Claude CodeCAUTION
Claude Code as one-shot MCP server to have an agent in your agent.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@steipete/claude-code-mcp) [](/CHANGELOG.md)
An MCP (Model Context Protocol) server that allows running Claude Code in one-shot mode, with bypassed permissions by default and optional native Claude Code permission modes.
Did you notice that Cursor sometimes struggles with complex, multi-step edits or operations? This server, with its powerful unified claude_code tool, aims to make Claude a more direct and capable agent for your coding tasks.
Overview
This MCP server provides one tool that can be used by LLMs to interact with Claude Code. When integrated with Claude Desktop or other MCP clients, it allows LLMs to:
- Run Claude Code with all permissions bypassed by default (using
--dangerously-skip-permissions) - Execute Claude Code with a native permission mode when requested
- Access file editing capabilities directly
- Enable specific tools by default
Permissions and Alternatives
This server is a thin MCP wrapper around the local Claude Code CLI. By default it preserves the historic behavior and starts Claude Code with --dangerously-skip-permissions. Set the tool's permissionMode argument to default, acceptEdits, auto, dontAsk, or plan when you want Claude Code's native permission checks instead. This wrapper is not an OS-level sandbox; for a hard file-system boundary, run the MCP server or Claude CLI inside your own container, VM, or platform sandbox.
The wrapper cannot approve prompts that belong to a parent MCP client, bypass macOS privacy prompts, or make another Claude Code session inherit its settings. If the calling client stalls while waiting for permission checks, fix the caller's MCP pe
278904636c85OBSERVED · 2026-09-24Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add claude-code-mcp -- npx -y @steipete/[email protected]
{
"mcpServers": {
"claude-code-mcp": {
"command": "npx",
"args": [
"-y",
"@steipete/[email protected]"
]
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
claude_code | read | Claude Code Agent: Your versatile multi-modal assistant for code, file, Git, and terminal operations via Claude CLI. Use \ |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
.cursor/rules/agent.mdc
.windsurfrules
.github/copilot-instructions.md
CLAUDE.md
CURSOR.md
vi.mock('../../package.json', () => ({const decoded = JSON.parse(atob(base64));
@modelcontextprotocol/sdk, zod, @eslint/js, @types/node, @vitest/coverage-v8, tsx, typescript, vitest
assets/claude_code_mcp_logo.png
Gates applied: no_behavioural_pass.
278904636c85full audit observations/trust-audit/mcp-server/steipete__claude-code-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-24 | 278904636c85 | CAUTION | B | 89 | first audit |
Questions
What is the Claude Code MCP server?
Claude Code as one-shot MCP server to have an agent in your agent.
What tools does Claude Code expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Claude Code safe to connect to an agent?
With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Claude Code need?
No credential environment variables were found in its source, so it appears to need none.
How does Claude Code run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @steipete/claude-code-mcp at 1.10.12.
How current is this page?
The grade is for one exact copy of the source (278904636c85), read on 2026-09-24. The repository is watched and re-audited when it changes.