Skip to content

feat(mcp): Add semantic Docker query tools - #534

Merged
shivasurya merged 3 commits into
mainfrom
pr-02-semantic-docker-queries
Feb 16, 2026
Merged

shivasurya merged 3 commits into
mainfrom
pr-02-semantic-docker-queries

Conversation

@shivasurya

@shivasurya shivasurya commented Feb 16, 2026 •

Copy link
Copy Markdown
Owner

Adds three semantic Docker MCP tools for advanced configuration filtering.

Stacked on: #531 (PR-01)

Tools Added

  1. find_dockerfile_instructions - Semantic Dockerfile queries with instruction-specific filters
  2. find_compose_services - Docker Compose service filtering
  3. get_dockerfile_details - Complete Dockerfile breakdown with multi-stage analysis

Features

Semantic Filtering:

  • Instruction-specific filters (has_digest, user, port, base_image)
  • Service configuration filters (privileged, volumes, ports)
  • Multi-stage build detection

Parsed Details:

  • FROM: base_image, tag, digest, stage_alias
  • USER: user, group
  • EXPOSE: port, protocol
  • COPY/ADD: source, destination, from_stage, chown
  • Compose: image, build, ports, volumes, environment, privileged, network_mode

Examples

Find unpinned base images:

{"tool": "find_dockerfile_instructions", "arguments": {"instruction_type": "FROM", "has_digest": false}}

Find privileged containers:

{"tool": "find_compose_services", "arguments": {"has_privileged": true}}

Get complete Dockerfile breakdown:

{"tool": "get_dockerfile_details", "arguments": {"file_path": "/app/Dockerfile"}}

Testing

  • 11 comprehensive test functions
  • 100% test pass rate
  • Clean linter

🤖 Generated with Claude Code

@safedep

safedep Bot commented Feb 16, 2026 •

Copy link
Copy Markdown

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

No dependency changes detected. Nothing to scan.

This report is generated by SafeDep Github App

@shivasurya shivasurya self-assigned this Feb 16, 2026
@shivasurya shivasurya added enhancement New feature or request docker Docker/Dockerfile related changes labels Feb 16, 2026
@codecov

codecov Bot commented Feb 16, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 87.71930% with 56 lines in your changes missing coverage. Please review.
✅ Project coverage is 82.87%. Comparing base (b3dad5b) to head (b51d043).
⚠️ Report is 2 commits behind head on main.

Files with missing lines Patch % Lines
sast-engine/mcp/tools.go 87.71% 46 Missing and 10 partials ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main     #534      +/-   ##
==========================================
+ Coverage   82.75%   82.87%   +0.11%     
==========================================
  Files         133      133              
  Lines       15666    16102     +436     
==========================================
+ Hits        12965    13345     +380     
- Misses       2221     2267      +46     
- Partials      480      490      +10     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

shivasurya and others added 3 commits February 15, 2026 22:10
Extend MCP's find_symbol tool to recognize Docker node types, enabling
basic Docker file queries through the existing MCP infrastructure.

Changes:
- Add dockerfile_instruction and compose_service to validTypes map
- Add LSP Symbol Kind mapping for Docker types (Constant=14, Module=2)
- Include Docker statistics in get_index_info response
- Add comprehensive unit tests with 95.4% coverage
- Create test fixtures for integration testing

This enables:
- Querying Dockerfile instructions via find_symbol(type="dockerfile_instruction")
- Querying docker-compose services via find_symbol(type="compose_service")
- Docker statistics in index info (docker_instructions, compose_services)

Foundation for PR-02 (semantic Docker queries) and PR-03 (dependency graph).

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Implements three new MCP tools for advanced Docker configuration analysis:

1. find_dockerfile_instructions - Semantic Dockerfile queries
   - Instruction-specific filtering (FROM, USER, EXPOSE, etc.)
   - Security analysis (unpinned images, root users)
   - Parsed details (base_image, tag, digest, user, port, etc.)

2. find_compose_services - Docker Compose service queries
   - Configuration filtering (privileged, port, volume)
   - Security risk analysis (CRITICAL/HIGH/MEDIUM/LOW)
   - Detects: Docker socket exposure, host network, dangerous caps

3. get_dockerfile_details - Complete Dockerfile breakdown
   - Multi-stage build analysis
   - Security summary with risk assessment
   - All instructions with parsed details

Implementation:
- Added 10 parsing helper functions (parseFromInstruction, etc.)
- Added 3 tool implementations (~500 lines)
- Added 3 tool definitions with comprehensive docs
- Wired up tool dispatch in executeTool()

Testing:
- Created tools_docker_semantic_test.go with 11 test functions
- 100% test pass rate
- 94.5% code coverage
- Tests cover: basic queries, filters, security analysis, parsing

Security Features:
- CWE-1188 detection (unpinned images)
- Root user detection (HIGH risk)
- Privileged container detection (CRITICAL risk)
- Docker socket exposure detection (CRITICAL risk)
- Host network mode detection (HIGH risk)
- Dangerous capability detection (HIGH risk)

Related: PR-01 (basic Docker MCP support)
Next: PR-03 (dependency graph analysis)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Remove automatic security analysis features that were not requested:
- Removed security_issue and risk_level from Dockerfile instructions
- Removed security_issues and risk_level from compose services
- Renamed security_summary to summary in get_dockerfile_details
- Removed issues and risk_level calculations

Changes:
- buildDockerInstructionMatch: Returns parsed details only
- buildComposeServiceMatch: Returns configuration only
- get_dockerfile_details: Returns summary stats without risk scoring
- Updated tool descriptions to remove security analysis mentions
- Updated all tests to remove security assertions
- Fixed linter issues (godot, gocritic)

The tools now provide semantic filtering and parsed details without
opinionated security scoring, allowing users to apply their own
security policies and risk thresholds.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@shivasurya
shivasurya force-pushed the pr-02-semantic-docker-queries branch from fc1e033 to b51d043 Compare February 16, 2026 03:11
@shivasurya
shivasurya force-pushed the pr-01-docker-mcp-basic-support branch from ed049da to 1014ea8 Compare February 16, 2026 03:11

shivasurya commented Feb 16, 2026 •

Copy link
Copy Markdown
Owner Author

Base automatically changed from pr-01-docker-mcp-basic-support to main February 16, 2026 03:17
@shivasurya
shivasurya merged commit 4dc118b into main Feb 16, 2026
7 checks passed
@shivasurya
shivasurya deleted the pr-02-semantic-docker-queries branch February 16, 2026 03:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docker Docker/Dockerfile related changes enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant