PROJECTSKILLSCONNECTING…

SYS.51 / INTEGRATIONS

Handing it to other software

MCP, webhooks, share links, SBOM and SARIF. Five ways the analysis leaves this product without a person copying anything.

Surfaces5 SECTIONS

MCP — letting the agent ask

Pulling gives an agent the Skills. This lets it ask the analysis, and get a short, dated answer — measured on this product’s own repository at about 6× fewer tokens than the output of a text search for the same question, and about 94× fewer than reading the files it names.

pskl mcp install --for <tool> connects a coding tool — Claude Code, Codex, Cursor, VS Code, Google Antigravity, PyCharm and the other JetBrains IDEs, and every tool in the table below — on macOS, Windows and Linux. It writes each tool’s own file in its own format, changing only the ProjectSkills entry and keeping the previous version as <file>.projectskills.bak. The connection is read-only: no tool changes anything. pskl mcp doctor checks the whole path each agent takes — the token, the server, its tools, the linked project and every tool configured here — and prints the fix for whatever fails, in your own shell.

Two scopes. In a repository (--scope project, the default where a tool supports it) the file is meant to be committed, so it holds no credential: VS Code asks for the token once and keeps it in its secret storage, and the other tools read PROJECTSKILLS_TOKEN from the environment in their own syntax. On this machine (--scope user) the tool starts pskl mcp serve, a local relay that uses your pskl login — nothing to set, and it works for an editor opened from the Dock or the Start menu, which never sees a shell’s variables. It is started by absolute path to Node and the CLI, so it needs no shell on Windows either.

ToolConnect itIn the repositoryOn this machine
Claude Codepskl mcp install --for claude.mcp.json — reads PROJECTSKILLS_TOKENprints the claude mcp add --scope user command to run
Codexpskl mcp install --for codex.codex/config.toml — reads PROJECTSKILLS_TOKEN~/.codex/config.toml — starts pskl mcp serve, which uses your sign-in
Cursorpskl mcp install --for cursor.cursor/mcp.json — reads PROJECTSKILLS_TOKEN~/.cursor/mcp.json — starts pskl mcp serve, which uses your sign-in
VS Codepskl mcp install --for vscode.vscode/mcp.json — asks for the token once and keeps it in its secret storageVS Code user mcp.json — starts pskl mcp serve, which uses your sign-in
Google Antigravitypskl mcp install --for antigravitynot offered: Antigravity does not expand environment variables, so a repository config would have to contain the token.~/.gemini/config/mcp_config.json — starts pskl mcp serve, which uses your sign-in
JetBrains IDEs (PyCharm, IntelliJ IDEA …)pskl mcp install --for jetbrainsnot offered: JetBrains AI Assistant is configured in the IDE’s settings, not in a repository file.prints what to paste — Settings | Tools | AI Assistant | Model Context Protocol (MCP) → Add → As JSON
Junie (JetBrains)pskl mcp install --for junienot offered: Junie does not document expanding environment variables in a repository config.~/.junie/mcp/mcp.json — starts pskl mcp serve, which uses your sign-in
Gemini CLIpskl mcp install --for gemini.gemini/settings.json — reads PROJECTSKILLS_TOKEN~/.gemini/settings.json — starts pskl mcp serve, which uses your sign-in
GitHub Copilot CLIpskl mcp install --for copilotnot offered: Copilot CLI no longer expands ${VAR} in its config (issue #1403), so the token would have to be written in.~/.copilot/mcp-config.json — starts pskl mcp serve, which uses your sign-in
Devin Desktop (formerly Windsurf)pskl mcp install --for devinnot offered: Devin Desktop has no repository-level MCP config.mcp_config.json (Devin, or Windsurf’s for older installs) — starts pskl mcp serve, which uses your sign-in
Kiropskl mcp install --for kiro.kiro/settings/mcp.json — reads PROJECTSKILLS_TOKEN~/.kiro/settings/mcp.json — starts pskl mcp serve, which uses your sign-in
Roo Codepskl mcp install --for roo.roo/mcp.json — reads PROJECTSKILLS_TOKENRoo’s mcp_settings.json in VS Code — starts pskl mcp serve, which uses your sign-in
Clinepskl mcp install --for clinenot offered: Cline writes a resolved variable back into its settings when a server is toggled (issue #9065); only the relay keeps the token out.Cline’s cline_mcp_settings.json in VS Code — starts pskl mcp serve, which uses your sign-in
Zedpskl mcp install --for zednot offered: Zed does not document expanding environment variables in headers.Zed settings.json (context_servers) — starts pskl mcp serve, which uses your sign-in
Claude Desktoppskl mcp install --for claude-desktopnot offered: Claude Desktop has no repository config.claude_desktop_config.json — starts pskl mcp serve, which uses your sign-in
Visual Studiopskl mcp install --for visual-studionot offered: Visual Studio reads .vscode/mcp.json and .cursor/mcp.json in the repository; configure those instead.%USERPROFILE%\.mcp.json — starts pskl mcp serve, which uses your sign-in
OpenCodepskl mcp install --for opencodeopencode.json — reads PROJECTSKILLS_TOKEN~/.config/opencode/opencode.json — starts pskl mcp serve, which uses your sign-in
Continuepskl mcp install --for continuenot offered: Continue does not document headers for remote servers.prints what to paste — .continue/mcpServers/projectskills.yaml
ToolWhat it answersPlan
list_projectsThe projects this account has, with each one’s latest analysis.Every plan
project_overviewWhat the project is, what it is built with, and where to start reading.Every plan
get_constitutionThe rules any AI must follow in this project.Every plan
list_skillsWhich Skills this project has, and when to use each.Every plan
get_skillOne Skill’s full text, exactly as pskl pull writes it.Every plan
get_findingsWhat the deterministic detectors found, and which did not run.Every plan
graph_findThe exact node key for a file, symbol or route name.Premium
graph_impactWhat depends on a file or symbol — what breaks if it changes.Premium
graph_askWhich part of the code a plain-language question touches.Premium
graph_pathHow two parts of the code are connected.Premium

Every answer opens with the snapshot it describes — its number, commit and date — and says so when the commit you are editing is not the analysed one, or a newer analysis is still running. Text quoted from the repository sits on lines that begin │, which the server tells the agent to read as data, never as instructions. A fact that was inferred rather than verified says (inferred), and its evidence follows as — path:line. Answers are sized for an agent’s context, and one that had to be cut says how much and how to narrow the question.

Access is the web’s: the same project membership, the same plan checks and the same per-feature rate limits, spent from the same allowance. Both protocol generations connect — the 2026-07-28 revision without a handshake, and 2025-11-25, 2025-06-18 and 2025-03-26 with one.

Webhooks

A signed POST when an analysis finishes, fails, or turns up something critical.

Each delivery is signed over the timestamp and the body together, so a captured request cannot be replayed with a rewritten header. Redirects are not followed — the address that was checked would not be the address fetched.

A destination that keeps failing is disabled rather than retried forever, and the row says so — a webhook that stopped working is otherwise invisible from the outside.

Share links

A read-only report for somebody with no account.

For a client, a reviewer, or somebody deciding whether to work with you. The page carries no file contents, no excerpts and no identifiers, and it is excluded from search indexes.

The link is the credential, so it is shown once, stored only as a hash, and expires. Expired, revoked and never-existed all answer with the same sentence — telling somebody a link *was* valid tells them they guessed a real one.

SBOM

CycloneDX, built from manifests — and saying so in the field the standard provides.

It is built from the dependency manifests in the repository, not from an installed tree, so it declares itself incomplete rather than asserting completeness by silence.

  • Versions come from a lock file where one is readable, and are left absent otherwise — never read off a range, because a caret range permits a version an advisory match would miss.
  • No licences are stated. This analysis reads the manifests that name packages and never the packages themselves, and a guessed licence is the one field a compliance reader trusts most.

Explaining a codebase to a person

A guided read, in the order somebody who knows the code would walk you through it.

pskl explain composes what the analysis already produced — the detected stack, the structural scan, the written summary — into plain language: no pillar, no verdict, no provenance glyphs. Those words are precise and they are exactly the ones that lose somebody on their first day.

Every section says what it could not establish, next to the claim it qualifies. A document that explains a codebase to somebody who cannot check it is the easiest place in this product to be quietly wrong.

DOCS23 CHAPTERS