A Docker management MCP server that provides tools for creating containers, executing commands, managing images, and inspecting Docker resources.
Single tool with acceptable naming but significant gaps in parameter descriptions and output documentation. The tool name 'create_container' follows verb_noun convention correctly. Input schema is present with type definitions for all three parameters. However, parameter descriptions are embedded in the tool description rather than provided as individual field annotations in the schema object, making them harder for LLMs to parse. Output schema is completely undocumented, the tool returns a string but there is no specification of what that string contains or what structure the caller should expect. Security input validation (_safe_token) is well-implemented server-side, mitigating command injection risks. Error handling is present but generic (returns error strings without recovery guidance). The tool's risk classification as WRITE is correct but not leveraged for confirmation or dry-run patterns.
Create and start a Docker container with optional dependencies. Parameters: • image: The Docker image to use (e.g., "ubuntu:latest", "node:16", "python:3.9-slim"). • container_name: A unique name for the container. • dependencies: Space-separated list of packages to install (e.g., "numpy pandas matplotlib" or "express lodash"). This tool uses 'docker run' in detached mode with a command that keeps the container running. If dependencies are specified, they will be installed after the container starts. Automatically detects appropriate package manager (pip, npm, apt, apk) based on the image.
Output schema completely undocumented. Tool returns a string but caller has no specification of content, format, or success/failure indicators.
Parameter descriptions are in tool docstring only, not in JSON Schema field descriptions. LLM cannot easily extract per-parameter constraints without parsing prose.
No error recovery guidance. Tool returns generic error strings ('Error: ...') without suggesting next steps or retryable vs. fatal classification.
Destructive operation (WRITE risk) lacks confirmation or dry-run pattern. LLM can accidentally create unwanted containers on a single call.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 56 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 22 | - | v1 |
No tool annotations (destructiveHint, idempotentHint) despite being a WRITE operation. Clients cannot auto-flag as dangerous.