SYS.51 / INTEGRATIONS
Handing it to other software
MCP, webhooks, share links, SBOM and SARIF. Five ways the analysis leaves this product without a person copying anything.
MCP — letting the agent ask
Pulling gives an agent the Skills. This lets it ask the analysis, and get a short, dated answer — measured on this product’s own repository at about 6× fewer tokens than the output of a text search for the same question, and about 94× fewer than reading the files it names.
pskl mcp install --for <tool> connects a coding tool — Claude Code, Codex, Cursor, VS Code, Google Antigravity, PyCharm and the other JetBrains IDEs, and every tool in the table below — on macOS, Windows and Linux. It writes each tool’s own file in its own format, changing only the ProjectSkills entry and keeping the previous version as <file>.projectskills.bak. The connection is read-only: no tool changes anything. pskl mcp doctor checks the whole path each agent takes — the token, the server, its tools, the linked project and every tool configured here — and prints the fix for whatever fails, in your own shell.
Two scopes. In a repository (--scope project, the default where a tool supports it) the file is meant to be committed, so it holds no credential: VS Code asks for the token once and keeps it in its secret storage, and the other tools read PROJECTSKILLS_TOKEN from the environment in their own syntax. On this machine (--scope user) the tool starts pskl mcp serve, a local relay that uses your pskl login — nothing to set, and it works for an editor opened from the Dock or the Start menu, which never sees a shell’s variables. It is started by absolute path to Node and the CLI, so it needs no shell on Windows either.
| Tool | Connect it | In the repository | On this machine |
|---|---|---|---|
| Claude Code | pskl mcp install --for claude | .mcp.json — reads PROJECTSKILLS_TOKEN | prints the claude mcp add --scope user command to run |
| Codex | pskl mcp install --for codex | .codex/config.toml — reads PROJECTSKILLS_TOKEN | ~/.codex/config.toml — starts pskl mcp serve, which uses your sign-in |
| Cursor | pskl mcp install --for cursor | .cursor/mcp.json — reads PROJECTSKILLS_TOKEN | ~/.cursor/mcp.json — starts pskl mcp serve, which uses your sign-in |
| VS Code | pskl mcp install --for vscode | .vscode/mcp.json — asks for the token once and keeps it in its secret storage | VS Code user mcp.json — starts pskl mcp serve, which uses your sign-in |
| Google Antigravity | pskl mcp install --for antigravity | not offered: Antigravity does not expand environment variables, so a repository config would have to contain the token. | ~/.gemini/config/mcp_config.json — starts pskl mcp serve, which uses your sign-in |
| JetBrains IDEs (PyCharm, IntelliJ IDEA …) | pskl mcp install --for jetbrains | not offered: JetBrains AI Assistant is configured in the IDE’s settings, not in a repository file. | prints what to paste — Settings | Tools | AI Assistant | Model Context Protocol (MCP) → Add → As JSON |
| Junie (JetBrains) | pskl mcp install --for junie | not offered: Junie does not document expanding environment variables in a repository config. | ~/.junie/mcp/mcp.json — starts pskl mcp serve, which uses your sign-in |
| Gemini CLI | pskl mcp install --for gemini | .gemini/settings.json — reads PROJECTSKILLS_TOKEN | ~/.gemini/settings.json — starts pskl mcp serve, which uses your sign-in |
| GitHub Copilot CLI | pskl mcp install --for copilot | not offered: Copilot CLI no longer expands ${VAR} in its config (issue #1403), so the token would have to be written in. | ~/.copilot/mcp-config.json — starts pskl mcp serve, which uses your sign-in |
| Devin Desktop (formerly Windsurf) | pskl mcp install --for devin | not offered: Devin Desktop has no repository-level MCP config. | mcp_config.json (Devin, or Windsurf’s for older installs) — starts pskl mcp serve, which uses your sign-in |
| Kiro | pskl mcp install --for kiro | .kiro/settings/mcp.json — reads PROJECTSKILLS_TOKEN | ~/.kiro/settings/mcp.json — starts pskl mcp serve, which uses your sign-in |
| Roo Code | pskl mcp install --for roo | .roo/mcp.json — reads PROJECTSKILLS_TOKEN | Roo’s mcp_settings.json in VS Code — starts pskl mcp serve, which uses your sign-in |
| Cline | pskl mcp install --for cline | not offered: Cline writes a resolved variable back into its settings when a server is toggled (issue #9065); only the relay keeps the token out. | Cline’s cline_mcp_settings.json in VS Code — starts pskl mcp serve, which uses your sign-in |
| Zed | pskl mcp install --for zed | not offered: Zed does not document expanding environment variables in headers. | Zed settings.json (context_servers) — starts pskl mcp serve, which uses your sign-in |
| Claude Desktop | pskl mcp install --for claude-desktop | not offered: Claude Desktop has no repository config. | claude_desktop_config.json — starts pskl mcp serve, which uses your sign-in |
| Visual Studio | pskl mcp install --for visual-studio | not offered: Visual Studio reads .vscode/mcp.json and .cursor/mcp.json in the repository; configure those instead. | %USERPROFILE%\.mcp.json — starts pskl mcp serve, which uses your sign-in |
| OpenCode | pskl mcp install --for opencode | opencode.json — reads PROJECTSKILLS_TOKEN | ~/.config/opencode/opencode.json — starts pskl mcp serve, which uses your sign-in |
| Continue | pskl mcp install --for continue | not offered: Continue does not document headers for remote servers. | prints what to paste — .continue/mcpServers/projectskills.yaml |
| Tool | What it answers | Plan |
|---|---|---|
list_projects | The projects this account has, with each one’s latest analysis. | Every plan |
project_overview | What the project is, what it is built with, and where to start reading. | Every plan |
get_constitution | The rules any AI must follow in this project. | Every plan |
list_skills | Which Skills this project has, and when to use each. | Every plan |
get_skill | One Skill’s full text, exactly as pskl pull writes it. | Every plan |
get_findings | What the deterministic detectors found, and which did not run. | Every plan |
graph_find | The exact node key for a file, symbol or route name. | Premium |
graph_impact | What depends on a file or symbol — what breaks if it changes. | Premium |
graph_ask | Which part of the code a plain-language question touches. | Premium |
graph_path | How two parts of the code are connected. | Premium |
Every answer opens with the snapshot it describes — its number, commit and date — and says so when the commit you are editing is not the analysed one, or a newer analysis is still running. Text quoted from the repository sits on lines that begin │, which the server tells the agent to read as data, never as instructions. A fact that was inferred rather than verified says (inferred), and its evidence follows as — path:line. Answers are sized for an agent’s context, and one that had to be cut says how much and how to narrow the question.
Access is the web’s: the same project membership, the same plan checks and the same per-feature rate limits, spent from the same allowance. Both protocol generations connect — the 2026-07-28 revision without a handshake, and 2025-11-25, 2025-06-18 and 2025-03-26 with one.
Webhooks
A signed POST when an analysis finishes, fails, or turns up something critical.
Each delivery is signed over the timestamp and the body together, so a captured request cannot be replayed with a rewritten header. Redirects are not followed — the address that was checked would not be the address fetched.
A destination that keeps failing is disabled rather than retried forever, and the row says so — a webhook that stopped working is otherwise invisible from the outside.
Share links
A read-only report for somebody with no account.
For a client, a reviewer, or somebody deciding whether to work with you. The page carries no file contents, no excerpts and no identifiers, and it is excluded from search indexes.
The link is the credential, so it is shown once, stored only as a hash, and expires. Expired, revoked and never-existed all answer with the same sentence — telling somebody a link *was* valid tells them they guessed a real one.
SBOM
CycloneDX, built from manifests — and saying so in the field the standard provides.
It is built from the dependency manifests in the repository, not from an installed tree, so it declares itself incomplete rather than asserting completeness by silence.
- Versions come from a lock file where one is readable, and are left absent otherwise — never read off a range, because a caret range permits a version an advisory match would miss.
- No licences are stated. This analysis reads the manifests that name packages and never the packages themselves, and a guessed licence is the one field a compliance reader trusts most.
Explaining a codebase to a person
A guided read, in the order somebody who knows the code would walk you through it.
pskl explain composes what the analysis already produced — the detected stack, the structural scan, the written summary — into plain language: no pillar, no verdict, no provenance glyphs. Those words are precise and they are exactly the ones that lose somebody on their first day.
Every section says what it could not establish, next to the claim it qualifies. A document that explains a codebase to somebody who cannot check it is the easiest place in this product to be quietly wrong.