
Valca
io.github.pranlabsv0.6.1Updated Oct 7, 2026
Scans code, IaC and AI-agent config for security problems. Read-only — nothing can be edited.
Overview
Lets an assistant run read-only security scans of code, IaC and AI-agent config, returning findings and the rule catalogue.
- What it does
- Valca exposes two read-only tools: scan(path) returns findings for a file or directory, including rule id, severity, message, file, line and a suggested fix, and list_rules() returns the full catalogue of rule ids, severities and what each catches. It covers secrets, GitHub Actions, Docker, Docker Compose, Terraform, Kubernetes, prompt injection, dependency integrity and more. No tool edits, fixes or writes anything.
- When to use it
- Useful when an assistant should check code or infrastructure files for security problems during a session, for example reviewing a Docker Compose file, a Terraform module or a GitHub Actions workflow. It is a read-only companion to the separate write-time hook, which is the enforcement path; the MCP server is opt-in by the agent.
- Requirements
- Local process run with uvx from the PyPI package valca, installed with the mcp extra. No accounts, API keys or headers are declared. Scanning is bounded to the directory valca-mcp started in, or to VALCA_MCP_ROOT if set. Network access is used only by the dependency rules, which send package names and version strings to api.osv.dev, pypi.org and registry.npmjs.org.
Installation
In SourceWeft
- Open Valca in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
Valca
AI coding security co-pilot — blocks insecure code at the moment of generation.
Formerly published as
vigilsec. The package is nowvalca. Both thevalcaandvigilcommands work, so existing hooks and scripts keep running unchanged.
Valca intercepts every file an AI coding assistant writes and blocks it if CRITICAL or HIGH security findings are detected — before the file hits disk. It's the only tool that operates at generation time rather than post-commit.
The Problem
AI coding assistants reproduce the most common patterns in their training data. The most common patterns are insecure defaults.
The clearest example: every existing IaC scanner (Checkov, Trivy, Snyk, Semgrep) misses the docker-compose port binding that exposes your database to the internet:
The correct form is "127.0.0.1:5432:5432". Valca catches it. Nothing else does.
Install
Wire the Claude Code hook (one time):
That's it. Every file Claude Code writes is now scanned before it saves. Reload Claude Code to activate.
Network access
Valca's core scanning is fully offline — the package has zero runtime dependencies and the engine never sends your code, file paths, or findings anywhere.
Three rules do reach the network, because checking whether a dependency is vulnerable or fabricated
is impossible offline. When a manifest (requirements.txt, package.json, lockfiles) is scanned,
these rules send package names and version strings only to:
Your source code, file contents, file paths, and scan results are never transmitted. If your
dependency inventory is itself sensitive, turn these rules off in .valcarc and Valca runs
completely offline:
Usage
Review what has been caught over time. Both commands read the local scan history — nothing leaves your machine.
valca stats reports how often each rule fires and how often you suppressed it,
so rules with poor precision in your codebase are visible rather than guessed at.
Exit codes:
See It in Action
Blocking a vulnerable GitHub Actions workflow at write time:
[Valca blocking a Comment-and-Control attack]
In April 2026, researchers found that all three major AI coding agents (Claude Code, Gemini CLI, Copilot) could be hijacked to exfiltrate ANTHROPIC_API_KEY and GITHUB_TOKEN via a hidden HTML comment in a GitHub issue. CVSS 9.4. No special access required.
Valca catches the vulnerable workflow (issues: trigger + AI agent + API key in env) before it reaches git — the only tool that does.
→ Full writeup: The Attack That Steals Your API Keys Through a GitHub Issue Comment
Rules
116 rules across 27 categories. All built-in, stdlib-only, zero runtime dependencies.
This catalogue is generated from the rule registry — it cannot drift from the shipped engine.
Secrets & Credential Exposure (14 rules)
GitHub Actions — AI Agent Surface (13 rules)
AI Agent — Prompt Injection (9 rules)
Dockerfile Hardening (8 rules)
Docker Compose (7 rules)
Terraform (7 rules)
Deserialization & Path Traversal (5 rules)
MCP Server Security (5 rules)
Web Application Security (5 rules)
AI Agent — Excessive Agency (4 rules)
Authentication & Session (4 rules)
Dependency Integrity (4 rules)
Kubernetes (4 rules)
Logging & Data Exposure (4 rules)
Swift / iOS (4 rules)
Dependency CVE Scanners (3 rules)
GitHub Actions — Workflow Hygiene (3 rules)
AI Agent — Configuration Files (2 rules)
JavaScript / TypeScript (2 rules)
Row-Level Security (2 rules)
Cross-Site Scripting (1 rule)
Cryptography (1 rule)
IAM Policies (1 rule)
Python (1 rule)
Shell Scripts (1 rule)
Trivy IaC Deep Scan (1 rule)
nginx (1 rule)
Configuration
Place a .valcarc file in your project root (or any ancestor directory):
Valca walks up the directory tree to find the nearest .valcarc (the former .vigilrc name is still read). Child config always wins over parent. Monorepos can have per-project overrides alongside a workspace default.
Inline suppression — for a specific line you've reviewed and accepted:
Same pattern as # noqa (flake8) and # nosec (bandit).
Opt-out
Valca collects anonymous, local-only telemetry: rule ID, severity, and file extension. No file paths, no code, no identifiable data. Stored at ~/.valca/events.jsonl — never sent anywhere. History from the former ~/.vigil/ location is migrated automatically.
Opt out permanently:
Or in .valcarc:
Adding a Rule
Then add it to DEFAULT_RULES in src/valca/rules/__init__.py. Write tests. Done.
GitHub Actions
Use the action — PranLabs/valca-action:
Or call it directly, without the action:
Findings appear as inline annotations on PR diffs, and in the repository's Security tab.
MCP server
The hook blocks an agent. The MCP server lets one ask.
Register it with any MCP client — for Claude Code, claude mcp add valca -- valca-mcp.
Two tools, both read-only:
There is no tool that edits, fixes or writes anything. A scanner that can modify
code is a new attack surface, and it is the one VGL-MCP003 and VGL-MCP005
exist to catch.
Three limits are built in rather than configurable:
- Scanning cannot leave the root. That root is the directory
valca-mcpstarted in, orVALCA_MCP_ROOTif set. The agent picks the argument toscan, so without a boundary it could walk to~/.sshand map a filesystem it was never given. - Paths come back relative to that root. An absolute path carries your username and directory layout.
- Matched source lines are never returned. For the secret rules that line is the secret.
Telemetry is off on this path whatever your configuration says. Your .valcarc
is still honoured — disabled_rules, exclude_paths and min_severity all
apply.
mcp is an optional extra, so installing Valca normally still pulls no runtime
dependencies at all.
The hook remains the enforcement path. It runs on every write whether the model wants it or not; MCP is opt-in by the agent, and a check an agent can decline is not enforcement.
Development
License
Business Source License 1.1 — free for non-commercial use. Commercial use requires a license agreement. Converts to MIT on 2030-06-26.
Feedback
Found a false positive? Want a rule that doesn't exist yet? Building with AI agents and hitting patterns Valca should catch?
Open an issue → github.com/PranLabs/valca/issues
Or: valca feedback
Source: README.md at commit caad412
Tools
0Version history
1- v0.6.1LatestOct 7, 2026


