streamable-httpupdated 3mo ago
MCP server that audits docker-compose.yml files for security misconfigurations. Trivy-grade check catalog, designed for AI agents โ every finding ships with a severity rating, full remediation text, and a YAML fix snippet you can paste.
What can you do with Docker Compose Audit?
Docker Compose Security Audit
MCP server that audits
docker-compose.ymlfiles for security misconfigurations. Trivy-grade check catalog, designed for AI agents โ every finding ships with a severity rating, full remediation text, and a YAML fix snippet you can paste.
Built by Unbearable Labs. Pay-per-event pricing โ you only pay when an audit runs.
Available on
- Apify Actor Store โ primary, metered usage (PPE)
- MCPize โ pending submission
- MCP.so โ pending submission
- PulseMCP โ pending submission
- Smithery โ pending submission
- Glama โ pending submission
Newsletter: Unbearable TechTips Weekly ยท All Actors: github.com/UnbearableDev
What it does
Point any MCP-capable client (Claude Desktop, Cursor, n8n, Make, Zapier, custom agents) at this server, hand it the contents of a docker-compose.yml, and get back a structured report with:
- Severity โ high / medium / low / info
- Service โ which compose service the finding affects
- Description โ what's wrong and why it matters
- Remediation โ what to do about it
- Fix snippet โ YAML you can paste directly into the file
Tools
| Tool | Purpose |
|---|---|
audit_compose(compose_yaml? | compose_url?, min_severity='low') |
Run all checks, return full report |
check_privilege(...) |
Container privilege & capability issues only |
check_network(...) |
Network exposure issues only |
check_filesystem(...) |
Volume mount & filesystem issues only |
check_secrets(...) |
Secret hygiene issues only |
check_resources(...) |
Resource limit issues only |
check_image_hygiene(...) |
Image tag / registry / pinning issues only |
check_runtime_lifecycle(...) |
Healthcheck / restart / init issues only |
check_logging(...) |
Logging driver / rotation issues only |
check_compose_hygiene(...) |
Deprecated fields / Compose-spec hygiene only |
list_checks(category?) |
Browse the full check catalog |
All audit-running tools accept the same input:
compose_yaml(string) โ paste the YAML content directly, ORcompose_url(string) โ public HTTPS URL to fetch (e.g. GitHub raw URL)
Provide exactly one. min_severity defaults to low (drops info findings); set to medium or high to filter further.
Example response (truncated)
{
"summary": {
"total_findings": 14,
"by_severity": {"high": 3, "medium": 6, "low": 5, "info": 0},
"by_category": {"privilege": 4, "network": 3, "secrets": 2, "...": 5}
},
"findings": [
{
"id": "DCS-002",
"category": "privilege",
"severity": "high",
"service": "web",
"title": "Privileged mode enabled",
"description": "Service 'web' has `privileged: true`...",
"remediation": "Remove `privileged: true`. If you need specific capabilities...",
"fix_yaml_snippet": " # remove `privileged: true`; if needed, use cap_add or devices selectively",
"references": ["CIS-Docker-5.4", "NIST-800-190"]
},
...
]
}
Pricing
| Event | USD |
|---|---|
| Any audit / check_* tool call | $0.02 |
list_checks discovery call |
$0.005 |
You pay only when a tool is invoked. No subscription, no monthly minimums.
Check catalog (25 live in v1, growing toward 54)
| Category | Live checks |
|---|---|
| Privilege | Root user (DCS-001), privileged mode (DCS-002), dangerous capabilities (DCS-003), cap_add: ALL (DCS-004), cap_drop: ALL missing (DCS-005), no-new-privileges missing (DCS-006) |
| Network | network_mode: host (DCS-010), port bound to 0.0.0.0 (DCS-011), SSH port exposed (DCS-013), DB port exposed (DCS-014) |
| Filesystem | /var/run/docker.sock mount (DCS-018), host root mount (DCS-019), sensitive host paths (DCS-020) |
| Secrets | Hardcoded secret in env (DCS-026), secret-pattern env without Docker secrets (DCS-027) |
| Resources | No memory limit (DCS-032), no CPU limit (DCS-033), no PID limit (DCS-034) |
| Image hygiene | Unpinned / :latest image (DCS-037) |
| Runtime lifecycle | No healthcheck (DCS-043), no restart policy (DCS-044) |
| Logging | No log driver (DCS-048), no log rotation (DCS-049) |
| Compose hygiene | Deprecated version: field (DCS-051), depends_on without healthcheck condition (DCS-052) |
Use list_checks to get the canonical, up-to-date catalog with IDs, severities, and titles.
Connecting from Claude Desktop
Add to your MCP config:
{
"mcpServers": {
"compose-audit": {
"transport": "streamable-http",
"url": "https://YOUR-ACTOR-URL.apify.actor/mcp"
}
}
}
(Replace YOUR-ACTOR-URL with the Standby URL shown on the Apify Store page after you start the Actor.)
Limits
- YAML size: 1 MB cap per audit call
- URL fetch: 5-second timeout, max 3 redirects, HTTPS only
- Session timeout: 5 minutes of inactivity
What's NOT covered (yet)
Pure static analysis of the compose file only. Out of scope for this version:
- Image vulnerability scanning (use Trivy / Grype for that)
- Live container inspection
- Kubernetes / Helm manifests (different surface)
- Dockerfile-specific lint (use Hadolint)
The next 29 checks on the v1.x โ v2 roadmap include build-context security, additional capability checks, secret-pattern detection in build args, and registry trust verification.
Source / contact
Issues, ideas, or false-positive reports: open an issue on the GitHub repo or email unbearabledev@gmail.com.
get the weekly newsletter(https://unbearabletechtips.beehiiv.com).
Install
Add Docker Compose Audit to your client. Pick the one you use.
claude mcp add --transport http docker-compose-audit https://unbearable-dev--docker-compose-audit.apify.actor/mcpcodex mcp add docker-compose-audit --url https://unbearable-dev--docker-compose-audit.apify.actor/mcp{
"mcpServers": {
"docker-compose-audit": {
"url": "https://unbearable-dev--docker-compose-audit.apify.actor/mcp"
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
{
"servers": {
"docker-compose-audit": {
"type": "http",
"url": "https://unbearable-dev--docker-compose-audit.apify.actor/mcp"
}
}
}Add to `.vscode/mcp.json` in your workspace.
{
"mcpServers": {
"docker-compose-audit": {
"url": "https://unbearable-dev--docker-compose-audit.apify.actor/mcp"
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"docker-compose-audit": {
"serverUrl": "https://unbearable-dev--docker-compose-audit.apify.actor/mcp"
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
2 tools
Docker Compose Audit exposes 2 tools to a connected agent.
- compose_yaml
- (string) โ paste the YAML content directly, **OR**
- compose_url
- (string) โ public HTTPS URL to fetch (e.g. GitHub raw URL)
Score
60 / 100
Good
- Documentation25/25
- Maintenance13/25
- Trust6/20
- Capability4/15
- Install experience12/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 92 days ago
- Has a release history
- Repository is not archived
- No licence detected
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 2 tool(s) documented
- Provides prompt templates
- Provides resources
- 6 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint โ no local install
Version history
| Versions | Published |
|---|---|
| 1.0.0Latest | Jun 2, 2026 |