# How to Run SkillSpector MCP Server with HTTP Transport: A Complete Guide

> Master running the SkillSpector MCP server with HTTP transport. This guide details easy steps to expose the scan_skill tool for remote agent communication.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: how-to-guide
- Published: 2026-07-12

---

**To run the SkillSpector MCP server with HTTP transport, install the optional `mcp` dependency and execute `skillspector mcp --transport http --host 0.0.0.0 --port 8080`, which exposes the `scan_skill` tool over HTTP for remote agent communication.**

NVIDIA SkillSpector exposes its AI agent scanning capabilities as a Model-Centered Programming (MCP) server, enabling any MCP-compatible client to evaluate skills before installation. While the default **stdio** transport suits local agents, the **HTTP** transport mode allows remote callers and A2A (Agent-to-Agent) protocols to invoke the `scan_skill` tool over the network.

## Prerequisites: Install the MCP Extra

The HTTP server functionality requires the `fastmcp` package, which is not included in the base installation. You must install SkillSpector with the `mcp` extra to access the server components.

```bash
pip install "skillspector[mcp]"

```

This dependency enables the `run()` function in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py) to initialize the FastMCP server with HTTP capabilities.

## Starting the HTTP Server

Use the `skillspector mcp` CLI command with the `--transport http` flag to start the server. The command is defined in [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py) and forwards arguments to the `run()` function in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py).

```bash

# Start with default settings (host: 127.0.0.1, port: 8000)

skillspector mcp --transport http

```

When started, the server configures the underlying FastMCP instance to use `streamable-http` transport and begins listening for JSON-RPC requests.

## Configuration Options: Host and Port

You can customize the bind address and port using the `--host` and `--port` options. According to the `run()` function signature in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py), these parameters default to `127.0.0.1` and `8000` respectively.

```bash

# Bind to all interfaces on port 8080

skillspector mcp --transport http --host 0.0.0.0 --port 8080

```

The implementation sets these values on the server settings object before invoking the HTTP transport:

```python

# From src/skillspector/mcp_server.py

server.settings.host = host
server.settings.port = port
server.run(transport="streamable-http")

```

## Invoking the scan_skill Tool Over HTTP

Once running, the server exposes the `scan_skill` tool via JSON-RPC over HTTP. You can call it using standard HTTP clients.

### Using curl

Send a POST request with a JSON-RPC payload to invoke the scanning functionality:

```bash
curl -X POST http://localhost:8080 \
     -H "Content-Type: application/json" \
     -d '{
           "jsonrpc":"2.0",
           "id":1,
           "method":"scan_skill",
           "params":{
             "target":"https://github.com/example/my-skill",
             "use_llm":true,
             "output_format":"json"
           }
         }'

```

The response contains the verdict dictionary generated by the `run_scan()` function in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py), including risk assessments and safety recommendations.

### Using Python with httpx

For programmatic access from Python applications:

```python
import httpx
import json

payload = {
    "jsonrpc": "2.0",
    "id": 1,
    "method": "scan_skill",
    "params": {
        "target": "https://github.com/example/my-skill",
        "use_llm": True,
        "output_format": "json",
    },
}

resp = httpx.post("http://localhost:8000", json=payload)
result = resp.json()
print(json.dumps(result, indent=2))

```

## How It Works: Source Code Breakdown

The HTTP transport implementation relies on two key components in the NVIDIA/SkillSpector repository.

**[`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py)** defines the CLI entry point that parses your transport selection:

```python
@app.command()
def mcp(
    transport: TransportChoice = TransportChoice.stdio,
    host: str = "127.0.0.1",
    port: int = 8000,
) -> None:
    """Run SkillSpector as an MCP server."""
    from skillspector.mcp_server import run as run_mcp
    run_mcp(transport=transport.value, host=host, port=port)

```

**[`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py)** contains the `run()` function that configures the server based on the transport mode:

```python
async def run(transport: str = "stdio", host: str = "127.0.0.1", port: int = 8000) -> None:
    """Run the MCP server over ``stdio`` (local agents) or ``http`` (remote/A2A)."""
    server = build_server()
    if transport == "stdio":
        server.run(transport="stdio")
    elif transport == "http":
        server.settings.host = host
        server.settings.port = port
        server.run(transport="streamable-http")
    else:
        raise ValueError(f"transport must be 'stdio' or 'http', got {transport!r}")

```

The `build_server()` function instantiates the FastMCP server and registers the `scan_skill` tool, which internally calls the LangGraph workflow defined in [`src/skillspector/graph.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/graph.py) to perform the actual security analysis.

## Summary

- **Install dependencies**: Use `pip install "skillspector[mcp]"` to obtain the FastMCP library required for HTTP transport.
- **Launch command**: Run `skillspector mcp --transport http` to start the server, with optional `--host` and `--port` arguments.
- **Implementation location**: The transport logic resides in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py) (`run()` function) and the CLI wrapper is in [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py).
- **Protocol**: The server uses `streamable-http` transport and accepts JSON-RPC requests to invoke the `scan_skill` tool.
- **Remote access**: Any HTTP client can communicate with the server, enabling A2A agents to evaluate skills before installation.

## Frequently Asked Questions

### What is the difference between stdio and HTTP transport in SkillSpector?

**stdio** transport connects the MCP server via standard input/output streams, designed for local agents running on the same machine (such as Claude Code or Codex CLI). **HTTP** transport exposes the server as a network endpoint, allowing remote agents, microservices, or A2A protocols to invoke `scan_skill` over TCP/IP connections.

### Can I change the default port from 8000 to something else?

Yes, pass the `--port` flag followed by your desired port number when starting the server. For example, `skillspector mcp --transport http --port 3000` binds the server to port 3000. This value is passed through to the `port` parameter in the `run()` function and assigned to `server.settings.port` before the server starts.

### Do I need to install the mcp extra if I only want to use stdio transport?

Yes, the `mcp` extra is required for both transport modes because it installs the `fastmcp` package that provides the underlying server framework. Whether you use stdio or HTTP, you must install SkillSpector with `pip install "skillspector[mcp]"` to access the `skillspector mcp` CLI command and the [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py) module.

### How do I verify the server is running correctly after starting it?

After executing the start command, check the console output for a log entry indicating the server is listening, such as `Listening on http://0.0.0.0:8080`. You can then send a test request using curl or any HTTP client to the root endpoint or invoke the `scan_skill` method with a valid JSON-RPC payload to confirm the server responds correctly.