infra-guard

infra-guard

Enables AI assistants to scan Terraform and Dockerfiles for security misconfigurations, returning structured Checkov findings that can be explained in plain language.

Category
Visit Server

README

infra-guard

An MCP server that scans Terraform and Dockerfiles for real security misconfigurations — open security groups, public S3 buckets, wildcard IAM policies, hardcoded secrets, containers running as root — and hands back structured findings instead of a guess.

It plugs into Claude Code, Claude Desktop, or Cursor as a tool. Ask your AI assistant to review your infrastructure code, and it calls infra-guard, gets back real findings from Checkov, and explains them to you.

Try it in the browser: infra-guard-frontend-production.up.railway.app — paste Terraform, click Scan, see real findings. No install required.

MCP endpoint: https://infra-guard-production.up.railway.app/mcp

Why this exists

I did cloud infrastructure work at A.P. Moller–Maersk — Terraform, Docker, AWS provisioning at real scale. Most portfolio projects are generic web apps; this one is the tool I actually wished existed: something that turns "does my Terraform have any obvious security holes" into a real, structured answer instead of an AI assistant's best guess.

infra-guard doesn't guess. It runs your file through Checkov, a real static analysis engine with hundreds of built-in checks, and returns the actual findings — check ID, title, affected resource, line range, code snippet. The hosting LLM (Claude, or whatever's on the other end of the MCP connection) explains the findings in plain English. The tool's job is just to be correct.

How it works

scanner.py   → core engine: scan_terraform(...) / scan_dockerfile(...) -> structured dict
server.py    → wraps both as MCP tools, served over stdio or Streamable HTTP
api.py       → wraps both as a plain REST API (POST /api/scan, POST /api/scan-dockerfile)
frontend/    → React + Vite playground that calls api.py, with a Terraform/Dockerfile toggle

scanner.py shells out to the Checkov CLI, parses its JSON output, and returns the same shape regardless of which framework ran:

{
  "summary": { "passed": 14, "failed": 34, "total_checks": 48 },
  "findings": [
    {
      "check_id": "CKV_AWS_24",
      "title": "Ensure no security groups allow ingress from 0.0.0.0:0 to port 22",
      "resource": "aws_security_group.app_sg",
      "start_line": 6,
      "end_line": 24,
      "code_snippet": "resource \"aws_security_group\" \"app_sg\" { ... }"
    }
  ]
}

server.py exposes two MCP tools, scan_terraform_file(file_content, filename) and scan_dockerfile_file(file_content, filename), with no interpretation layer of its own — the structured data goes straight to whatever LLM is hosting the session.

insecure_example.tf has four intentional Terraform issues (open SSH ingress, a public+unencrypted S3 bucket, a wildcard IAM policy, a hardcoded RDS password) — 14 passed / 34 failed checks. insecure_example.Dockerfile has five (unpinned base image, ADD instead of COPY, port 22 exposed, no HEALTHCHECK, runs as root) — 26 passed / 5 failed checks.

Running it locally

Requires uv.

git clone https://github.com/SanjanaJanardhan/infra-guard.git
cd infra-guard
uv sync

Run the scanner directly:

uv run python3 scanner.py

Run the MCP server over stdio (for local clients like Claude Code/Desktop):

uv run python3 server.py

Run it over Streamable HTTP (for remote clients, or to reproduce the deployed setup):

uv run python3 server.py --transport streamable-http --port 8000

Connecting it to an MCP client

Claude Code / Claude Desktop — add to .mcp.json (project-level) or your global MCP config:

{
  "mcpServers": {
    "infra-guard": {
      "command": "uv",
      "args": ["--directory", "/absolute/path/to/infra-guard", "run", "python3", "server.py"]
    }
  }
}

Any Streamable HTTP client (including the live deployment above) — point it at:

https://infra-guard-production.up.railway.app/mcp

Running the playground locally

# terminal 1 — API
uv run python3 api.py

# terminal 2 — frontend
cd frontend
npm install
npm run dev

The frontend reads its API base URL from VITE_API_URL (see frontend/.env.local), defaulting to http://localhost:8001.

Deployment

Three services on Railway, all built from Docker/Nixpacks with no manual server config:

  • MCP server — Dockerfile, Streamable HTTP
  • REST API — Dockerfile.api, same scanner.py core, powers the playground
  • Frontend — Railway's Nixpacks builder auto-detects the Vite app in frontend/; VITE_API_URL is set at build time to the deployed API's URL

Both Python services read PORT from the environment, so they adapt to whatever port Railway assigns with no config changes.

Stack

Python · Checkov · MCP Python SDK · FastAPI · React · Vite · uv · Docker · Railway

Roadmap

  • [x] Core Terraform scanning engine
  • [x] MCP server over stdio
  • [x] Streamable HTTP transport
  • [x] Deployed to Railway
  • [x] Web frontend with a live playground
  • [x] Dockerfile scanning, including a Terraform/Dockerfile toggle in the playground
  • [ ] Cost-impact estimate for findings

License

MIT

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured