How to Run SkillSpector MCP Server with HTTP Transport: A Complete Guide

To run the SkillSpector MCP server with HTTP transport, install the optional mcp dependency and execute skillspector mcp --transport http --host 0.0.0.0 --port 8080, which exposes the scan_skill tool over HTTP for remote agent communication.

NVIDIA SkillSpector exposes its AI agent scanning capabilities as a Model-Centered Programming (MCP) server, enabling any MCP-compatible client to evaluate skills before installation. While the default stdio transport suits local agents, the HTTP transport mode allows remote callers and A2A (Agent-to-Agent) protocols to invoke the scan_skill tool over the network.

Prerequisites: Install the MCP Extra

The HTTP server functionality requires the fastmcp package, which is not included in the base installation. You must install SkillSpector with the mcp extra to access the server components.

pip install "skillspector[mcp]"

This dependency enables the run() function in src/skillspector/mcp_server.py to initialize the FastMCP server with HTTP capabilities.

Starting the HTTP Server

Use the skillspector mcp CLI command with the --transport http flag to start the server. The command is defined in src/skillspector/cli.py and forwards arguments to the run() function in src/skillspector/mcp_server.py.


# Start with default settings (host: 127.0.0.1, port: 8000)

skillspector mcp --transport http

When started, the server configures the underlying FastMCP instance to use streamable-http transport and begins listening for JSON-RPC requests.

Configuration Options: Host and Port

You can customize the bind address and port using the --host and --port options. According to the run() function signature in src/skillspector/mcp_server.py, these parameters default to 127.0.0.1 and 8000 respectively.


# Bind to all interfaces on port 8080

skillspector mcp --transport http --host 0.0.0.0 --port 8080

The implementation sets these values on the server settings object before invoking the HTTP transport:


# From src/skillspector/mcp_server.py

server.settings.host = host
server.settings.port = port
server.run(transport="streamable-http")

Invoking the scan_skill Tool Over HTTP

Once running, the server exposes the scan_skill tool via JSON-RPC over HTTP. You can call it using standard HTTP clients.

Using curl

Send a POST request with a JSON-RPC payload to invoke the scanning functionality:

curl -X POST http://localhost:8080 \
     -H "Content-Type: application/json" \
     -d '{
           "jsonrpc":"2.0",
           "id":1,
           "method":"scan_skill",
           "params":{
             "target":"https://github.com/example/my-skill",
             "use_llm":true,
             "output_format":"json"
           }
         }'

The response contains the verdict dictionary generated by the run_scan() function in src/skillspector/mcp_server.py, including risk assessments and safety recommendations.

Using Python with httpx

For programmatic access from Python applications:

import httpx
import json

payload = {
    "jsonrpc": "2.0",
    "id": 1,
    "method": "scan_skill",
    "params": {
        "target": "https://github.com/example/my-skill",
        "use_llm": True,
        "output_format": "json",
    },
}

resp = httpx.post("http://localhost:8000", json=payload)
result = resp.json()
print(json.dumps(result, indent=2))

How It Works: Source Code Breakdown

The HTTP transport implementation relies on two key components in the NVIDIA/SkillSpector repository.

src/skillspector/cli.py defines the CLI entry point that parses your transport selection:

@app.command()
def mcp(
    transport: TransportChoice = TransportChoice.stdio,
    host: str = "127.0.0.1",
    port: int = 8000,
) -> None:
    """Run SkillSpector as an MCP server."""
    from skillspector.mcp_server import run as run_mcp
    run_mcp(transport=transport.value, host=host, port=port)

src/skillspector/mcp_server.py contains the run() function that configures the server based on the transport mode:

async def run(transport: str = "stdio", host: str = "127.0.0.1", port: int = 8000) -> None:
    """Run the MCP server over ``stdio`` (local agents) or ``http`` (remote/A2A)."""
    server = build_server()
    if transport == "stdio":
        server.run(transport="stdio")
    elif transport == "http":
        server.settings.host = host
        server.settings.port = port
        server.run(transport="streamable-http")
    else:
        raise ValueError(f"transport must be 'stdio' or 'http', got {transport!r}")

The build_server() function instantiates the FastMCP server and registers the scan_skill tool, which internally calls the LangGraph workflow defined in src/skillspector/graph.py to perform the actual security analysis.

Summary

  • Install dependencies: Use pip install "skillspector[mcp]" to obtain the FastMCP library required for HTTP transport.
  • Launch command: Run skillspector mcp --transport http to start the server, with optional --host and --port arguments.
  • Implementation location: The transport logic resides in src/skillspector/mcp_server.py (run() function) and the CLI wrapper is in src/skillspector/cli.py.
  • Protocol: The server uses streamable-http transport and accepts JSON-RPC requests to invoke the scan_skill tool.
  • Remote access: Any HTTP client can communicate with the server, enabling A2A agents to evaluate skills before installation.

Frequently Asked Questions

What is the difference between stdio and HTTP transport in SkillSpector?

stdio transport connects the MCP server via standard input/output streams, designed for local agents running on the same machine (such as Claude Code or Codex CLI). HTTP transport exposes the server as a network endpoint, allowing remote agents, microservices, or A2A protocols to invoke scan_skill over TCP/IP connections.

Can I change the default port from 8000 to something else?

Yes, pass the --port flag followed by your desired port number when starting the server. For example, skillspector mcp --transport http --port 3000 binds the server to port 3000. This value is passed through to the port parameter in the run() function and assigned to server.settings.port before the server starts.

Do I need to install the mcp extra if I only want to use stdio transport?

Yes, the mcp extra is required for both transport modes because it installs the fastmcp package that provides the underlying server framework. Whether you use stdio or HTTP, you must install SkillSpector with pip install "skillspector[mcp]" to access the skillspector mcp CLI command and the src/skillspector/mcp_server.py module.

How do I verify the server is running correctly after starting it?

After executing the start command, check the console output for a log entry indicating the server is listening, such as Listening on http://0.0.0.0:8080. You can then send a test request using curl or any HTTP client to the root endpoint or invoke the scan_skill method with a valid JSON-RPC payload to confirm the server responds correctly.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →