Smithery CLIBLOCK
Install, manage and develop MCP servers and skills for agents
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Smithery CLI [](https://www.npmjs.com/package/smithery) [](https://www.npmjs.com/package/smithery)
Smithery CLI connects your agents to thousands of skills and MCP servers directly from the command line. To get started, simply run npx skills add smithery/cli.
Installation
npm install -g smithery@latest
Requires Node.js 20+.
Commands
MCP Servers
smithery mcp search [term] # Search the Smithery registry smithery mcp add # Add an MCP server connection smithery mcp list # List your connections smithery mcp remove # Remove connections
Tools
Interact with tools from MCP servers connected via smithery mcp.
smithery tool list [connection] # List tools from your connected MCP servers smithery tool find [query] # Search tools by name or intent smithery tool get # Show full details for one tool smithery tool call [args] # Call a tool
Skills
Browse skills on the Smithery Skills Registry and install them with the upstream installer:
npx skills add # e.g. npx skills add smithery-ai/cli
Auth
smithery auth login # Login with Smithery (OAuth) smithery auth logout # Log out smithery auth whoami # Check current user smithery auth token # Mint a service token smithery auth token --policy '' # Mint a restricted token
Namespaces
smithery namespace list # List your namespaces smithery namespace use # Set current namespace
Publishing
smithery mcp publish -n # Publish an MCP server URL smithery mcp publish -n
81e1b624a82aOBSERVED · 2026-09-27Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add test-server-stateless --env SMITHERY_API_KEY=${SMITHERY_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"test-server-stateless": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"SMITHERY_API_KEY": "${SMITHERY_API_KEY}"
}
}
}
}Exposed tools (17)
12 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create-dashboard | write | Create a dashboard |
experiment-get | read | Get experiment details |
experiment-results-get | read | Get experiment results |
get_config | read | Returns the config passed to the server |
get_server_info | read | Get server type info |
get_session_data | read | Get accumulated session data |
increment | read | Test stateful behavior - should increment across calls |
issues.create | write | Create an issue |
issues.labels.add | write | Add a label |
issues.labels.remove | destructive | Remove a label |
issues.list | read | List issues |
page.updated | read | Fires when a page changes. |
ping | read | Ping |
proof_ping | read | proof_ping |
pulls.create | write | Create a pull request |
repo.search | read | Search repos |
search | read | Search across repos |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (24)
deploy-payload.ts
const stdioFn = new Function(
console.log(`${pc.green("✓")} Secret "${name}" set for ${server}`)console.log(`${pc.green("✓")} Secret "${name}" deleted from ${server}`)console.log(`SMITHERY_API_KEY=${apiKey}`)issues.labels.remove
.release-please-manifest.json
vi.mock("../../utils/command-prompts", () => ({import { setOutputMode } from "../../utils/output"vi.mock("../../utils/runtime", () => ({vi.mock("../../utils/command-prompts", () => ({vi.mock("../../utils/cli-utils", async (importOriginal) => {await addServer("http://127.0.0.1:9090/mcp", {mcpUrl: "http://127.0.0.1:9090/mcp",
await addServer("http://127.0.0.1:9090/mcp", {addServer("http://127.0.0.1:9090/mcp", {server: "http://127.0.0.1:9090/mcp",
@anthropic-ai/mcpb, @modelcontextprotocol/sdk, @smithery/api, @smithery/sdk, @types/inquirer, @types/inquirer-autocomplete-prompt, @types/node, @types/ws
zod, @modelcontextprotocol/sdk
zod, @modelcontextprotocol/sdk
* collect configs when smithery api key is prompted ([#173](https://github.com/smithery-ai/cli/issues/173)) ([de6d248](https://github.com/smithery-ai/cli/commit/de6d248a498cb263f8789245d1846ea178aa1bb
* collect configs when smithery api key is prompted ([#173](https://github.com/smithery-ai/cli/issues/173)) ([de6d248](https://github.com/smithery-ai/cli/commit/de6d248a498cb263f8789245d1846ea178aa1bb
- Updated `run` command to load configurations from keychain instead of remote storage
POST https://api.smithery.ai/tokens
Gates applied: no_behavioural_pass.
81e1b624a82afull audit observations/trust-audit/mcp-server/smithery-ai__smithery-cli.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-27 | 81e1b624a82a | BLOCK | D | 69 | first audit |
Questions
What is the Smithery CLI MCP server?
Install, manage and develop MCP servers and skills for agents
What tools does Smithery CLI expose?
17 in total: 12 read-only, 4 that write, and 1 that can delete or overwrite (issues.labels.remove). Every one is listed on this page with its risk.
Is Smithery CLI safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Smithery CLI need?
It reads SMITHERY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Smithery CLI run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as test-server-stateless at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (81e1b624a82a), read on 2026-09-27. The repository is watched and re-audited when it changes.