# How to Install SkillSpector with the MCP Extra: A Complete Guide

> Install SkillSpector with the MCP extra using uv tool install for agent integration. Get the complete installation guide for NVIDIA's SkillSpector and enable the Model Context Protocol server.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: how-to-guide
- Published: 2026-07-12

---

**Install SkillSpector with the MCP extra using `uv tool install 'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git'` to enable the Model Context Protocol server for agent integration.**

SkillSpector is an open-source security analysis tool from NVIDIA that evaluates AI skills and extensions for potential risks. While the base package provides CLI functionality, installing the optional **MCP extra** transforms SkillSpector into a Model Context Protocol server that AI agents can invoke directly. This guide covers the complete installation process and configuration required to run SkillSpector as an MCP-enabled service.

## Prerequisites

Before installing SkillSpector with the MCP extra, ensure you have Python 3.10+ and either `uv` or `pip` available. The NVIDIA/SkillSpector repository recommends using `uv` for faster dependency resolution, though both package managers support the same extras syntax.

Create and activate a virtual environment to isolate dependencies:

```bash
python -m venv .venv
source .venv/bin/activate  # On Windows: .venv\Scripts\activate

```

## Installing SkillSpector with the MCP Extra

The MCP extra adds the `mcp_server` module located in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py), which implements a FastMCP server exposing the `scan_skill` tool. This extra is defined in the project's [`pyproject.toml`](https://github.com/NVIDIA/SkillSpector/blob/main/pyproject.toml) under `[project.optional-dependencies]`.

### Using uv (Recommended)

The canonical installation method uses `uv tool install` with the extra specification:

```bash

# Install with MCP support

uv tool install 'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git'

```

For CLI-only usage without MCP capabilities, omit the extra:

```bash

# CLI-only install (no MCP)

uv tool install git+https://github.com/NVIDIA/skillspector.git

```

### Using pip

If you prefer `pip`, replace `uv tool install` with `pip install` while maintaining the same bracket syntax for extras:

```bash
pip install 'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git'

```

## Running the MCP Server

Once installed with the MCP extra, the `skillspector mcp` sub-command becomes available. The server implementation in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py) creates a FastMCP instance that exposes the `scan_skill` tool and internally calls `run_scan` to forward requests to the core LangGraph workflow defined in [`src/skillspector/graph.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/graph.py).

### stdio Transport (Local CLI)

The stdio transport is ideal for local CLI agents like Claude Code:

```bash
skillspector mcp

```

### HTTP/SSE Transport (Remote)

For remote callers or web-based agents, use the HTTP transport:

```bash
skillspector mcp --transport http --host 127.0.0.1 --port 8000

```

The server returns a structured verdict including **risk_score**, **severity**, **recommendation**, and LLM accounting details (`llm_requested`, `llm_available`, `llm_used`). The `safe_to_install` boolean is determined using the `RISK_THRESHOLD` constant defined in [`src/skillspector/constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/constants.py).

## Registering with AI Agents

After starting the MCP server, register it with your agent environment. For Claude Code, use:

```bash
claude mcp add skillspector -- skillspector mcp

```

Once registered, agents can invoke the `scan_skill` tool directly, receiving a complete security report before deciding whether to install a skill. The tool accepts parameters including `target` (the skill URL), `use_llm` (boolean for LLM analysis), and `output_format` (e.g., "json").

## Summary

- **Install the MCP extra** using `'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git'` syntax with either `uv` or `pip`
- **The extra enables** the `mcp_server` module in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py), which FastMCP uses to expose the `scan_skill` tool
- **Start the server** using `skillspector mcp` for stdio transport or add `--transport http` for remote access
- **Register with agents** like Claude Code to allow direct invocation of security scans before skill installation
- **Core functionality** relies on `run_scan` calling the LangGraph workflow in [`src/skillspector/graph.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/graph.py) and applying risk thresholds from [`src/skillspector/constants.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/constants.py)

## Frequently Asked Questions

### What is the MCP extra in SkillSpector?

The **MCP extra** is an optional dependency group that installs Model Context Protocol support, adding the `mcp_server` module located at [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py). According to the NVIDIA/SkillSpector source code, this extra enables SkillSpector to run as a FastMCP server that exposes the `scan_skill` tool to AI agents, whereas the base install only provides CLI functionality.

### Can I use SkillSpector without the MCP extra?

Yes, SkillSpector functions as a standalone CLI tool without the MCP extra. The base installation allows you to run security scans directly from the command line. However, you cannot use the `skillspector mcp` sub-command or integrate with MCP-compatible agents like Claude Code until you install the extra using `'skillspector[mcp]'` syntax.

### How do I verify the MCP server is running correctly?

Start the server with `skillspector mcp` and check that the process initializes without errors. For HTTP transport, verify connectivity by accessing `http://127.0.0.1:8000` (or your configured host/port). The server correctly initializes when it can load [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py) and establish the FastMCP connection, logging available tools including `scan_skill`.

### What transport options does the SkillSpector MCP server support?

SkillSpector supports two transport modes: **stdio** (default) for local CLI agents, and **HTTP/SSE** for remote network access. Start stdio transport with `skillspector mcp` alone, or specify HTTP with `skillspector mcp --transport http --host 0.0.0.0 --port 8080`. The transport layer is handled by FastMCP in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py), while the core scanning logic remains in [`src/skillspector/graph.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/graph.py).