  • Fix snippet — Dockerfile syntax you can paste directly

Tools

Tool Purpose
audit_dockerfile(dockerfile_content? | dockerfile_url?, min_severity='low') Run all checks
check_base_image(...) FROM/tag/digest/registry checks only
check_instructions(...) CMD form, ADD vs COPY, MAINTAINER, etc.
check_security(...) USER, sudo, chmod 777, curl|bash, hardcoded secrets, HEALTHCHECK
check_efficiency(...) apt cache hygiene, pip caching
check_secrets(...) ARG with secret-pattern names
list_checks(category?) Browse the full check catalog

Provide exactly one of dockerfile_content (paste the file) or dockerfile_url (HTTPS URL — e.g. GitHub raw).

Check catalog (v1: 18 checks across 5 categories)

ID Category Severity Title
DFA-001 base_image medium Image uses :latest tag or no tag
DFA-002 base_image info No SHA256 digest pin on FROM
DFA-003 base_image medium Untrusted registry
DFA-010 instructions low CMD in shell form
DFA-011 instructions low ENTRYPOINT in shell form
DFA-012 instructions info MAINTAINER instruction is deprecated
DFA-013 instructions medium ADD used where COPY would suffice
DFA-020 security medium No USER directive (runs as root)
DFA-021 security high USER root set explicitly
DFA-022 security high sudo invoked in RUN
DFA-023 security high chmod 777 in RUN
DFA-024 security medium curl|bash pattern in RUN
DFA-025 security high Hardcoded secret in ENV
DFA-027 security low No HEALTHCHECK
DFA-030 efficiency low apt-get update without install
DFA-031 efficiency low apt-get install without --no-install-recommends
DFA-032 efficiency low pip install without --no-cache-dir
DFA-040 secrets medium ARG with secret-pattern name

Use list_checks to get the canonical, up-to-date catalog.

Pricing

Event USD
Any audit / check_* tool call $0.02
list_checks discovery $0.005

Example response (truncated)

{
  "summary": {
    "total_findings": 6,
    "by_severity": {"high": 2, "medium": 2, "low": 2, "info": 0}
  },
  "findings": [
    {
      "id": "DFA-021",
      "category": "security",
      "severity": "high",
      "instruction": "USER",
      "line_number": 3,
      "title": "USER root set explicitly",
      "description": "...",
      "remediation": "Switch to a non-root UID after any root-required RUN steps.",
      "fix_dockerfile_snippet": "USER 10001:10001",
      "references": ["CIS-Docker-4.1"]
    }
  ]
}

Connecting from Claude Desktop

{
  "mcpServers": {
    "dockerfile-audit": {
      "transport": "streamable-http",
      "url": "https://YOUR-ACTOR-URL.apify.actor/mcp"
    }
  }
}

Limits

  • Dockerfile size: 200 KB cap per audit
  • URL fetch: 5s timeout, max 3 redirects, HTTPS only
  • Session timeout: 5 minutes of inactivity

What's NOT covered (yet)

  • Live image vulnerability scanning (use Trivy / Grype for that)
  • Multi-stage build optimization analysis (DFA-004 / DFA-005 — roadmapped)
  • Compose-file audit (separate MCP: docker-compose-audit)

Sibling MCPs from Unbearable Labs

Source / contact

Issues and ideas: unbearabledev@gmail.com or the GitHub org UnbearableDev.

Recommended MCP Servers

How it compares

Remote Dockerfile lint MCP integration, not an in-repo Claude skill or full container runtime scanner.

FAQ

Who is io.github.UnbearableDev/dockerfile-audit for?

It is for developers and small teams who use AI coding agents to harden Dockerfiles before ship, especially when local Hadolint is not always installed.

When should I use io.github.UnbearableDev/dockerfile-audit?

Use it when you change a Dockerfile, before merging a container PR, or when you want a quick security and hygiene pass without opening a separate terminal workflow.

How do I add io.github.UnbearableDev/dockerfile-audit to my agent?

Add the Apify streamable-http MCP remote URL from the server manifest, set Authorization to Bearer plus your Apify API token from console.apify.com, then restart or refresh MCP in Claude Code, Cursor, or a compatible client.

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.