arcwall-security MCP Server
The io.github.rom-baro/arcwall-security MCP server provides security scanning for AI coding tools. It detects secrets, produces threat models, and runs pre-commit checks. It is described as applicable to Claude Code, Cursor, Windsurf, and “any MCP-compatible AI coding tool.” Tooling includes specific scan capabilities.
🛠️ Key Features
- Detects hardcoded secrets
- Generates threat models
- Runs pre-commit checks
- Includes a tool named
arcwall_scan_secrets(hardcoded credentials)
🚀 Use Cases
- Scanning AI coding tool workflows (Claude Code, Cursor, Windsurf, other MCP-compatible tools)
- Pre-commit security checks for AI-assisted development
- Secret detection for repositories using MCP integrations
⚡ Developer Benefits
- Centralizes security scanning across MCP-compatible AI coding tools
- Provides a dedicated secrets scanning tool:
arcwall_scan_secrets
⚠️ Limitations
- Setup requires an API key from https://arcwall.io and configuration in the MCP settings for the target AI tool