Setting up Smithery CLI Skill: Controlling MCP tools via terminal

Smithery CLI connects AI agents to MCP servers and skills right from the terminal: installation, commands, and security notes.

  • Skill Road
  • Setting up Smithery CLI Skill: Controlling MCP tools via terminal

Published on 09.09.2026

What the Smithery CLI skill is

Smithery is a registry service and tool catalog for the Model Context Protocol standard, or MCP, which lets AI agents access external tools and data sources in a standardized way. The associated Smithery CLI, developed in the arcadeai-labs/smithery-cli repository, is described by the provider as the command-line tool that lets users connect their agents to thousands of skills and MCP servers directly from the terminal. Instead of configuring each integration by hand, the CLI bundles search, installation, management, and invocation of MCP tools into a single command-line program. The skill is aimed primarily at developers who want to wire up several AI agents to different external services without maintaining a separate configuration file for every connection by hand.

Installation and core functionality

According to the official README, installation happens via the Node package manager npm using the command npm install global smithery latest, and Node.js version 20 or newer is required. After installation, several command groups become available. The MCP server area lets users search the Smithery registry for suitable servers, add a found server by its URL, list existing connections, and remove connections that are no longer needed. A second command group revolves around the actual tools provided by connected MCP servers: users can list available tools, search them by keyword or intent, inspect details for a single tool, and finally invoke it with matching parameters.

Authentication, namespaces, and skill management

For accessing protected areas of the registry and publishing one's own server, the CLI includes an authentication section that supports browser-based OAuth login, logout, identity verification, and minting service tokens with optionally restricted permissions. In addition, namespace commands let users manage and switch between multiple workspaces, which is particularly useful for teams that maintain separate environments for development and production. Besides MCP servers, Smithery also supports its own skills registry, containing separate, reusable capability modules for agents, which is browsed and installed via an upstream installer called npx skills add.

Practical use: connecting and publishing servers

Day-to-day usage typically starts with a search, for example for a GitHub tool, followed by adding the found server under a chosen identifier. Users can then search tools on the connected server and invoke them directly with structured arguments, for instance to create a new issue in a repository. Anyone running their own MCP server can publish it to the registry via the publish command, either directly by URL or as a bundled MCP bundle archive, making it discoverable to other users. For contributing to the CLI itself, the source code is openly available and can be cloned via git, built with the pnpm package manager, and tested locally.

Security, best practices, and limitations

Because the CLI manages access tokens for third-party services and grants agents access to potentially sensitive tools, authentication should always go through the intended OAuth and token mechanisms rather than being replaced by manually copying credentials into configuration files. Restricted service tokens with a defined policy are preferable when an agent should only have limited rights, instead of granting it full account access. A known risk factor in MCP integrations in general is that connected servers can perform actions on behalf of the agent, which is why only trusted servers from official sources should be connected. The limitation of the Smithery CLI is that it functions purely as a connection and management tool: it neither guarantees the quality of individual registered servers nor takes responsibility for their behavior, so reviewing individual tools before production use remains advisable.

Published on 09.09.2026

Categories

Frequently asked questions

Does this skill strictly require the global Smithery CLI?

Yes. The skill provides operational guidelines for the agent. Real execution requires @smithery/cli installed globally on the machine.

Is the Smithery CLI free to use?

Yes. The repository is published under the AGPL-3.0 open-source license.

Does the agent execute mutating actions autonomously?

The skill explicitly instructs agents to request human confirmation prior to dispatching state-changing operations.