Atlas / MCP servers / smithery-ai / Smithery CLI

Smithery CLIBLOCK

mcp/smithery-ai/smithery-cli

Install, manage and develop MCP servers and skills for agents

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
17 12r · 4w · 1d
Transport
stdio · streamable-http
License
AGPL-3.0
Stars
837
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Smithery CLI [](https://www.npmjs.com/package/smithery) [](https://www.npmjs.com/package/smithery)

Smithery CLI connects your agents to thousands of skills and MCP servers directly from the command line. To get started, simply run npx skills add smithery/cli.

Installation

npm install -g smithery@latest

Requires Node.js 20+.

Commands

MCP Servers

smithery mcp search [term]              # Search the Smithery registry
smithery mcp add                   # Add an MCP server connection
smithery mcp list                       # List your connections
smithery mcp remove             # Remove connections

Tools

Interact with tools from MCP servers connected via smithery mcp.

smithery tool list [connection]        # List tools from your connected MCP servers
smithery tool find [query]             # Search tools by name or intent
smithery tool get    # Show full details for one tool
smithery tool call   [args]  # Call a tool

Skills

Browse skills on the Smithery Skills Registry and install them with the upstream installer:

npx skills add    # e.g. npx skills add smithery-ai/cli

Auth

smithery auth login                     # Login with Smithery (OAuth)
smithery auth logout                    # Log out
smithery auth whoami                    # Check current user
smithery auth token                     # Mint a service token
smithery auth token --policy ''   # Mint a restricted token

Namespaces

smithery namespace list                 # List your namespaces
smithery namespace use            # Set current namespace

Publishing

smithery mcp publish  -n           # Publish an MCP server URL
smithery mcp publish  -n 
Read from source at commit 81e1b624a82aOBSERVED · 2026-09-27
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add test-server-stateless --env SMITHERY_API_KEY=${SMITHERY_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "test-server-stateless": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "SMITHERY_API_KEY": "${SMITHERY_API_KEY}"
      }
    }
  }
}
03

Exposed tools (17)

12 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create-dashboardwriteCreate a dashboard
experiment-getreadGet experiment details
experiment-results-getreadGet experiment results
get_configreadReturns the config passed to the server
get_server_inforeadGet server type info
get_session_datareadGet accumulated session data
incrementreadTest stateful behavior - should increment across calls
issues.createwriteCreate an issue
issues.labels.addwriteAdd a label
issues.labels.removedestructiveRemove a label
issues.listreadList issues
page.updatedreadFires when a page changes.
pingreadPing
proof_pingreadproof_ping
pulls.createwriteCreate a pull request
repo.searchreadSearch repos
searchreadSearch across repos
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (24)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
src/lib/deploy-payload.ts
deploy-payload.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/utils/run/prepare-stdio-connection.ts:95
const stdioFn = new Function(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/commands/mcp/secrets.ts:89
console.log(`${pc.green("✓")} Secret "${name}" set for ${server}`)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/commands/mcp/secrets.ts:107
console.log(`${pc.green("✓")} Secret "${name}" deleted from ${server}`)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/index.ts:485
console.log(`SMITHERY_API_KEY=${apiKey}`)
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
issues.labels.remove
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/commands/__tests__/add-flow.test.ts:7
vi.mock("../../utils/command-prompts", () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/commands/__tests__/add-flow.test.ts:11
import { setOutputMode } from "../../utils/output"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/commands/__tests__/deploy.test.ts:78
vi.mock("../../utils/runtime", () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/commands/__tests__/deploy.test.ts:82
vi.mock("../../utils/command-prompts", () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/commands/__tests__/deploy.test.ts:88
vi.mock("../../utils/cli-utils", async (importOriginal) => {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/commands/__tests__/mcp-add-uplink.test.ts:96
await addServer("http://127.0.0.1:9090/mcp", {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/commands/__tests__/mcp-add-uplink.test.ts:112
mcpUrl: "http://127.0.0.1:9090/mcp",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/commands/__tests__/mcp-add-uplink.test.ts:133
await addServer("http://127.0.0.1:9090/mcp", {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/commands/__tests__/mcp-add-uplink.test.ts:176
addServer("http://127.0.0.1:9090/mcp", {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/commands/__tests__/uplink-target.test.ts:127
server: "http://127.0.0.1:9090/mcp",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/mcpb, @modelcontextprotocol/sdk, @smithery/api, @smithery/sdk, @types/inquirer, @types/inquirer-autocomplete-prompt, @types/node, @types/ws
Why it matters. 33 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
test/fixtures/stateful-server/package.json
zod, @modelcontextprotocol/sdk
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
test/fixtures/stateless-server/package.json
zod, @modelcontextprotocol/sdk
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:126
* collect configs when smithery api key is prompted ([#173](https://github.com/smithery-ai/cli/issues/173)) ([de6d248](https://github.com/smithery-ai/cli/commit/de6d248a498cb263f8789245d1846ea178aa1bb
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:451
* collect configs when smithery api key is prompted ([#173](https://github.com/smithery-ai/cli/issues/173)) ([de6d248](https://github.com/smithery-ai/cli/commit/de6d248a498cb263f8789245d1846ea178aa1bb
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:1218
- Updated `run` command to load configurations from keychain instead of remote storage
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
skills/smithery-homepage/references/connect-api.md:107
POST https://api.smithery.ai/tokens
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-09-27 · audit v0.4.1 · source sha 81e1b624a82afull audit observations/trust-audit/mcp-server/smithery-ai__smithery-cli.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2781e1b624a82aBLOCKD69first audit
06

Questions

What is the Smithery CLI MCP server?

Install, manage and develop MCP servers and skills for agents

What tools does Smithery CLI expose?

17 in total: 12 read-only, 4 that write, and 1 that can delete or overwrite (issues.labels.remove). Every one is listed on this page with its risk.

Is Smithery CLI safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Smithery CLI need?

It reads SMITHERY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Smithery CLI run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as test-server-stateless at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (81e1b624a82a), read on 2026-09-27. The repository is watched and re-audited when it changes.

Advertisement