Docker MCP Server
OCI · GHCR.IO/L337-ORG/DOCKER-MCP-SERVER:2.2.2 · 3 COMPONENTS · SCANNED AUG 3
Manage Docker (containers, images, Compose, Swarm, registries) via the Docker SDK and CLI.
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →
Supply Chain Security0
- Malware scan not yet available for this package.Unverified
- CVE data not yet available for this package.Unverified
- Install-script risk not yet assessed.Unverified
- Dependency-health data not yet available.Unverified
Provenance & Transparency32
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- License check failed: no license is declared. See how to fix → Fail
- Actively maintained (last published 2 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability72
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 35053 tokens (~216/item across 162 items; 156 tools + 6 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage71
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 0% of tool parameters carry a description.Fail
- Structured output schemas are declared (23% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
Unverified: 2 categories
Categories scored 0 because we could not verify them: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
oci · ghcr.io/l337-org/docker-mcp-server:2.2.2
claude mcp add l337-org-docker-mcp-server -- docker run --rm -i ghcr.io/l337-org/docker-mcp-server:2.2.2
codex mcp add l337-org-docker-mcp-server -- docker run --rm -i ghcr.io/l337-org/docker-mcp-server:2.2.2
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"l337-org-docker-mcp-server": {
"type": "local",
"command": [
"docker",
"run",
"--rm",
"-i",
"ghcr.io/l337-org/docker-mcp-server:2.2.2"
],
"enabled": true
}
}
} mcp_servers:
l337-org-docker-mcp-server:
command: "docker"
args: ["run", "--rm", "-i", "ghcr.io/l337-org/docker-mcp-server:2.2.2"] {
"mcpServers": {
"l337-org-docker-mcp-server": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"ghcr.io/l337-org/docker-mcp-server:2.2.2"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 1 Aug 26 +27
- Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
- MCP protocol: unverified → pass ▲ functional
- Schema quality: unverified → 100 ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- First check of Schema quality: good functional
- First check of Schema quality: fail functional
- First check of Tool coverage: 0 functional
- First check of Tool coverage: 23 functional
- First check of Schema quality: fail functional
- 31 Jul 26 6
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Analysed oci/ghcr.io/l337-org/docker-mcp-server:2.2.2
Provenance none
Ecosystem: oci · Outcome: none
Reason: no_attestation
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
system_reconnect ~145
Rebuild a pooled Docker client from its configured endpoint, to recover a wedged connection. Validates the rebuilt client before swapping in (and only then closes the old one), so a failed rebuild leaves the working client in place. Rebuilds the default host's client when `host` is omitted. It CANNOT retarget to a different daemon — to add or change a daemon, edit DOCKER_MCP_SERVER_HOSTS and restart. `system_close` closes pooled clients without rebuilding; `host_list` shows the configured endpoints. returns: dict - the rebuilt host's version info (same shape as `system_version`), confirming connectivity
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
system_version ~81
Return Docker server version information. Engine version, API level, and per-component versions — the first thing to check for feature availability. `system_info` reports runtime state (counts, drivers, swarm role) instead. returns: dict - {"Version", "ApiVersion", "MinAPIVersion", "Os", "Arch", "Components", ...}
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
volume_create ~318
Create a volume managed by Docker. Named volumes persist after their containers stop or are removed; use them for databases, uploads, or any data that must outlive a container. Anonymous volumes (no `name`) are only removed automatically when the container was started with `--rm` or removed with `docker rm -v`; otherwise they accumulate and must be pruned manually. Common `driver_opts` for the default `local` driver: bind-mount an existing host path with `{"type": "none", "device": "/host/path", "o": "bind"}`, or mount an NFS share with `{"type": "nfs", "device": "server:/export", "o": "addr=server,rw"}`. Third-party drivers (e.g. `rexray`, `convoy`) accept their own option keys. List existing volumes with `volume_list`; reclaim unused ones with `volume_prune`. Created volumes are stamped with provenance labels. args: name - Volume name; auto-generated if omitted (creates an anonymous volume) driver - Volume driver to use (default: "local") driver_opts - Driver-specific options dict labels - Labels to set on the volume returns: dict - The created volume's attrs ({"Name", "Driver", "Mountpoint", "Labels", ...})
| Name | Type | Req | Description |
|---|---|---|---|
| driver | string | — | — |
| driver_opts | object | — | — |
| labels | object | — | — |
| name | string | — | — |
No output schema declared.
No examples provided.
volume_inspect ~115
Get a volume's full inspect payload by name. Use it after `volume_list` to see a volume's on-disk location, driver, and labels — e.g. before a backup or `volume_remove`. Volumes are addressed purely by name; they have no separate id. args: name - The volume name (volumes have no ids) returns: dict - The volume's attrs (Name, Driver, Mountpoint, CreatedAt, Labels, Options, Scope)
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | — |
No output schema declared.
No examples provided.
volume_list ~151
List volumes. Volumes are addressed by name only — feed a Name to `volume_inspect` for detail or `volume_remove` / `volume_prune` to clean up. filters={"dangling": True} finds volumes that no container references. args: filters - Filter by attributes (e.g. dangling, name, label) managed_only - Only return volumes created by this MCP server (filters on the docker-mcp-server.managed label); combines with any `filters` given returns: list - One volume document ({"Name", "Driver", "Mountpoint", ...}) per volume
| Name | Type | Req | Description |
|---|---|---|---|
| filters | object | — | — |
| managed_only | boolean | — | — |
No output schema declared.
No examples provided.
volume_prune ~160
Remove volumes not referenced by any container, running or stopped. A volume used by even one stopped container is not "unused" and survives the prune — remove the container first (or use `container_prune`, then this) to reclaim its volumes. Valid filter keys: `label` (key or key=value), `all` ("true" as a string — without it only anonymous volumes are eligible, matching `docker volume prune`'s default). Use `volume_list` first to see what currently exists. args: filters - Narrow which unused volumes to remove; omit to remove all anonymous ones returns: dict - {"VolumesDeleted": [...], "SpaceReclaimed": <bytes>}
| Name | Type | Req | Description |
|---|---|---|---|
| filters | object | — | — |
No output schema declared.
No examples provided.
volume_remove ~129
Remove a single volume by name. Fails if any container, running or stopped, still references the volume — remove or recreate those containers first, or pass `force=True` to remove it anyway (the containers keep their reference but lose the underlying data). For bulk cleanup of volumes with no container references at all, use `volume_prune` instead. args: name - Volume name to remove force - Remove even if a container still references the volume returns: bool - True after removal
| Name | Type | Req | Description |
|---|---|---|---|
| force | boolean | — | — |
| name | string | yes | — |
| Name | Type | Req | Description |
|---|---|---|---|
| result | boolean | yes | — |
No examples provided.