Infrastructure-as-Code scanner exposed as MCP tools to Claude Desktop, Cursor, Continue.dev, and other MCP hosts. Scans Terraform and AWS CDK, performs security analysis with optional LLM augmentation, and provides rule-engine integration via Checkov and cdk-nag plugins.
The iac-scanner MCP server defines 4 tools with reasonable naming (action verbs: scan, run, list, iac_analysis) and clear parameter schemas. All tools have descriptions and input schemas with type definitions. However, descriptions lack depth for LLM optimization, parameter descriptions are minimal, output schemas are undocumented, and error handling guidance is absent. The server follows basic MCP structure but falls short of production-grade patterns around response shaping, pagination, and error recovery.
Return ready-to-use analysis + fix prompt templates. Host LLMs can apply these prompts to content returned by scan_iac_path to produce findings without iac-scanner needing an API key.
List the IaC formats this server can scan.
Run the Checkov rule engine against a path (if installed). Returns deterministic, framework-mapped findings with CWE/CIS/NIST tags. Safe to combine with the host LLM's own analysis for hybrid coverage.
Read Infrastructure-as-Code at the given path. Supports Terraform (directory with main.tf) and AWS CDK (directory with index.ts/js). Secrets are redacted and known secret files (tfstate, tfvars, .env) are skipped. Input is size-capped at 200KB by default. Returns the raw content plus metadata (iac_type, entry_path, file list).
Output schemas completely undocumented. No tool declares return type/structure. LLMs cannot plan downstream calls or extract data reliably.
Error handling completely absent. No guidance on retryability, recovery steps, or user-fixable errors. A path-not-found or Checkov-missing error gives LLM nothing to act on.
Insufficient parameter constraints and descriptions. 'path' parameter lacks guidance on format (absolute vs relative), required directory structure (must contain main.tf?), or validation rules. 'iac_type' parameter has enum but no description of what each type requires.
list_iac_types description (13 chars) violates hard minimum. Fails 20-char threshold and provides no context on when/why to call.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
No pagination or result-limit documentation. scan_iac_path mentions 'size-capped at 200KB by default' but no per-result limits on run_rule_engine findings. Large finding lists could exhaust LLM context.
iac_analysis_prompt naming is vague. 'iac_analysis_prompt' is a noun phrase; should start with verb like 'get_' or 'fetch_'.
Tool composition unclear. Relationship between scan_iac_path and run_rule_engine not documented. When should LLM call both? Can results be combined? Do they return compatible formats?