# Bounded Dockerfile static audit

Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment.

Inspect one supplied Dockerfile for 14 bounded static risk and hygiene signals with line ranges, rule IDs, redacted evidence and remediation. Understands continuations, escape directives, literal stage inheritance and JSON forms. No execution, image/CVE scan, fetch, variable evaluation or safe-image verdict; heredocs, ONBUILD and custom frontends are rejected.

Release: 0.29.0. Built: 2026-10-06T15:38:00Z.

## Choose for
- Get bounded static observations about one supplied Dockerfile's literal image references, stage/user configuration, COPY/ADD sources, secret-like names and instruction forms.

## Outside this profile
- Build or execute a Dockerfile, inspect an image or registry, find CVEs, certify security, analyze Compose/Kubernetes, evaluate shell commands or ARG values, or parse heredocs, ONBUILD or custom syntax frontends.

Proposed nominal USD 0.003 per successful call; payer fees excluded. No verified runtime availability.

- [Exact release contract](/reference/services/dockerfile-audit.json)
- [Input schema](/reference/schemas/dockerfile-audit.input.json)
- [Output schema](/reference/schemas/dockerfile-audit.output.json)
- [Fixed example](/reference/examples/dockerfile-audit.json)
- [Complete HTML reference](/discover/tools/dockerfile-audit)
