Skip to main content
Glama
rom-baro

@arcwall/mcp-server

by rom-baro

@arcwall/mcp-server

Security scanning for Claude Code, Cursor, Windsurf, and any MCP-compatible AI coding tool.

Setup

  1. Get your free API key at https://arcwall.io

  2. Add to your MCP config:

Claude Code (~/.claude/mcp.json):

{
  "mcpServers": {
    "arcwall": {
      "command": "npx",
      "args": ["@arcwall/mcp-server"],
      "env": { "ARCWALL_API_KEY": "your-key-here" }
    }
  }
}

Cursor (.cursor/mcp.json): Same config. Windsurf: Add via MCP settings panel.

  1. Restart your AI tool — Arcwall is ready.

Related MCP server: mycop

Tools

  • arcwall_scan_secrets — hardcoded credentials

  • arcwall_scan_mcp — MCP config vulnerabilities

  • arcwall_scan_agent_instructions — CLAUDE.md, .cursorrules security

  • arcwall_threat_model — STRIDE analysis

  • arcwall_check_prompt — prompt injection testing

  • arcwall_pre_commit — pre-commit security check

  • arcwall_scan_dependencies — known CVEs in packages

Usage

Ask your AI assistant:

  • "Scan this repo for secrets"

  • "Check my MCP configs for vulnerabilities"

  • "Is my CLAUDE.md safe?"

  • "Generate a threat model for this project"

  • "Run a security check before I commit"

  • "Are there vulnerable packages in this project?"

Install Server
A
license - permissive license
A
quality
D
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    B
    maintenance
    Automatically detects security vulnerabilities in AI-generated code, scanning for hardcoded secrets, injection flaws, XSS, weak cryptography, authentication issues, path traversal, and vulnerable dependencies across JavaScript, Python, Java, and Go.
    Last updated
    55
    2
    MIT
  • A
    license
    -
    quality
    C
    maintenance
    Agentic security scanning in Claude Code, Cursor, Windsurf
    Last updated
    8
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Agent-native "safe to ship?" security gate for AI-generated code. Uses real parsers and inter-rocedural taint analysis (JS/TS, Python, Go) to flag the classes AI coding agents get wrong — secrets, SQL injection, SS, SSRF, path traversal, command injection, weak JWT/CORS — and ranks findings by confidence. Exposes a scan tool over MCP.
    Last updated
    1
    21
    2
    MIT

View all related MCP servers

Related MCP Connectors

  • Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.

  • Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.

  • Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/rom-baro/arcwall-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server