How to Install SkillSpector with the MCP Extra: A Complete Guide
Install SkillSpector with the MCP extra using uv tool install 'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git' to enable the Model Context Protocol server for agent integration.
SkillSpector is an open-source security analysis tool from NVIDIA that evaluates AI skills and extensions for potential risks. While the base package provides CLI functionality, installing the optional MCP extra transforms SkillSpector into a Model Context Protocol server that AI agents can invoke directly. This guide covers the complete installation process and configuration required to run SkillSpector as an MCP-enabled service.
Prerequisites
Before installing SkillSpector with the MCP extra, ensure you have Python 3.10+ and either uv or pip available. The NVIDIA/SkillSpector repository recommends using uv for faster dependency resolution, though both package managers support the same extras syntax.
Create and activate a virtual environment to isolate dependencies:
python -m venv .venv
source .venv/bin/activate # On Windows: .venv\Scripts\activate
Installing SkillSpector with the MCP Extra
The MCP extra adds the mcp_server module located in src/skillspector/mcp_server.py, which implements a FastMCP server exposing the scan_skill tool. This extra is defined in the project's pyproject.toml under [project.optional-dependencies].
Using uv (Recommended)
The canonical installation method uses uv tool install with the extra specification:
# Install with MCP support
uv tool install 'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git'
For CLI-only usage without MCP capabilities, omit the extra:
# CLI-only install (no MCP)
uv tool install git+https://github.com/NVIDIA/skillspector.git
Using pip
If you prefer pip, replace uv tool install with pip install while maintaining the same bracket syntax for extras:
pip install 'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git'
Running the MCP Server
Once installed with the MCP extra, the skillspector mcp sub-command becomes available. The server implementation in src/skillspector/mcp_server.py creates a FastMCP instance that exposes the scan_skill tool and internally calls run_scan to forward requests to the core LangGraph workflow defined in src/skillspector/graph.py.
stdio Transport (Local CLI)
The stdio transport is ideal for local CLI agents like Claude Code:
skillspector mcp
HTTP/SSE Transport (Remote)
For remote callers or web-based agents, use the HTTP transport:
skillspector mcp --transport http --host 127.0.0.1 --port 8000
The server returns a structured verdict including risk_score, severity, recommendation, and LLM accounting details (llm_requested, llm_available, llm_used). The safe_to_install boolean is determined using the RISK_THRESHOLD constant defined in src/skillspector/constants.py.
Registering with AI Agents
After starting the MCP server, register it with your agent environment. For Claude Code, use:
claude mcp add skillspector -- skillspector mcp
Once registered, agents can invoke the scan_skill tool directly, receiving a complete security report before deciding whether to install a skill. The tool accepts parameters including target (the skill URL), use_llm (boolean for LLM analysis), and output_format (e.g., "json").
Summary
- Install the MCP extra using
'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git'syntax with eitheruvorpip - The extra enables the
mcp_servermodule insrc/skillspector/mcp_server.py, which FastMCP uses to expose thescan_skilltool - Start the server using
skillspector mcpfor stdio transport or add--transport httpfor remote access - Register with agents like Claude Code to allow direct invocation of security scans before skill installation
- Core functionality relies on
run_scancalling the LangGraph workflow insrc/skillspector/graph.pyand applying risk thresholds fromsrc/skillspector/constants.py
Frequently Asked Questions
What is the MCP extra in SkillSpector?
The MCP extra is an optional dependency group that installs Model Context Protocol support, adding the mcp_server module located at src/skillspector/mcp_server.py. According to the NVIDIA/SkillSpector source code, this extra enables SkillSpector to run as a FastMCP server that exposes the scan_skill tool to AI agents, whereas the base install only provides CLI functionality.
Can I use SkillSpector without the MCP extra?
Yes, SkillSpector functions as a standalone CLI tool without the MCP extra. The base installation allows you to run security scans directly from the command line. However, you cannot use the skillspector mcp sub-command or integrate with MCP-compatible agents like Claude Code until you install the extra using 'skillspector[mcp]' syntax.
How do I verify the MCP server is running correctly?
Start the server with skillspector mcp and check that the process initializes without errors. For HTTP transport, verify connectivity by accessing http://127.0.0.1:8000 (or your configured host/port). The server correctly initializes when it can load src/skillspector/mcp_server.py and establish the FastMCP connection, logging available tools including scan_skill.
What transport options does the SkillSpector MCP server support?
SkillSpector supports two transport modes: stdio (default) for local CLI agents, and HTTP/SSE for remote network access. Start stdio transport with skillspector mcp alone, or specify HTTP with skillspector mcp --transport http --host 0.0.0.0 --port 8080. The transport layer is handled by FastMCP in src/skillspector/mcp_server.py, while the core scanning logic remains in src/skillspector/graph.py.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →