Dockerfile Audit MCP Server

Hadolint-grade Dockerfile audit — 19 checks: secrets, privileges, supply chain, hygiene.

Local serverstdio

What is the Dockerfile Audit MCP server?

Most developer tooling work still happens through a UI a human drives. Dockerfile Audit MCP server moves it into the conversation instead. Hadolint-grade Dockerfile audit — 19 checks: secrets, privileges, supply chain, hygiene.

The short version

Point any MCP-capable client (Claude Desktop, Cursor, n8n, Make, Zapier, custom agents) at this server, hand it a Dockerfile, get back a structured report:

  • Severity — — high / medium / low / info
  • Line number — — exact location in the file
  • Description — — what's wrong and why it matters
  • Remediation — — what to do about it
  • Fix snippet — — Dockerfile syntax you can paste directly

Getting it running

The server ships on PyPI as without, so your MCP client can launch it on demand — there is no separate build step. Add the server block to your client's configuration, restart it, and the tools register themselves.

How it compares

This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. It is maintained by UnbearableDev; worth a glance at recent repository activity before you build anything load-bearing on it.

We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.

Things to watch

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Keep per-call confirmation enabled while you learn its behaviour; it is the cheapest safeguard you have.

How to install the Dockerfile Audit MCP server

{
  "mcpServers": {
    "dockerfile-audit": {
      "transport": "streamable-http",
      "url": "https://YOUR-ACTOR-URL.apify.actor/mcp"
    }
  }
}

Configuration as documented by the project. Restart the client after saving.

Frequently asked questions

It connects Dockerfile Audit to MCP-compatible AI assistants such as Claude and Cursor. Instead of copying data back and forth by hand, the assistant works with Dockerfile Audit directly.