by paiml
Pragmatic AI Labs MCP Agent Toolkit - An MCP Server designed to make code with agents more deterministic
# Add to your Claude Code skills
git clone https://github.com/paiml/paiml-mcp-agent-toolkitGuides for using ai agents skills like paiml-mcp-agent-toolkit.
Last scanned: 5/30/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-30T16:02:49.044Z",
"npmAuditRan": true,
"pipAuditRan": true
}See how paiml-mcp-agent-toolkit compares with popular alternatives.
paiml-mcp-agent-toolkit is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by paiml. Pragmatic AI Labs MCP Agent Toolkit - An MCP Server designed to make code with agents more deterministic. It has 164 GitHub stars.
Yes. paiml-mcp-agent-toolkit passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/paiml/paiml-mcp-agent-toolkit" and add it to your Claude Code skills directory (see the Installation section above).
paiml-mcp-agent-toolkit is primarily written in Rust. It is open-source under paiml on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh paiml-mcp-agent-toolkit against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Installation | MCP Server | Usage | Features | Examples | Documentation
PMAT (Pragmatic Multi-language Agent Toolkit) provides everything needed to analyze code quality and generate AI-ready context:
.pmat-gates.toml configPart of the PAIML Stack, following Toyota Way quality principles (Jidoka, Genchi Genbutsu, Kaizen).
Every result includes TDG grade, Big-O complexity, git churn, code clones, pattern diversity, fault annotations, call graph, and syntax-highlighted source.
# Install from crates.io
cargo install pmat
Note for macOS Users: If you experience issues installing via
rustup, we recommend installing/updating Rust using Homebrew:brew install rustbefore runningcargo install pmat.
# Or from source (latest)
git clone https://github.com/paiml/paiml-mcp-agent-toolkit
cd paiml-mcp-agent-toolkit && cargo install --path .
PMAT is an MCP server first and a CLI second. One binary serves three surfaces, and they share one tool registry — you pick a surface, not a feature set.
| Surface | Start it with | Use it when |
|---|---|---|
| CLI | pmat analyze complexity --path . |
A human or a shell script reads the output. |
| MCP over stdio | pmat --mode mcp |
An MCP client launches pmat itself as a subprocess — Claude Code, Claude Desktop, Cline. One client, one process, no port, no token. |
| MCP over HTTP | pmat serve --transport http --port 8765 |
One long-lived server that several clients — or another machine — talk to. Streamable HTTP, bearer auth. |
New in 3.32.0:
mcp-httpmoved into the default feature set.cargo install pmatnow gives you the HTTP transport; the old--features mcp-httpdance is gone. Compiling the transport in does not open a socket — onlypmat servebinds one.
Claude Code launches pmat as a subprocess. Nothing to keep running, nothing to authenticate.
cargo install pmat
claude mcp add --scope user pmat -- pmat --mode mcp
claude mcp list
# pmat: pmat --mode mcp - ✔ Connected
Claude Desktop takes the same command as JSON, in its own claude_desktop_config.json:
{
"mcpServers": {
"pmat": { "command": "pmat", "args": ["--mode", "mcp"] }
}
}
For clients that cannot pass flags, MCP_VERSION=1 pmat starts the identical server.
Smoke-test the stdio surface without any client at all:
printf '%s\n' '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' \
| pmat --mode mcp 2>/dev/null | jq -r '.result.tools | length'
# 19
One server, many clients. Copy-paste the whole block:
cargo install pmat
export PMAT_MCP_HTTP_TOKEN='pmat-mcp-demo-token-0123456789' # >= 16 chars; use your own
pmat serve --transport http --port 8765 &
# pmat MCP (streamable HTTP) listening on http://127.0.0.1:8765/
# auth: Bearer, from PMAT_MCP_HTTP_TOKEN; unauthenticated requests get 401
# tools: 20
sleep 2
claude mcp add --scope user --transport http pmat http://127.0.0.1:8765/ \
--header "Authorization: Bearer $PMAT_MCP_HTTP_TOKEN"
claude mcp list
# pmat: http://127.0.0.1:8765/ (HTTP) - ✔ Connected
The server binds 127.0.0.1 unless you pass --host. To reach it from another machine, bind an
externally routable address and treat PMAT_MCP_HTTP_TOKEN as a real secret — the tool
surface can read and analyse any path the server process can read.
1. MCP is served at the root path /, not /mcp. There is no path prefix.
for p in / /mcp /health; do
printf '%-7s %s\n' "$p" "$(curl -s -o /dev/null -w '%{http_code}' -X POST "http://127.0.0.1:8765$p" \
-H "Authorization: Bearer $PMAT_MCP_HTTP_TOKEN" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}')"
done
# / 200
# /mcp 404
# /health 404
2. PMAT_MCP_HTTP_TOKEN is mandatory and must be at least 16 characters. Below that
the server refuses to start rather than falling back to serving unauthenticated — the
underlying pmcp transport answers every request when no auth provider is wired, so "no
token" has to mean "no server". Requests with no token, or a wrong one, get 401.
PMAT_MCP_HTTP_TOKEN=too-short-123 pmat serve --transport http --port 8765
# Error: PMAT_MCP_HTTP_TOKEN must be at least 16 characters; got 13
3. Hand-rolled clients must send Accept: application/json, text/event-stream. The
streamable transport rejects the request without it, and curl -f turns that into an
empty string with no message — so probe with plain curl -s while debugging.
curl -s -w '\n-> HTTP %{http_code}\n' -X POST http://127.0.0.1:8765/ \
-H "Authorization: Bearer $PMAT_MCP_HTTP_TOKEN" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'
# {"jsonrpc":"2.0","error":{"code":-32700,"message":"Accept header must include application/json or text/event-stream"},"id":null}
# -> HTTP 406
4. There is no /health endpoint. GET /health is a 404, so a curl -f .../health readiness loop never turns green and never says why. Probe with a real
tools/list call instead:
curl -s -X POST http://127.0.0.1:8765/ \
-H "Authorization: Bearer $PMAT_MCP_HTTP_TOKEN" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' \
| jq -r '.result.tools | length'
# 19
No MCP session id is involved: initialize returns no Mcp-Session-Id header, and
tools/call works directly — with or without a preceding initialize.
Both transports are built from the same registry, so HTTP serves all 20 tools, not a
subset. The tools/list payloads are byte-identical:
printf '%s\n%s\n' \
'{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"p","version":"1"}}}' \
'{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}' \
| pmat --mode mcp 2>/dev/null \
| jq -Sc 'select(.id==2)|.result.tools|sort_by(.name)' > /tmp/pmat-stdio-tools.json
curl -s -X POST http://127.0.0.1:8765/ \
-H "Authorization: Bearer $PMAT_MCP_HTTP_TOKEN" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' \
| jq -Sc '.result.tools|sort_by(.name)' > /tmp/pmat-http-tools.json
cmp /tmp/pmat-stdio-tools.json /tmp/pmat-http-tools.json && echo "identical"
# identical
The 19: analyze_complexity, analyze_satd, analyze_dead_code, analyze_dag,
analyze_deep_context, analyze_big_o, analyze_reachability,
analyze_hardcoded_paths, analyze_vacuous_tests, quality_gate, quality_proxy,
generate_context, scaffold_project, git_operation, pmat_query_code,
pmat_get_function, pmat_find_similar, pmat_index_stats,
pdmt_deterministic_todos. Names and descriptions are also committed as the machine-checked
manifest mcp.json at the repository root, regenerated from the server's own
registrations — so it cannot drift from what t