{
  "id": "dockerfile-audit",
  "name": "Bounded Dockerfile static audit",
  "description": "Inspect one supplied Dockerfile for 14 bounded static risk and hygiene signals with line ranges, rule IDs, redacted evidence and remediation. Understands continuations, escape directives, literal stage inheritance and JSON forms. No execution, image/CVE scan, fetch, variable evaluation or safe-image verdict; heredocs, ONBUILD and custom frontends are rejected.",
  "category": "supply-chain",
  "priceUsd": "0.003",
  "pricingStatus": "proposed-unverified",
  "pricing": {
    "unit": "one successful operation call",
    "proposedNominalUsd": "0.003",
    "sixDecimalTokenBaseUnits": "3000",
    "subscription": false,
    "includesPayerWalletOrNetworkFees": false,
    "liveQuoteVerified": false,
    "condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
  },
  "intents": [
    "audit supplied Dockerfile text",
    "Dockerfile static risk analysis",
    "lint Dockerfile build hygiene",
    "review Dockerfile base image pinning and runtime user"
  ],
  "whenToUse": [
    "Get bounded static observations about one supplied Dockerfile's literal image references, stage/user configuration, COPY/ADD sources, secret-like names and instruction forms."
  ],
  "whenNotToUse": [
    "Build or execute a Dockerfile, inspect an image or registry, find CVEs, certify security, analyze Compose/Kubernetes, evaluate shell commands or ARG values, or parse heredocs, ONBUILD or custom syntax frontends."
  ],
  "capabilities": [
    "supplied Dockerfile",
    "line-numbered findings",
    "static audit",
    "multi-stage build",
    "base image digest pinning",
    "root USER signal",
    "secret-like variable names",
    "redacted evidence",
    "COPY ADD review"
  ],
  "limits": {
    "inputCodeUnits": 65536,
    "dockerfileUtf8Bytes": 65536,
    "physicalLines": 2048,
    "instructions": 512,
    "instructionCodeUnits": 8192,
    "stages": 64,
    "findings": 128,
    "outputBytes": 180000,
    "rules": 14,
    "variableEvaluation": "none",
    "sourceEcho": "none",
    "externalRequests": 0,
    "shellAnalysis": "none"
  },
  "errorCodes": [
    "INVALID_INPUT",
    "INVALID_DOCKERFILE",
    "UNSUPPORTED_DOCKERFILE_SYNTAX",
    "DOCKERFILE_LIMIT"
  ],
  "requirementsProfile": {
    "format": "declared-requirements-v1",
    "facts": {
      "execution.suppliedCode": false,
      "execution.remoteMutation": false,
      "execution.llmInference": false,
      "execution.paidMcp": false,
      "verification.semanticTruth": false,
      "verification.sourceAuthenticity": false,
      "verification.liveVulnerabilities": false,
      "numbers.arbitraryPrecisionJson": false,
      "numbers.model": "ieee754-binary64",
      "privacy.requestBodyPersisted": false,
      "execution.deterministic": true,
      "execution.networkAccess": false,
      "privacy.resultBodyPersisted": false,
      "payment.x402": true,
      "payment.mpp": true,
      "operation.id": "dockerfile-audit",
      "operation.category": "supply-chain",
      "limit.httpRequestBytes": 131072,
      "limit.requestBytes": 131072,
      "limit.responseBytes": 524288,
      "limit.resultBytes": 180000,
      "limit.jsonDepth": 32,
      "limit.jsonNodes": 20000,
      "dockerfile.profile": "bounded-dockerfile-static-v1",
      "dockerfile.maxUtf8Bytes": 65536,
      "dockerfile.maxLines": 2048,
      "dockerfile.maxInstructions": 512,
      "dockerfile.maxStages": 64,
      "dockerfile.fullConformance": false,
      "dockerfile.findingsComplete": false,
      "dockerfile.imageBuild": false,
      "dockerfile.imagePull": false,
      "dockerfile.shellExecution": false,
      "dockerfile.baseImageMetadata": false,
      "dockerfile.securityCertification": false,
      "input.dockerfile.maxLength": 65536,
      "input.dockerfile.minLength": 1
    },
    "unknownPolicy": "Undeclared requirements are unknown, never compatible. Matching declared facts does not establish semantic fit or input validity.",
    "preflight": "/preflight"
  },
  "documentation": "/reference/tools/dockerfile-audit.md",
  "serviceContract": "/reference/services/dockerfile-audit.json",
  "errors": [
    {
      "status": 400,
      "meaning": "Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch",
      "retry": "Correct the request before payment"
    },
    {
      "status": 402,
      "meaning": "Payment challenge or rejected payment",
      "retry": "Use official protocol SDK; inspect payment outcome before another payment"
    },
    {
      "status": 409,
      "meaning": "Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN",
      "retry": "Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay"
    },
    {
      "status": 413,
      "meaning": "Input or generated output too large",
      "retry": "Reduce input; no payment attempted for validation failure"
    },
    {
      "status": 415,
      "meaning": "Unsupported media type or compression",
      "retry": "Send uncompressed application/json"
    },
    {
      "status": 422,
      "meaning": "Schema or service-specific semantic validation failure",
      "retry": "Correct input using returned error code; no payment attempted"
    },
    {
      "status": 429,
      "meaning": "Request/payment-attempt rate exceeded",
      "retry": "Wait for rate limit window; preserve existing payment identity"
    },
    {
      "status": 503,
      "meaning": "Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement",
      "retry": "Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation"
    }
  ],
  "numericPrecision": "JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.",
  "paymentWorkflow": {
    "discoveryOnly": false,
    "supportedProtocols": [
      "x402",
      "mpp"
    ],
    "x402": {
      "credentialHeader": "PAYMENT-SIGNATURE",
      "challengeHeader": "PAYMENT-REQUIRED",
      "receiptHeader": "PAYMENT-RESPONSE",
      "version": 2,
      "scheme": "exact",
      "paymentIdentifier": "payment-identifier extension MUST equal the HTTP Idempotency-Key",
      "sdk": "@x402/core with @x402/evm"
    },
    "mpp": {
      "supported": true,
      "credentialHeader": "Authorization",
      "challengeHeader": "WWW-Authenticate",
      "receiptHeader": "Payment-Receipt",
      "method": "tempo",
      "intent": "charge",
      "sdk": "mppx",
      "tokenDecimals": 6
    },
    "steps": [
      "Check configured readiness and the exact service schema",
      "Generate a fresh random Idempotency-Key for this operation; never use a discovery probe fixture for purchases",
      "Send valid input without a credential to obtain the official protocol challenge",
      "Use the official SDK and authorized wallet to fulfill the challenge",
      "Retry only with identical key, body, protocol and credential",
      "On PAYMENT_UNCERTAIN stop and request operator reconciliation; never blindly pay again"
    ],
    "versionedRetries": "Request fingerprint includes service release version. Retries across a version upgrade can conflict; coordinate upgrades outside the 24-hour replay window and reconcile pending attempts.",
    "docs": "/llms.txt"
  },
  "method": "POST",
  "paths": {
    "x402": "/v1/x402/dockerfile-audit",
    "mpp": "/v1/mpp/dockerfile-audit"
  },
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "type": "object",
    "properties": {
      "profile": {
        "type": "string",
        "const": "bounded-dockerfile-static-v1"
      },
      "dockerfile": {
        "type": "string",
        "minLength": 1,
        "maxLength": 65536
      }
    },
    "required": [
      "profile",
      "dockerfile"
    ],
    "additionalProperties": false
  },
  "outputSchema": {
    "type": "object",
    "required": [
      "operation",
      "version",
      "result",
      "provenance"
    ],
    "properties": {
      "operation": {
        "const": "dockerfile-audit",
        "type": "string"
      },
      "version": {
        "const": "0.29.0",
        "type": "string"
      },
      "result": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "profile": {
            "type": "string",
            "const": "bounded-dockerfile-static-v1"
          },
          "analysis": {
            "type": "string",
            "const": "bounded-static-observations"
          },
          "inputBytes": {
            "type": "integer",
            "minimum": 1,
            "maximum": 65536
          },
          "physicalLines": {
            "type": "integer",
            "minimum": 1,
            "maximum": 2048
          },
          "instructionCount": {
            "type": "integer",
            "minimum": 1,
            "maximum": 512
          },
          "finalStageIndex": {
            "type": "integer",
            "minimum": 0,
            "maximum": 63
          },
          "stages": {
            "minItems": 1,
            "maxItems": 64,
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "index": {
                  "type": "integer",
                  "minimum": 0,
                  "maximum": 63
                },
                "fromLine": {
                  "type": "integer",
                  "exclusiveMinimum": 0,
                  "maximum": 9007199254740991
                },
                "endLine": {
                  "type": "integer",
                  "exclusiveMinimum": 0,
                  "maximum": 9007199254740991
                },
                "baseKind": {
                  "type": "string",
                  "enum": [
                    "external-image",
                    "prior-stage",
                    "scratch",
                    "variable-dependent"
                  ]
                },
                "digestPinned": {
                  "type": [
                    "boolean",
                    "null"
                  ]
                },
                "runtimeUser": {
                  "type": "string",
                  "enum": [
                    "explicit-root",
                    "explicit-nonroot",
                    "named-user-unknown",
                    "base-unknown",
                    "variable-dependent"
                  ]
                },
                "userSourceLine": {
                  "anyOf": [
                    {
                      "type": "integer",
                      "exclusiveMinimum": 0,
                      "maximum": 9007199254740991
                    },
                    {
                      "type": "null"
                    }
                  ]
                }
              },
              "required": [
                "index",
                "fromLine",
                "endLine",
                "baseKind",
                "digestPinned",
                "runtimeUser",
                "userSourceLine"
              ],
              "additionalProperties": false
            }
          },
          "rulesEvaluated": {
            "minItems": 14,
            "maxItems": 14,
            "type": "array",
            "items": {
              "type": "string",
              "enum": [
                "DF001",
                "DF002",
                "DF003",
                "DF004",
                "DF005",
                "DF006",
                "DF007",
                "DF008",
                "DF009",
                "DF010",
                "DF011",
                "DF012",
                "DF013",
                "DF014"
              ]
            }
          },
          "findings": {
            "maxItems": 128,
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "ruleId": {
                  "type": "string",
                  "enum": [
                    "DF001",
                    "DF002",
                    "DF003",
                    "DF004",
                    "DF005",
                    "DF006",
                    "DF007",
                    "DF008",
                    "DF009",
                    "DF010",
                    "DF011",
                    "DF012",
                    "DF013",
                    "DF014"
                  ]
                },
                "severity": {
                  "type": "string",
                  "enum": [
                    "info",
                    "warning"
                  ]
                },
                "category": {
                  "type": "string",
                  "enum": [
                    "reproducibility",
                    "security-configuration",
                    "build-hygiene",
                    "portability"
                  ]
                },
                "confidence": {
                  "type": "string",
                  "enum": [
                    "syntactic",
                    "heuristic"
                  ]
                },
                "line": {
                  "type": "integer",
                  "exclusiveMinimum": 0,
                  "maximum": 9007199254740991
                },
                "endLine": {
                  "type": "integer",
                  "exclusiveMinimum": 0,
                  "maximum": 9007199254740991
                },
                "stageIndex": {
                  "anyOf": [
                    {
                      "type": "integer",
                      "minimum": 0,
                      "maximum": 9007199254740991
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "evidence": {
                  "type": "string",
                  "maxLength": 180
                },
                "message": {
                  "type": "string",
                  "maxLength": 300
                },
                "remediation": {
                  "type": "string",
                  "maxLength": 400
                }
              },
              "required": [
                "ruleId",
                "severity",
                "category",
                "confidence",
                "line",
                "endLine",
                "stageIndex",
                "evidence",
                "message",
                "remediation"
              ],
              "additionalProperties": false
            }
          },
          "summary": {
            "type": "object",
            "properties": {
              "totalFindings": {
                "type": "integer",
                "minimum": 0,
                "maximum": 9007199254740991
              },
              "returnedFindings": {
                "type": "integer",
                "minimum": 0,
                "maximum": 128
              },
              "bySeverity": {
                "type": "object",
                "properties": {
                  "info": {
                    "type": "integer",
                    "minimum": 0,
                    "maximum": 9007199254740991
                  },
                  "warning": {
                    "type": "integer",
                    "minimum": 0,
                    "maximum": 9007199254740991
                  }
                },
                "required": [
                  "info",
                  "warning"
                ],
                "additionalProperties": false
              },
              "truncated": {
                "type": "boolean"
              },
              "variableDependentInstructions": {
                "type": "integer",
                "minimum": 0,
                "maximum": 9007199254740991
              }
            },
            "required": [
              "totalFindings",
              "returnedFindings",
              "bySeverity",
              "truncated",
              "variableDependentInstructions"
            ],
            "additionalProperties": false
          },
          "limitations": {
            "minItems": 1,
            "maxItems": 12,
            "type": "array",
            "items": {
              "type": "string",
              "maxLength": 350
            }
          }
        },
        "required": [
          "profile",
          "analysis",
          "inputBytes",
          "physicalLines",
          "instructionCount",
          "finalStageIndex",
          "stages",
          "rulesEvaluated",
          "findings",
          "summary",
          "limitations"
        ],
        "additionalProperties": false
      },
      "provenance": {
        "type": "object",
        "required": [
          "inputSha256",
          "outputSha256",
          "deterministic",
          "externalRequests"
        ],
        "properties": {
          "inputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "outputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "deterministic": {
            "const": true
          },
          "externalRequests": {
            "const": 0
          }
        }
      }
    },
    "additionalProperties": false
  },
  "exampleInput": {
    "profile": "bounded-dockerfile-static-v1",
    "dockerfile": "FROM node:22 AS build\nWORKDIR /app\nCOPY . .\nRUN npm ci\nFROM node:22-slim\nCOPY --from=build /app /app\nUSER 1000:1000\nENTRYPOINT [\"node\", \"/app/server.js\"]\n"
  },
  "exampleResponse": {
    "operation": "dockerfile-audit",
    "version": "0.29.0",
    "result": {
      "profile": "bounded-dockerfile-static-v1",
      "analysis": "bounded-static-observations",
      "inputBytes": 154,
      "physicalLines": 8,
      "instructionCount": 8,
      "finalStageIndex": 1,
      "stages": [
        {
          "index": 0,
          "fromLine": 1,
          "endLine": 4,
          "baseKind": "external-image",
          "digestPinned": false,
          "runtimeUser": "base-unknown",
          "userSourceLine": null
        },
        {
          "index": 1,
          "fromLine": 5,
          "endLine": 8,
          "baseKind": "external-image",
          "digestPinned": false,
          "runtimeUser": "explicit-nonroot",
          "userSourceLine": 7
        }
      ],
      "rulesEvaluated": [
        "DF001",
        "DF002",
        "DF003",
        "DF004",
        "DF005",
        "DF006",
        "DF007",
        "DF008",
        "DF009",
        "DF010",
        "DF011",
        "DF012",
        "DF013",
        "DF014"
      ],
      "findings": [
        {
          "ruleId": "DF002",
          "severity": "info",
          "category": "reproducibility",
          "confidence": "syntactic",
          "line": 1,
          "endLine": 1,
          "stageIndex": 0,
          "evidence": "FROM external image: explicit tag, no sha256 digest",
          "message": "External base image has a tag but no digest pin.",
          "remediation": "Consider pinning a verified digest for reproducibility; arrange updates so pinning does not indefinitely prevent security fixes."
        },
        {
          "ruleId": "DF007",
          "severity": "info",
          "category": "build-hygiene",
          "confidence": "syntactic",
          "line": 3,
          "endLine": 3,
          "stageIndex": 0,
          "evidence": "COPY includes a literal whole-context source; ignore rules not inspected",
          "message": "A local COPY or ADD source includes the context root or a whole-context wildcard.",
          "remediation": "Review .dockerignore and prefer the required paths. Context contents and ignore rules were not supplied, so accidental inclusion is not established."
        },
        {
          "ruleId": "DF002",
          "severity": "info",
          "category": "reproducibility",
          "confidence": "syntactic",
          "line": 5,
          "endLine": 5,
          "stageIndex": 1,
          "evidence": "FROM external image: explicit tag, no sha256 digest",
          "message": "External base image has a tag but no digest pin.",
          "remediation": "Consider pinning a verified digest for reproducibility; arrange updates so pinning does not indefinitely prevent security fixes."
        }
      ],
      "summary": {
        "totalFindings": 3,
        "returnedFindings": 3,
        "bySeverity": {
          "info": 3,
          "warning": 0
        },
        "truncated": false,
        "variableDependentInstructions": 0
      },
      "limitations": [
        "Static observations only: no build, command execution, filesystem access, network requests, registry lookup, vulnerability scan or safety verdict.",
        "Base-image metadata, runtime overrides, build arguments, named contexts, .dockerignore and source files are not available. Variable expressions are not evaluated, including ARG defaults.",
        "Shell programs and package-install commands are opaque. No shell correctness, package pinning or script security analysis is performed.",
        "Recognized instructions without a listed rule are retained for structure only. This is not a complete Docker parser, compiler or build-success check.",
        "Heredocs, ONBUILD, custom/labs frontends, unknown instructions/flags, ambiguous terminal escapes and malformed supported forms are rejected rather than partially interpreted.",
        "Findings are potential issues to review. Secret checks use names only; values, source snippets, image references and URLs are not echoed. A report with no findings does not establish safety.",
        "The final stage is the last textual FROM; --target selection is not an input. Rules inspect all textual stages, including stages a build might skip. Docker #check suppressions do not suppress this profile's rules."
      ]
    },
    "provenance": {
      "inputSha256": "da6f61385220259b52108217ce4cdf1b3ba1cca6ab6e6fc3a888dfc8b17095dc",
      "outputSha256": "590de60e78b37fc2620732486c55052fcc81de4436e975f6161100084cbcab00",
      "deterministic": true,
      "externalRequests": 0
    }
  },
  "requiredHeaders": {
    "Content-Type": "application/json",
    "Idempotency-Key": "random 16–128 character operation identifier"
  },
  "fixedExample": "/reference/examples/dockerfile-audit.json",
  "execution": {
    "deterministic": true,
    "externalRequests": 0,
    "maxExternalRequests": 0,
    "resultSnapshotPersisted": false,
    "fixedExampleIsIllustrativeSnapshot": false,
    "requiresPayment": true,
    "supportsMcpExecution": false
  },
  "releaseSnapshot": {
    "format": "static-release-reference-v1",
    "sourceVersion": "0.29.0",
    "sourceRegistrySha256": "a2b5ec09bf6c38b9d2879d746a4fded374f5928b445377b0270ef6aa8e6cac65",
    "generatedAt": "2026-10-06T15:38:00Z",
    "releaseAcceptance": "not-verified-by-generator",
    "runtimeReadiness": "not-evaluated",
    "livePaymentsVerified": false,
    "indexingVerified": false,
    "apiOrigin": null,
    "notice": "Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment."
  }
}
