An MCP server providing Docker, system audit, and security toolsets for system introspection and management
Scoring was not performed
Output schemas not documented in visible code. docker_listContainers returns a SimpleContainer struct with ID, Names, Image, State, Status fields, but no OpenAPI/JSON Schema is visible. audit_getAndVerifyLog returns a JSON array but expected field names/types are not documented.
No parameter descriptions for tools accepting no input. audit_getAndVerifyLog and docker_listContainers both reflect toolsets.NoArgs{} but provide no schema description of what they return.
Descriptions lack recovery guidance for errors. audit_getAndVerifyLog returns 'TAMPERING DETECTED' but does not guide the LLM on next steps. docker tools have minimal descriptions that don't explain failure modes.
Tool descriptions are too generic or minimal. 'Lists running Docker containers on the host' doesn't explain when to use this vs other discovery tools, what fields mean, or pagination. 'Verifies the cryptographic integrity...' is correct but doesn't say what to do if verification fails.
containerID parameter for docker tools lacks constraints. No description of whether partial IDs work, max length, or format. Should document 'Container ID or name (12+ character hex ID or full name from docker_listContainers)' and validate early.
No error classification. Errors return raw Go error wraps (e.g., 'failed to create docker client: %w') rather than categorizing as retryable, user-fixable, or fatal. LLM cannot determine recovery strategy.
Destructive operations (docker_stopContainer, docker_restartContainer) lack confirmation step or dry-run capability. An agent calling docker_stopContainer on the wrong container ID permanently stops it without confirmation.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 0 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 37 | - | v1 |