How MCP Server Integration with Claude Code, Codex CLI, and Gemini CLI Enables Automated Security Scanning

SkillSpector's optional MCP server turns static security analysis into a runtime guardrail that Claude Code, Codex CLI, and Gemini CLI can invoke via the Model Context Protocol to block malicious skills before installation.

NVIDIA's SkillSpector repository provides an MCP (Model Context Protocol) server implementation that transforms its static and LLM-powered security scanner into a callable tool for AI agents. This integration allows Claude Code, Codex CLI, Gemini CLI, and other MCP-compatible agents to automatically evaluate third-party skills for security risks before executing them, effectively embedding security scanning directly into the development workflow.

MCP Server Architecture and Implementation

The integration centers on a FastMCP server implementation that exposes SkillSpector's core scanning capabilities as a standardized tool that any MCP client can consume.

FastMCP Server Construction

In src/skillspector/mcp_server.py, the server builds a FastMCP instance when the optional mcp extra is installed. The implementation registers a single tool called scan_skill at lines 34-55, which forwards arguments to the core run_scan function. This design ensures that agents调用 the exact same security graph that the standalone CLI uses, producing consistent risk assessments across all interfaces.

Tool Contract and Parameters

The scan_skill function accepts three parameters with specific type constraints:

async def scan_skill(target: str,
                     use_llm: bool = True,
                     output_format: str = "json") -> dict[str, Any]:
  • target: Accepts Git URLs, file URLs, .zip archives, .md files, or local directories pointing to the skill to analyze
  • use_llm: Toggles the optional semantic LLM pass for deeper code understanding
  • output_format: Selects between JSON, markdown, SARIF, or terminal output representations

The function returns a structured dictionary containing risk_score, safe_to_install, findings, recommendation, and transparency fields including llm_used and scan_mode (lines 55-67 in mcp_server.py).

CLI Transport Configuration

The skillspector mcp command in src/skillspector/cli.py serves as the entry point for launching the server with configurable transport mechanisms.

Starting the Server

Lines 36-47 and 71-78 in cli.py implement the MCP command logic. The CLI parses transport flags and imports the run function from mcp_server.py to initialize the server with the selected configuration. This allows system administrators to deploy the security scanner as either a local process or a network-accessible service.

Transport Options

SkillSpector supports two transport modes for different deployment scenarios:

  • stdio (default): Uses standard input/output streams for local agents like Claude Code that spawn the server as a subprocess
  • http: Provides a streamable HTTP/SSE transport for remote agents or A2A (Agent-to-Agent) callers requiring network accessibility

Agent Integration with Claude Code, Codex CLI, and Gemini CLI

Any MCP-compatible agent can register the SkillSpector server to enable automatic security validation of skills before installation.

Claude Code Registration

Claude Code users register SkillSpector through the following command:

claude mcp add skillspector -- skillspector mcp

As documented in the README (lines 23-30), this registration allows Claude to automatically spawn the server process and invoke scan_skill whenever the agent encounters a skill requiring validation.

Codex CLI and Gemini CLI Compatibility

Codex CLI and Gemini CLI integrate through the same MCP protocol standards. These agents connect to the running server via either transport method and call scan_skill with the target repository URL. The consistent JSON output format ensures all three agents can parse risk scores and recommendations uniformly, regardless of which LLM powers the agent itself.

Runtime Gating and Security Verdicts

The agent receives a structured verdict that enables automated policy enforcement. When risk_score ≤ 50, the safe_to_install field returns true alongside a specific recommendation string. Agents can use these fields to block installations, warn users, or automatically proceed based on organizational security policies. This transforms SkillSpector from an out-of-band audit tool into an active runtime guardrail.

Security Guarantees and Transparency

The MCP server implementation includes specific safeguards to prevent accidental execution of malicious code while maintaining clear audit trails.

Static Analysis Safeguards

The server never executes the scanned skill. According to the source code in mcp_server.py, the implementation runs only static analyses combined with optional LLM evaluation of file contents. This architectural constraint prevents the MCP server itself from becoming a vector for code execution attacks.

LLM Usage Transparency

The response includes explicit llm_requested and llm_used boolean fields that indicate whether a semantic pass actually occurred. This transparency prevents security teams from accidentally trusting static-only scans when LLM analysis was expected, ensuring consistent security postures across automated workflows.

Implementation Examples

Install the optional MCP dependencies to enable server functionality:

pip install "skillspector[mcp]"

Start the server locally for Claude Code integration:

skillspector mcp

Launch with HTTP transport for remote agents:

skillspector mcp --transport http --host 127.0.0.1 --port 8000

Call the tool from any MCP-compatible agent:

from mcp_client import MCPClient

client = MCPClient(transport="http", host="127.0.0.1", port=8000)

result = client.call_tool(
    "scan_skill",
    target="https://github.com/example/skill-repo",
    use_llm=True,
    output_format="json"
)

if not result["safe_to_install"]:
    raise InstallationBlockedError(f"Risk score {result['risk_score']}: {result['recommendation']}")

Summary

  • FastMCP Implementation: The src/skillspector/mcp_server.py file implements a FastMCP server exposing the scan_skill tool that wraps the core run_scan function
  • Transport Flexibility: src/skillspector/cli.py supports both stdio (for local agents) and HTTP/SSE (for remote agents) transport modes via the skillspector mcp command
  • Agent Compatibility: Claude Code, Codex CLI, and Gemini CLI register the server using standard MCP client commands and receive structured JSON verdicts
  • Runtime Protection: The integration enables agents to block skill installations when risk_score exceeds 50 or safe_to_install returns false
  • Safety Architecture: The server performs only static analysis and optional LLM evaluation, never executing the scanned skill code

Frequently Asked Questions

How do I register SkillSpector with Claude Code specifically?

Use the command claude mcp add skillspector -- skillspector mcp in your terminal. This registers the local server binary with Claude Code's MCP client, allowing Claude to automatically spawn the process and invoke scan_skill when analyzing skill repositories.

Can SkillSpector's MCP server run without installing the LLM components?

Yes. The use_llm parameter defaults to true but can be set to false when calling scan_skill. However, the mcp extra must still be installed via pip install "skillspector[mcp]" to enable the server functionality itself, even if you only want static analysis.

What is the security threshold that determines if a skill is safe to install?

The safe_to_install field returns true when the risk_score is less than or equal to 50. This threshold is evaluated in the run_scan function within src/skillspector/mcp_server.py, and the accompanying recommendation field provides human-readable guidance for scores above this threshold.

Does the MCP server execute the skill code during scanning?

No. According to the implementation in src/skillspector/mcp_server.py, the server exclusively performs static analysis and optional LLM evaluation of file contents. It never executes the scanned skill, preventing the MCP server from becoming an attack vector for malicious code execution.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →