
Valca
io.github.pranlabsv0.6.1更新于 Oct 7, 2026
Scans code, IaC and AI-agent config for security problems. Read-only — nothing can be edited.
概览
让助手对代码、IaC 和 AI 代理配置执行只读安全扫描,返回发现项和规则目录。
- 功能
- Valca 提供两个只读工具:scan(path) 返回文件或目录的发现项,包括规则 ID、严重级别、消息、文件、行号和修复建议;list_rules() 返回完整规则目录,含每条规则的 ID、严重级别和检测内容。覆盖密钥、GitHub Actions、Docker、Docker Compose、Terraform、Kubernetes、提示注入、依赖完整性等。没有任何工具会编辑、修复或写入内容。
- 适用场景
- 适合在会话中让助手检查代码或基础设施文件的安全问题,例如审查 Docker Compose 文件、Terraform 模块或 GitHub Actions 工作流。它是独立写入时钩子的只读补充,钩子才是强制路径;MCP 服务器由代理自行选择启用。
- 运行要求
- 通过 uvx 从 PyPI 包 valca 启动的本地进程,需安装 mcp 附加组件。未声明账户、API 密钥或请求头。扫描范围限于 valca-mcp 启动时的目录,或由 VALCA_MCP_ROOT 指定。仅依赖规则需要网络,会把包名和版本字符串发送到 api.osv.dev、pypi.org 和 registry.npmjs.org。
安装
在 SourceWeft 中
- 打开 控制台中的 Valca,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
Valca
AI coding security co-pilot — blocks insecure code at the moment of generation.
Formerly published as
vigilsec. The package is nowvalca. Both thevalcaandvigilcommands work, so existing hooks and scripts keep running unchanged.
Valca intercepts every file an AI coding assistant writes and blocks it if CRITICAL or HIGH security findings are detected — before the file hits disk. It's the only tool that operates at generation time rather than post-commit.
The Problem
AI coding assistants reproduce the most common patterns in their training data. The most common patterns are insecure defaults.
The clearest example: every existing IaC scanner (Checkov, Trivy, Snyk, Semgrep) misses the docker-compose port binding that exposes your database to the internet:
The correct form is "127.0.0.1:5432:5432". Valca catches it. Nothing else does.
Install
Wire the Claude Code hook (one time):
That's it. Every file Claude Code writes is now scanned before it saves. Reload Claude Code to activate.
Network access
Valca's core scanning is fully offline — the package has zero runtime dependencies and the engine never sends your code, file paths, or findings anywhere.
Three rules do reach the network, because checking whether a dependency is vulnerable or fabricated
is impossible offline. When a manifest (requirements.txt, package.json, lockfiles) is scanned,
these rules send package names and version strings only to:
Your source code, file contents, file paths, and scan results are never transmitted. If your
dependency inventory is itself sensitive, turn these rules off in .valcarc and Valca runs
completely offline:
Usage
Review what has been caught over time. Both commands read the local scan history — nothing leaves your machine.
valca stats reports how often each rule fires and how often you suppressed it,
so rules with poor precision in your codebase are visible rather than guessed at.
Exit codes:
See It in Action
Blocking a vulnerable GitHub Actions workflow at write time:
[Valca blocking a Comment-and-Control attack]
In April 2026, researchers found that all three major AI coding agents (Claude Code, Gemini CLI, Copilot) could be hijacked to exfiltrate ANTHROPIC_API_KEY and GITHUB_TOKEN via a hidden HTML comment in a GitHub issue. CVSS 9.4. No special access required.
Valca catches the vulnerable workflow (issues: trigger + AI agent + API key in env) before it reaches git — the only tool that does.
→ Full writeup: The Attack That Steals Your API Keys Through a GitHub Issue Comment
Rules
116 rules across 27 categories. All built-in, stdlib-only, zero runtime dependencies.
This catalogue is generated from the rule registry — it cannot drift from the shipped engine.
Secrets & Credential Exposure (14 rules)
GitHub Actions — AI Agent Surface (13 rules)
AI Agent — Prompt Injection (9 rules)
Dockerfile Hardening (8 rules)
Docker Compose (7 rules)
Terraform (7 rules)
Deserialization & Path Traversal (5 rules)
MCP Server Security (5 rules)
Web Application Security (5 rules)
AI Agent — Excessive Agency (4 rules)
Authentication & Session (4 rules)
Dependency Integrity (4 rules)
Kubernetes (4 rules)
Logging & Data Exposure (4 rules)
Swift / iOS (4 rules)
Dependency CVE Scanners (3 rules)
GitHub Actions — Workflow Hygiene (3 rules)
AI Agent — Configuration Files (2 rules)
JavaScript / TypeScript (2 rules)
Row-Level Security (2 rules)
Cross-Site Scripting (1 rule)
Cryptography (1 rule)
IAM Policies (1 rule)
Python (1 rule)
Shell Scripts (1 rule)
Trivy IaC Deep Scan (1 rule)
nginx (1 rule)
Configuration
Place a .valcarc file in your project root (or any ancestor directory):
Valca walks up the directory tree to find the nearest .valcarc (the former .vigilrc name is still read). Child config always wins over parent. Monorepos can have per-project overrides alongside a workspace default.
Inline suppression — for a specific line you've reviewed and accepted:
Same pattern as # noqa (flake8) and # nosec (bandit).
Opt-out
Valca collects anonymous, local-only telemetry: rule ID, severity, and file extension. No file paths, no code, no identifiable data. Stored at ~/.valca/events.jsonl — never sent anywhere. History from the former ~/.vigil/ location is migrated automatically.
Opt out permanently:
Or in .valcarc:
Adding a Rule
Then add it to DEFAULT_RULES in src/valca/rules/__init__.py. Write tests. Done.
GitHub Actions
Use the action — PranLabs/valca-action:
Or call it directly, without the action:
Findings appear as inline annotations on PR diffs, and in the repository's Security tab.
MCP server
The hook blocks an agent. The MCP server lets one ask.
Register it with any MCP client — for Claude Code, claude mcp add valca -- valca-mcp.
Two tools, both read-only:
There is no tool that edits, fixes or writes anything. A scanner that can modify
code is a new attack surface, and it is the one VGL-MCP003 and VGL-MCP005
exist to catch.
Three limits are built in rather than configurable:
- Scanning cannot leave the root. That root is the directory
valca-mcpstarted in, orVALCA_MCP_ROOTif set. The agent picks the argument toscan, so without a boundary it could walk to~/.sshand map a filesystem it was never given. - Paths come back relative to that root. An absolute path carries your username and directory layout.
- Matched source lines are never returned. For the secret rules that line is the secret.
Telemetry is off on this path whatever your configuration says. Your .valcarc
is still honoured — disabled_rules, exclude_paths and min_severity all
apply.
mcp is an optional extra, so installing Valca normally still pulls no runtime
dependencies at all.
The hook remains the enforcement path. It runs on every write whether the model wants it or not; MCP is opt-in by the agent, and a check an agent can decline is not enforcement.
Development
License
Business Source License 1.1 — free for non-commercial use. Commercial use requires a license agreement. Converts to MIT on 2030-06-26.
Feedback
Found a false positive? Want a rule that doesn't exist yet? Building with AI agents and hitting patterns Valca should catch?
Open an issue → github.com/PranLabs/valca/issues
Or: valca feedback
来源:README.md,提交 caad412
工具
0版本历史
1- v0.6.1最新Oct 7, 2026


