A Model Context Protocol server for Docker management through ChatGPT
This server provides 7 Docker management tools with moderate definition quality. All tools have names, descriptions, and basic parameter schemas present, but fall short of production standards in several areas: (1) Descriptions are generic and lack 'WHEN to use' context, action clarity, or recovery guidance; (2) Parameter descriptions are minimal or missing depth, most are single-phrase strings under 30 chars; (3) No output schemas are documented, LLMs cannot infer what fields these tools return; (4) No error handling guidance or recovery instructions; (5) Critical destructive operations (container_remove, container_exec) lack confirmation or dry-run patterns; (6) Parameter validation rules are undocumented (e.g., container_exec's 'command' accepts any string, no injection warnings). Tool names follow verb_noun convention well, but descriptions need substantial expansion. This server lands in the 'fair/poor' band typical of community MCP servers.
Create and start a new Docker container
Execute a command in a running container
Get container logs
Remove a container
Start a stopped container
Stop a running container
List all Docker containers
No output schemas documented. LLMs cannot plan downstream calls or extract required fields. Every tool lacks a 'returns' clause specifying field names, types, and structure.
Parameter descriptions are minimal (single phrase, <30 chars). LLMs need format, range, and constraint details. E.g., 'command' in container_exec lacks any mention of shell syntax, injection risks, or timeout behavior.
Destructive operations (container_remove, container_exec) lack confirmation or dry-run patterns. Agents can irreversibly delete containers or execute arbitrary commands without user acknowledgment.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 53 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 37 | - | v1 |
Tool descriptions lack recovery guidance and actionable error context. Description text like 'List all Docker containers' does not explain when to call this vs other tools, what happens on failure, or what the next step should be.
No permission or scope declarations. Tools manipulate system resources (Docker containers) but provide no audit context, role checks, or least-privilege guidance.
Command injection risk in container_exec. The 'command' parameter accepts a raw string with no description of escaping rules, shell behavior, or injection safeguards. LLMs can be tricked into passing 'rm -rf /' or similar payloads.