Dockerfile Audit — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Dockerfile Audit (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Hadolint-grade Dockerfile audit as an MCP server. 18+ checks across 5 categories, every finding ships with severity, line number, remediation text, and a copy-paste Dockerfile snippet.
Built by [Unbearable Labs](https://github.com/UnbearableDev). Pay-per-event pricing — only billed when a tool is actually called.
Newsletter: Unbearable TechTips Weekly · All Actors: github.com/UnbearableDev
Point any MCP-capable client (Claude Desktop, Cursor, n8n, Make, Zapier, custom agents) at this server, hand it a Dockerfile, get back a structured report:
| Tool | Purpose | |
|---|---|---|
| `audit_dockerfile(dockerfile_content? \ | dockerfile_url?, min_severity='low')` | Run all checks |
check_base_image(...) | FROM/tag/digest/registry checks only | |
check_instructions(...) | CMD form, ADD vs COPY, MAINTAINER, etc. | |
check_security(...) | USER, sudo, chmod 777, curl\ | bash, hardcoded secrets, HEALTHCHECK |
check_efficiency(...) | apt cache hygiene, pip caching | |
check_secrets(...) | ARG with secret-pattern names | |
list_checks(category?) | Browse the full check catalog |
Provide exactly one of dockerfile_content (paste the file) or dockerfile_url (HTTPS URL — e.g. GitHub raw).
| ID | Category | Severity | Title | |
|---|---|---|---|---|
| DFA-001 | base_image | medium | Image uses :latest tag or no tag | |
| DFA-002 | base_image | info | No SHA256 digest pin on FROM | |
| DFA-003 | base_image | medium | Untrusted registry | |
| DFA-010 | instructions | low | CMD in shell form | |
| DFA-011 | instructions | low | ENTRYPOINT in shell form | |
| DFA-012 | instructions | info | MAINTAINER instruction is deprecated | |
| DFA-013 | instructions | medium | ADD used where COPY would suffice | |
| DFA-020 | security | medium | No USER directive (runs as root) | |
| DFA-021 | security | high | USER root set explicitly | |
| DFA-022 | security | high | sudo invoked in RUN | |
| DFA-023 | security | high | chmod 777 in RUN | |
| DFA-024 | security | medium | curl\ | bash pattern in RUN |
| DFA-025 | security | high | Hardcoded secret in ENV | |
| DFA-027 | security | low | No HEALTHCHECK | |
| DFA-030 | efficiency | low | apt-get update without install | |
| DFA-031 | efficiency | low | apt-get install without --no-install-recommends | |
| DFA-032 | efficiency | low | pip install without --no-cache-dir | |
| DFA-040 | secrets | medium | ARG with secret-pattern name |
Use list_checks to get the canonical, up-to-date catalog.
| Event | USD |
|---|---|
| Any audit / check_* tool call | $0.02 |
list_checks discovery | $0.005 |
{
"summary": {
"total_findings": 6,
"by_severity": {"high": 2, "medium": 2, "low": 2, "info": 0}
},
"findings": [
{
"id": "DFA-021",
"category": "security",
"severity": "high",
"instruction": "USER",
"line_number": 3,
"title": "USER root set explicitly",
"description": "...",
"remediation": "Switch to a non-root UID after any root-required RUN steps.",
"fix_dockerfile_snippet": "USER 10001:10001",
"references": ["CIS-Docker-4.1"]
}
]
}{
"mcpServers": {
"dockerfile-audit": {
"transport": "streamable-http",
"url": "https://YOUR-ACTOR-URL.apify.actor/mcp"
}
}
}docker-compose-audit)docker-compose.ymlIssues and ideas: [email protected] or the GitHub org UnbearableDev.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.