# How MCP Server Integration with Claude Code, Codex CLI, and Gemini CLI Enables Automated Security Scanning

> Learn how SkillSpector's MCP server integrates with Claude Code, Codex CLI, and Gemini CLI for automated security scanning. Block malicious skills before installation with runtime guardrails.

- Repository: [NVIDIA Corporation/SkillSpector](https://github.com/NVIDIA/SkillSpector)
- Tags: how-to-guide
- Published: 2026-06-25

---

**SkillSpector's optional MCP server turns static security analysis into a runtime guardrail that Claude Code, Codex CLI, and Gemini CLI can invoke via the Model Context Protocol to block malicious skills before installation.**

NVIDIA's SkillSpector repository provides an MCP (Model Context Protocol) server implementation that transforms its static and LLM-powered security scanner into a callable tool for AI agents. This integration allows Claude Code, Codex CLI, Gemini CLI, and other MCP-compatible agents to automatically evaluate third-party skills for security risks before executing them, effectively embedding security scanning directly into the development workflow.

## MCP Server Architecture and Implementation

The integration centers on a FastMCP server implementation that exposes SkillSpector's core scanning capabilities as a standardized tool that any MCP client can consume.

### FastMCP Server Construction

In [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py), the server builds a **FastMCP** instance when the optional `mcp` extra is installed. The implementation registers a single tool called `scan_skill` at lines 34-55, which forwards arguments to the core `run_scan` function. This design ensures that agents调用 the exact same security graph that the standalone CLI uses, producing consistent risk assessments across all interfaces.

### Tool Contract and Parameters

The `scan_skill` function accepts three parameters with specific type constraints:

```python
async def scan_skill(target: str,
                     use_llm: bool = True,
                     output_format: str = "json") -> dict[str, Any]:

```

- **`target`**: Accepts Git URLs, file URLs, `.zip` archives, `.md` files, or local directories pointing to the skill to analyze
- **`use_llm`**: Toggles the optional semantic LLM pass for deeper code understanding
- **`output_format`**: Selects between JSON, markdown, SARIF, or terminal output representations

The function returns a structured dictionary containing `risk_score`, `safe_to_install`, `findings`, `recommendation`, and transparency fields including `llm_used` and `scan_mode` (lines 55-67 in [`mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/mcp_server.py)).

## CLI Transport Configuration

The `skillspector mcp` command in [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py) serves as the entry point for launching the server with configurable transport mechanisms.

### Starting the Server

Lines 36-47 and 71-78 in [`cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/cli.py) implement the MCP command logic. The CLI parses transport flags and imports the `run` function from [`mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/mcp_server.py) to initialize the server with the selected configuration. This allows system administrators to deploy the security scanner as either a local process or a network-accessible service.

### Transport Options

SkillSpector supports two transport modes for different deployment scenarios:

- **`stdio`** (default): Uses standard input/output streams for local agents like Claude Code that spawn the server as a subprocess
- **`http`**: Provides a streamable HTTP/SSE transport for remote agents or A2A (Agent-to-Agent) callers requiring network accessibility

## Agent Integration with Claude Code, Codex CLI, and Gemini CLI

Any MCP-compatible agent can register the SkillSpector server to enable automatic security validation of skills before installation.

### Claude Code Registration

Claude Code users register SkillSpector through the following command:

```bash
claude mcp add skillspector -- skillspector mcp

```

As documented in the README (lines 23-30), this registration allows Claude to automatically spawn the server process and invoke `scan_skill` whenever the agent encounters a skill requiring validation.

### Codex CLI and Gemini CLI Compatibility

Codex CLI and Gemini CLI integrate through the same MCP protocol standards. These agents connect to the running server via either transport method and call `scan_skill` with the target repository URL. The consistent JSON output format ensures all three agents can parse risk scores and recommendations uniformly, regardless of which LLM powers the agent itself.

### Runtime Gating and Security Verdicts

The agent receives a structured verdict that enables automated policy enforcement. When `risk_score ≤ 50`, the `safe_to_install` field returns `true` alongside a specific `recommendation` string. Agents can use these fields to block installations, warn users, or automatically proceed based on organizational security policies. This transforms SkillSpector from an out-of-band audit tool into an active runtime guardrail.

## Security Guarantees and Transparency

The MCP server implementation includes specific safeguards to prevent accidental execution of malicious code while maintaining clear audit trails.

### Static Analysis Safeguards

The server never executes the scanned skill. According to the source code in [`mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/mcp_server.py), the implementation runs only static analyses combined with optional LLM evaluation of file contents. This architectural constraint prevents the MCP server itself from becoming a vector for code execution attacks.

### LLM Usage Transparency

The response includes explicit `llm_requested` and `llm_used` boolean fields that indicate whether a semantic pass actually occurred. This transparency prevents security teams from accidentally trusting static-only scans when LLM analysis was expected, ensuring consistent security postures across automated workflows.

## Implementation Examples

Install the optional MCP dependencies to enable server functionality:

```bash
pip install "skillspector[mcp]"

```

Start the server locally for Claude Code integration:

```bash
skillspector mcp

```

Launch with HTTP transport for remote agents:

```bash
skillspector mcp --transport http --host 127.0.0.1 --port 8000

```

Call the tool from any MCP-compatible agent:

```python
from mcp_client import MCPClient

client = MCPClient(transport="http", host="127.0.0.1", port=8000)

result = client.call_tool(
    "scan_skill",
    target="https://github.com/example/skill-repo",
    use_llm=True,
    output_format="json"
)

if not result["safe_to_install"]:
    raise InstallationBlockedError(f"Risk score {result['risk_score']}: {result['recommendation']}")

```

## Summary

- **FastMCP Implementation**: The [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py) file implements a FastMCP server exposing the `scan_skill` tool that wraps the core `run_scan` function
- **Transport Flexibility**: [`src/skillspector/cli.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/cli.py) supports both stdio (for local agents) and HTTP/SSE (for remote agents) transport modes via the `skillspector mcp` command
- **Agent Compatibility**: Claude Code, Codex CLI, and Gemini CLI register the server using standard MCP client commands and receive structured JSON verdicts
- **Runtime Protection**: The integration enables agents to block skill installations when `risk_score` exceeds 50 or `safe_to_install` returns false
- **Safety Architecture**: The server performs only static analysis and optional LLM evaluation, never executing the scanned skill code

## Frequently Asked Questions

### How do I register SkillSpector with Claude Code specifically?

Use the command `claude mcp add skillspector -- skillspector mcp` in your terminal. This registers the local server binary with Claude Code's MCP client, allowing Claude to automatically spawn the process and invoke `scan_skill` when analyzing skill repositories.

### Can SkillSpector's MCP server run without installing the LLM components?

Yes. The `use_llm` parameter defaults to `true` but can be set to `false` when calling `scan_skill`. However, the `mcp` extra must still be installed via `pip install "skillspector[mcp]"` to enable the server functionality itself, even if you only want static analysis.

### What is the security threshold that determines if a skill is safe to install?

The `safe_to_install` field returns `true` when the `risk_score` is less than or equal to 50. This threshold is evaluated in the `run_scan` function within [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py), and the accompanying `recommendation` field provides human-readable guidance for scores above this threshold.

### Does the MCP server execute the skill code during scanning?

No. According to the implementation in [`src/skillspector/mcp_server.py`](https://github.com/NVIDIA/SkillSpector/blob/main/src/skillspector/mcp_server.py), the server exclusively performs static analysis and optional LLM evaluation of file contents. It never executes the scanned skill, preventing the MCP server from becoming an attack vector for malicious code execution.