Skip to content
mcp/skillhub

TAR Engine MCP Server

by qingxuantangio.github.qingxuantang/tar-enginev0.3.3

Audit AI skill safety before you ship. Static, semantic, adversarial, supply chain scans.

2Pythonstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Maintained3mo ago

Install TAR Engine MCP server

Install in Claude Code

claude mcp add tar-engine -e TAR_ENGINE_BYOK_OPENAI_KEY='<tar-engine-byok-openai-key>' -e TAR_ENGINE_BYOK_ANTHROPIC_KEY='<tar-engine-byok-anthropic-key>' -- uvx tar-engine tar-engine tar-engine-mcp

Configuration

VariableRequiredSecretDescription
TAR_ENGINE_URL——Override the audit backend. Default is the hosted playground at https://tarai.dev. Set to http://localhost:8765 (or your own tar-engine deployment) to self-host and keep SKILL.md content on your machine.
TAR_ENGINE_BYOK_OPENAI_KEY—yesOpenAI API key that unlocks the semantic LLM and adversarial prompt-fuzz layers. Static and supply-chain layers run without it.
TAR_ENGINE_BYOK_ANTHROPIC_KEY—yesAnthropic API key alternative to the OpenAI key for the semantic and adversarial layers.

Freshness

Maintained — last maintenance signal 3mo ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-07-23 · 3mo ago · GitHub

  2. Latest release

    2026-06-16 · 4mo ago · GitHub · v0.3.0

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-07-23 · 3mo ago · official registry · v0.3.3

FAQ

›How do I install the TAR Engine MCP server in Claude Code?

Run: claude mcp add tar-engine -e TAR_ENGINE_BYOK_OPENAI_KEY='<tar-engine-byok-openai-key>' -e TAR_ENGINE_BYOK_ANTHROPIC_KEY='<tar-engine-byok-anthropic-key>' -- uvx tar-engine tar-engine tar-engine-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does TAR Engine require an API key?

Yes. It expects TAR_ENGINE_BYOK_OPENAI_KEY, TAR_ENGINE_BYOK_ANTHROPIC_KEY, of which 2 are secrets.

›Can I use TAR Engine as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is TAR Engine in the official MCP registry?

Yes, as io.github.qingxuantang/tar-engine.