# How to Register SkillSpector with Claude Code: A Complete MCP Setup Guide

> Register SkillSpector with Claude Code for MCP setup. Install extras, launch the server, and execute the command to enable the scan_skill security guardrail. Follow this guide for a complete setup.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: how-to-guide
- Published: 2026-07-12

---

**Register SkillSpector with Claude Code by installing the MCP extras, launching the server with `skillspector mcp`, and executing `claude mcp add skillspector -- skillspector mcp` to enable the `scan_skill` security guardrail.**

SkillSpector is NVIDIA’s open-source security scanner for AI agent skills. When you register SkillSpector with Claude Code, you create a Model-Context Protocol (MCP) bridge that intercepts potentially unsafe skill deployments before they execute. This integration runs over stdio transport and requires no external API keys when configured with the Claude CLI provider.

## Install SkillSpector with MCP Support

Before registering, install the package with the optional MCP dependencies. The [`pyproject.toml`](https://github.com/NVIDIA/SkillSpector/blob/main/pyproject.toml) in the repository defines an `mcp` extra that includes FastMCP and related server components.

```bash
uv tool install --force 'skillspector[mcp] @ git+https://github.com/NVIDIA/SkillSpector.git'

```

This command installs the CLI entry point and the server implementation found in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py).

## Start the SkillSpector MCP Server

The server exposes a single tool, `scan_skill(target, use_llm=true, output_format="json")`, which performs static analysis and optional LLM-driven semantic validation. The implementation in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py) defines a FastMCP-compatible server that handles RPC calls over stdio.

Launch the server using the CLI entry point defined in [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py) (lines 466-499):

```bash

# Configure the Claude CLI provider (uses existing `claude` binary, no API key required)

export SKILLSPECTOR_PROVIDER=claude_cli

# Start the MCP server over stdio (fastest transport for local agents)

skillspector mcp

```

The stdio transport provides the lowest latency for Claude Code interactions, as the server runs as a child process and communicates through standard input/output streams.

## Register the Tool with Claude Code

With the server running in one terminal, register it with Claude Code using the MCP discovery command. The repository’s [`README.md`](https://github.com/NVIDIA/SkillSpector/blob/main/README.md) documents this exact registration syntax:

```bash
claude mcp add skillspector -- skillspector mcp

```

This one-liner tells Claude Code to add a tool named `skillspector` whose implementation is the `skillspector mcp` command. After registration, Claude Code can invoke `skillspector.scan_skill(...)` from within any skill’s execution flow.

The server returns a JSON object containing `risk_score`, `severity`, `recommendation`, and `safe_to_install` flags. Claude Code uses this verdict to abort or modify execution based on the security assessment.

## Provider Architecture and Configuration

SkillSpector’s MCP implementation is provider-agnostic. When `use_llm=true` is passed to `scan_skill`, the server routes the request to the configured provider without requiring specific LLM credentials.

The Claude CLI provider, implemented in [`src/skillspector/providers/claude_cli/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/claude_cli/provider.py), wraps the local `claude` binary for model inference. This provider leverages your existing `claude auth login` session and requires no separate API key.

Set the provider explicitly before starting the server:

```bash
export SKILLSPECTOR_PROVIDER=claude_cli

```

When the MCP server receives a scan request, it performs static analysis first, then optionally calls the provider for semantic analysis if `use_llm` is enabled.

## Complete Workflow Example

Follow these steps to implement SkillSpector as a Claude Code guardrail:

1. **Install and configure** the environment:
   ```bash
   uv tool install --force 'skillspector[mcp] @ git+https://github.com/NVIDIA/SkillSpector.git'
   export SKILLSPECTOR_PROVIDER=claude_cli
   ```

2. **Start the MCP server** in a dedicated terminal:
   ```bash
   skillspector mcp
   ```

3. **Register with Claude Code** in another terminal:
   ```bash
   claude mcp add skillspector -- skillspector mcp
   ```

4. **Invoke from a Claude Code skill** (pseudo-code):
   ```python
   result = await skillspector.scan_skill(
       target="https://github.com/example/my-skill",
       use_llm=True,
       output_format="json"
   )
   
   if not result["safe_to_install"]:
       raise RuntimeError(f"Skill rejected: {result['recommendation']}")
   ```

## Summary

- **Register SkillSpector with Claude Code** using the single command `claude mcp add skillspector -- skillspector mcp` after starting the MCP server with `skillspector mcp`.
- The server implementation in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py) exposes the `scan_skill` tool that performs both static and LLM-driven security analysis.
- Configure the Claude CLI provider via `SKILLSPECTOR_PROVIDER=claude_cli` to use the `claude` binary at [`src/skillspector/providers/claude_cli/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/claude_cli/provider.py), eliminating the need for API keys.
- The stdio transport provides fast local execution, making it ideal for guardrails that must evaluate skills before allowing Claude Code to execute them.

## Frequently Asked Questions

### What is the exact command to register SkillSpector with Claude Code?

Run `claude mcp add skillspector -- skillspector mcp` in your terminal. This tells Claude Code to add a tool named `skillspector` that executes the `skillspector mcp` command to start the MCP server. The registration persists in Claude Code’s configuration until you remove it with `claude mcp remove skillspector`.

### Does SkillSpector require an API key when used with Claude Code?

No. When you set `SKILLSPECTOR_PROVIDER=claude_cli`, SkillSpector uses the Claude CLI provider implemented in [`src/skillspector/providers/claude_cli/provider.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/providers/claude_cli/provider.py), which wraps your local `claude` binary. This provider uses your existing `claude auth login` session and requires no separate API key for LLM analysis.

### What parameters does the scan_skill tool accept?

The `scan_skill` tool accepts three parameters: `target` (the skill path or URL to scan), `use_llm` (boolean, defaults to true for semantic analysis), and `output_format` (string, defaults to "json"). These are defined in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py) and return a JSON object containing risk scores, severity levels, recommendations, and a `safe_to_install` boolean.

### Can I use SkillSpector with MCP servers other than Claude Code?

Yes. While the `claude_cli` provider is optimized for Claude Code integration, the MCP server in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py) is provider-agnostic. It supports any MCP client over stdio or HTTP/SSE transports, and can interface with Bedrock, OpenAI, Anthropic, or other LLM providers by changing the `SKILLSPECTOR_PROVIDER` environment variable.