How to Run SkillSpector MCP Server with HTTP Transport: A Complete Guide
To run the SkillSpector MCP server with HTTP transport, install the optional mcp dependency and execute skillspector mcp --transport http --host 0.0.0.0 --port 8080, which exposes the scan_skill tool over HTTP for remote agent communication.
NVIDIA SkillSpector exposes its AI agent scanning capabilities as a Model-Centered Programming (MCP) server, enabling any MCP-compatible client to evaluate skills before installation. While the default stdio transport suits local agents, the HTTP transport mode allows remote callers and A2A (Agent-to-Agent) protocols to invoke the scan_skill tool over the network.
Prerequisites: Install the MCP Extra
The HTTP server functionality requires the fastmcp package, which is not included in the base installation. You must install SkillSpector with the mcp extra to access the server components.
pip install "skillspector[mcp]"
This dependency enables the run() function in src/skillspector/mcp_server.py to initialize the FastMCP server with HTTP capabilities.
Starting the HTTP Server
Use the skillspector mcp CLI command with the --transport http flag to start the server. The command is defined in src/skillspector/cli.py and forwards arguments to the run() function in src/skillspector/mcp_server.py.
# Start with default settings (host: 127.0.0.1, port: 8000)
skillspector mcp --transport http
When started, the server configures the underlying FastMCP instance to use streamable-http transport and begins listening for JSON-RPC requests.
Configuration Options: Host and Port
You can customize the bind address and port using the --host and --port options. According to the run() function signature in src/skillspector/mcp_server.py, these parameters default to 127.0.0.1 and 8000 respectively.
# Bind to all interfaces on port 8080
skillspector mcp --transport http --host 0.0.0.0 --port 8080
The implementation sets these values on the server settings object before invoking the HTTP transport:
# From src/skillspector/mcp_server.py
server.settings.host = host
server.settings.port = port
server.run(transport="streamable-http")
Invoking the scan_skill Tool Over HTTP
Once running, the server exposes the scan_skill tool via JSON-RPC over HTTP. You can call it using standard HTTP clients.
Using curl
Send a POST request with a JSON-RPC payload to invoke the scanning functionality:
curl -X POST http://localhost:8080 \
-H "Content-Type: application/json" \
-d '{
"jsonrpc":"2.0",
"id":1,
"method":"scan_skill",
"params":{
"target":"https://github.com/example/my-skill",
"use_llm":true,
"output_format":"json"
}
}'
The response contains the verdict dictionary generated by the run_scan() function in src/skillspector/mcp_server.py, including risk assessments and safety recommendations.
Using Python with httpx
For programmatic access from Python applications:
import httpx
import json
payload = {
"jsonrpc": "2.0",
"id": 1,
"method": "scan_skill",
"params": {
"target": "https://github.com/example/my-skill",
"use_llm": True,
"output_format": "json",
},
}
resp = httpx.post("http://localhost:8000", json=payload)
result = resp.json()
print(json.dumps(result, indent=2))
How It Works: Source Code Breakdown
The HTTP transport implementation relies on two key components in the NVIDIA/SkillSpector repository.
src/skillspector/cli.py defines the CLI entry point that parses your transport selection:
@app.command()
def mcp(
transport: TransportChoice = TransportChoice.stdio,
host: str = "127.0.0.1",
port: int = 8000,
) -> None:
"""Run SkillSpector as an MCP server."""
from skillspector.mcp_server import run as run_mcp
run_mcp(transport=transport.value, host=host, port=port)
src/skillspector/mcp_server.py contains the run() function that configures the server based on the transport mode:
async def run(transport: str = "stdio", host: str = "127.0.0.1", port: int = 8000) -> None:
"""Run the MCP server over ``stdio`` (local agents) or ``http`` (remote/A2A)."""
server = build_server()
if transport == "stdio":
server.run(transport="stdio")
elif transport == "http":
server.settings.host = host
server.settings.port = port
server.run(transport="streamable-http")
else:
raise ValueError(f"transport must be 'stdio' or 'http', got {transport!r}")
The build_server() function instantiates the FastMCP server and registers the scan_skill tool, which internally calls the LangGraph workflow defined in src/skillspector/graph.py to perform the actual security analysis.
Summary
- Install dependencies: Use
pip install "skillspector[mcp]"to obtain the FastMCP library required for HTTP transport. - Launch command: Run
skillspector mcp --transport httpto start the server, with optional--hostand--portarguments. - Implementation location: The transport logic resides in
src/skillspector/mcp_server.py(run()function) and the CLI wrapper is insrc/skillspector/cli.py. - Protocol: The server uses
streamable-httptransport and accepts JSON-RPC requests to invoke thescan_skilltool. - Remote access: Any HTTP client can communicate with the server, enabling A2A agents to evaluate skills before installation.
Frequently Asked Questions
What is the difference between stdio and HTTP transport in SkillSpector?
stdio transport connects the MCP server via standard input/output streams, designed for local agents running on the same machine (such as Claude Code or Codex CLI). HTTP transport exposes the server as a network endpoint, allowing remote agents, microservices, or A2A protocols to invoke scan_skill over TCP/IP connections.
Can I change the default port from 8000 to something else?
Yes, pass the --port flag followed by your desired port number when starting the server. For example, skillspector mcp --transport http --port 3000 binds the server to port 3000. This value is passed through to the port parameter in the run() function and assigned to server.settings.port before the server starts.
Do I need to install the mcp extra if I only want to use stdio transport?
Yes, the mcp extra is required for both transport modes because it installs the fastmcp package that provides the underlying server framework. Whether you use stdio or HTTP, you must install SkillSpector with pip install "skillspector[mcp]" to access the skillspector mcp CLI command and the src/skillspector/mcp_server.py module.
How do I verify the server is running correctly after starting it?
After executing the start command, check the console output for a log entry indicating the server is listening, such as Listening on http://0.0.0.0:8080. You can then send a test request using curl or any HTTP client to the root endpoint or invoke the scan_skill method with a valid JSON-RPC payload to confirm the server responds correctly.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →