
Valca
io.github.pranlabsv0.6.1更新於 Oct 7, 2026
Scans code, IaC and AI-agent config for security problems. Read-only — nothing can be edited.
概覽
讓助理對程式碼、IaC 與 AI 代理設定執行唯讀安全掃描,回傳發現項目與規則目錄。
- 功能
- Valca 提供兩個唯讀工具:scan(path) 回傳檔案或目錄的發現項目,包含規則 ID、嚴重性、訊息、檔案、行號與修正建議;list_rules() 回傳完整規則目錄,含每條規則的 ID、嚴重性與偵測內容。涵蓋密鑰、GitHub Actions、Docker、Docker Compose、Terraform、Kubernetes、提示注入、相依性完整性等。沒有任何工具會編輯、修正或寫入內容。
- 適用情境
- 適合在工作階段中讓助理檢查程式碼或基礎設施檔案的安全問題,例如審查 Docker Compose 檔案、Terraform 模組或 GitHub Actions 工作流程。它是獨立寫入時掛鉤的唯讀補充,掛鉤才是強制路徑;MCP 伺服器由代理自行選擇啟用。
- 執行需求
- 透過 uvx 從 PyPI 套件 valca 啟動的本機程序,需安裝 mcp 額外元件。未宣告帳號、API 金鑰或標頭。掃描範圍限於 valca-mcp 啟動時的目錄,或由 VALCA_MCP_ROOT 指定。僅相依性規則需要網路,會把套件名稱與版本字串傳送到 api.osv.dev、pypi.org 與 registry.npmjs.org。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Valca,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
Valca
AI coding security co-pilot — blocks insecure code at the moment of generation.
Formerly published as
vigilsec. The package is nowvalca. Both thevalcaandvigilcommands work, so existing hooks and scripts keep running unchanged.
Valca intercepts every file an AI coding assistant writes and blocks it if CRITICAL or HIGH security findings are detected — before the file hits disk. It's the only tool that operates at generation time rather than post-commit.
The Problem
AI coding assistants reproduce the most common patterns in their training data. The most common patterns are insecure defaults.
The clearest example: every existing IaC scanner (Checkov, Trivy, Snyk, Semgrep) misses the docker-compose port binding that exposes your database to the internet:
The correct form is "127.0.0.1:5432:5432". Valca catches it. Nothing else does.
Install
Wire the Claude Code hook (one time):
That's it. Every file Claude Code writes is now scanned before it saves. Reload Claude Code to activate.
Network access
Valca's core scanning is fully offline — the package has zero runtime dependencies and the engine never sends your code, file paths, or findings anywhere.
Three rules do reach the network, because checking whether a dependency is vulnerable or fabricated
is impossible offline. When a manifest (requirements.txt, package.json, lockfiles) is scanned,
these rules send package names and version strings only to:
Your source code, file contents, file paths, and scan results are never transmitted. If your
dependency inventory is itself sensitive, turn these rules off in .valcarc and Valca runs
completely offline:
Usage
Review what has been caught over time. Both commands read the local scan history — nothing leaves your machine.
valca stats reports how often each rule fires and how often you suppressed it,
so rules with poor precision in your codebase are visible rather than guessed at.
Exit codes:
See It in Action
Blocking a vulnerable GitHub Actions workflow at write time:
[Valca blocking a Comment-and-Control attack]
In April 2026, researchers found that all three major AI coding agents (Claude Code, Gemini CLI, Copilot) could be hijacked to exfiltrate ANTHROPIC_API_KEY and GITHUB_TOKEN via a hidden HTML comment in a GitHub issue. CVSS 9.4. No special access required.
Valca catches the vulnerable workflow (issues: trigger + AI agent + API key in env) before it reaches git — the only tool that does.
→ Full writeup: The Attack That Steals Your API Keys Through a GitHub Issue Comment
Rules
116 rules across 27 categories. All built-in, stdlib-only, zero runtime dependencies.
This catalogue is generated from the rule registry — it cannot drift from the shipped engine.
Secrets & Credential Exposure (14 rules)
GitHub Actions — AI Agent Surface (13 rules)
AI Agent — Prompt Injection (9 rules)
Dockerfile Hardening (8 rules)
Docker Compose (7 rules)
Terraform (7 rules)
Deserialization & Path Traversal (5 rules)
MCP Server Security (5 rules)
Web Application Security (5 rules)
AI Agent — Excessive Agency (4 rules)
Authentication & Session (4 rules)
Dependency Integrity (4 rules)
Kubernetes (4 rules)
Logging & Data Exposure (4 rules)
Swift / iOS (4 rules)
Dependency CVE Scanners (3 rules)
GitHub Actions — Workflow Hygiene (3 rules)
AI Agent — Configuration Files (2 rules)
JavaScript / TypeScript (2 rules)
Row-Level Security (2 rules)
Cross-Site Scripting (1 rule)
Cryptography (1 rule)
IAM Policies (1 rule)
Python (1 rule)
Shell Scripts (1 rule)
Trivy IaC Deep Scan (1 rule)
nginx (1 rule)
Configuration
Place a .valcarc file in your project root (or any ancestor directory):
Valca walks up the directory tree to find the nearest .valcarc (the former .vigilrc name is still read). Child config always wins over parent. Monorepos can have per-project overrides alongside a workspace default.
Inline suppression — for a specific line you've reviewed and accepted:
Same pattern as # noqa (flake8) and # nosec (bandit).
Opt-out
Valca collects anonymous, local-only telemetry: rule ID, severity, and file extension. No file paths, no code, no identifiable data. Stored at ~/.valca/events.jsonl — never sent anywhere. History from the former ~/.vigil/ location is migrated automatically.
Opt out permanently:
Or in .valcarc:
Adding a Rule
Then add it to DEFAULT_RULES in src/valca/rules/__init__.py. Write tests. Done.
GitHub Actions
Use the action — PranLabs/valca-action:
Or call it directly, without the action:
Findings appear as inline annotations on PR diffs, and in the repository's Security tab.
MCP server
The hook blocks an agent. The MCP server lets one ask.
Register it with any MCP client — for Claude Code, claude mcp add valca -- valca-mcp.
Two tools, both read-only:
There is no tool that edits, fixes or writes anything. A scanner that can modify
code is a new attack surface, and it is the one VGL-MCP003 and VGL-MCP005
exist to catch.
Three limits are built in rather than configurable:
- Scanning cannot leave the root. That root is the directory
valca-mcpstarted in, orVALCA_MCP_ROOTif set. The agent picks the argument toscan, so without a boundary it could walk to~/.sshand map a filesystem it was never given. - Paths come back relative to that root. An absolute path carries your username and directory layout.
- Matched source lines are never returned. For the secret rules that line is the secret.
Telemetry is off on this path whatever your configuration says. Your .valcarc
is still honoured — disabled_rules, exclude_paths and min_severity all
apply.
mcp is an optional extra, so installing Valca normally still pulls no runtime
dependencies at all.
The hook remains the enforcement path. It runs on every write whether the model wants it or not; MCP is opt-in by the agent, and a check an agent can decline is not enforcement.
Development
License
Business Source License 1.1 — free for non-commercial use. Commercial use requires a license agreement. Converts to MIT on 2030-06-26.
Feedback
Found a false positive? Want a rule that doesn't exist yet? Building with AI agents and hitting patterns Valca should catch?
Open an issue → github.com/PranLabs/valca/issues
Or: valca feedback
來源:README.md,提交 caad412
工具
0版本歷史
1- v0.6.1最新Oct 7, 2026


