Agent skill

Ripwire MCP

by redhat-et in redhat-et/ripwire

Wire ripwire into an agent as an MCP server — ripwire wrap AGENT (Claude Code, Cursor, Codex, Gemini…) — and choose the server verb mid-task.

Apache-2.0Auto-check: notesAgent Workflows

Install Ripwire MCP

skills CLI
$ npx skills add redhat-et/ripwire --skill ripwire-mcp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install redhat-et/ripwire ripwire-mcp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ripwire-mcp .claude/skills/ripwire-mcp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ripwire-mcp
GitHub stars
2.4k
Token cost
~5.4k tokens
SKILL.md length
2,818 words
Files
2
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

Wire ripwire into an agent as an MCP server — ripwire wrap AGENT (Claude Code, Cursor, Codex, Gemini…) — and choose the server verb mid-task.

  • Tasks that involve MCP servers
  • SKILL.md covers Wiring — ripwire wrap prints…, The read verbs + fetch_body…, Remote transport: --listen… and Editor transport: --lsp…, plus 3 more sections
  • Calls git

What it does

Ripwire MCP is an agent skill from redhat-et/ripwire. Wire ripwire into an agent as an MCP server — ripwire wrap AGENT (Claude Code, Cursor, Codex, Gemini…) — and choose the server verb mid-task. Also tool HEALTH: a symbol you expected is missing from the ranked output, the index feels stale after a rebase, 'is my ripwire setup broken?'

Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `mcp-reference.md`).

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: The ripgrep of AI context: a zero-dependency C++23 CLI + MCP server for coding agents. Find what you want without reading the repo, then check you built what you meant — blast… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve MCP servers

Example prompts

  • “is my ripwire setup broken?”
  • “/ripwire-mcp”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read

What it can do on your machine

Read from SKILL.md and the folder at commit 60dd3b3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ripwire MCP loads about 5.4k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 2,818 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from redhat-et/ripwire at commit 60dd3b3, republished under its Apache-2.0 licence (© redhat-et). 2,818 words, ~5,387 tokens.

Download SKILL.mdSave it as .claude/skills/ripwire-mcp/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
ripwire-mcp
description
Wire ripwire into an agent as an MCP server — `ripwire wrap AGENT` (Claude Code, Cursor, Codex, Gemini…) — and choose the server verb mid-task. Also tool HEALTH: a symbol you expected is missing from the ranked output, the index feels stale after a rebase, 'is my ripwire setup broken?'
allowed-tools
Bash, Read

ripwire as an MCP server

Auditing somebody's .mcp.json for safety instead → ripwire-security-scan.

Trigger: "wire ripwire into my agent", "set up the ripwire MCP server", or "which ripwire MCP verb answers this?".

The 33 verbs, at a glance: 17 read verbs (analyze, rank_by — the same map, ranked by authority/hub/rrf instead of plain PageRank — for, find_symbol, find_referencing_symbols, grep, cochange, memory_recall, situational_awareness, mentions, owners, lego, batch — N read sub-queries in ONE call — fetch_body, and flags — what is BUILT but DARK here: every compile / CMake option() / getenv gate with its default and the size of the code it guards, the answer to "why don't I see feature X?", and doc_drift — which of the repo's markdown claims are now FALSE: dead file:line anchors, deleted symbols, = N constants and [N] extents the code has since changed; call it before trusting a design doc or audit you did not just write, and slice — per-line def-use rows of ONE variable inside ONE definition, flow=back|fwd|both for the transitive data-flow slice, @FILE:LINE seeds by location and pre-picks the variable the seed line names) + 13 flagship-reflex verbs (exemplar, quality_delta, quality_baseline, impact, uses, affected — which tests transitively reach a changed file/symbol, the pre-PR "what do I run?" reflex — path_between, connect — the minimal joining subgraph over N task symbols — the L4 one-call/B11-parity trio explore, from_trace, edit_check — so an MCP-only agent gets the same write & done reflexes as the CLI — and the CROSS-BRANCH pair whereis / stray_content, which answer "where does this content live?" across every branch: the question git cherry cannot, since it compares commit ancestry and every other verb indexes one worktree. stray_content marks a branch superseded when the live line re-implemented its work, which is exactly the case git cherry calls unmerged forever) + the 3 span-addressed edit verbs (replace_symbol_body, insert_before_symbol, insert_after_symbol). Only find_symbol and find_referencing_symbols attach a stable handle= instead of the body (fetch it only when you need it, via fetch_body); the edit verbs enforce a safety contract (staleness refusal, ambiguity refusal, atomic writes) detailed below and in full in mcp-reference.md.

The server exposes 33 MCP verbs: 17 read verbs (incl. rank_by/fetch_body/flags/slice), 13 flagship-reflex verbs (affected/connect/explore/from_trace/edit_check and the cross-branch pair whereis/stray_content) and 3 edit verbs — ripwire wrap codex --force prints the live count.

Wiring — ripwire wrap <agent> prints the recipe

ripwire wrap claude      # → claude mcp add ripwire -- ripwire --mcp
ripwire wrap cursor      # → JSON mcpServers stanza for .cursor/mcp.json (also: windsurf, gemini)
ripwire wrap codex       # → TOML stanza for ~/.codex/config.toml
ripwire wrap opencode    # → CLI first (AGENTS.md is read automatically); its config key is "mcp", NOT mcpServers
ripwire wrap aider       # → no MCP: ripwire . --for="<task>" > .ripwire-map.txt; aider --read .ripwire-map.txt
ripwire wrap --all       # → auto-detect installed agents, emit each one's config in one run

wrap never edits config itself — it prints; you review and run. Before printing it security-scans ./skills and .agents/skills: a CRITICAL finding blocks the recipe (exit 1) unless you pass --force; WARNs print and continue. Bare ripwire wrap lists the supported agents.

Audit the active Codex surface

Run ripwire <repo> --doctor --agent=codex after install/update or when Codex appears to be using a stale binary, missing a skill, skipping the advisory CLI-first hooks, or starting the wrong MCP executable. This extends the ordinary six-check doctor with four read-only checks over the LIVE environment: PATH binary agreement, exact parity between the installed skills and .ripwire-manifest-v1, executability of all three Codex hook roles, and the configured mcp_servers.ripwire command plus --mcp argument. Failing rows give the exact installer/wrap repair command. The report deliberately emits no config contents or full shell commands, so it is safe to paste for diagnosis; --agent=codex alone refuses because it modifies doctor.

"no project root" / "memory limit reached" / _memory_stop

$HOME, / and system directories are never a project root over MCP — not as the launch directory and not as path=: pass the project directory itself (a server started as ripwire ~ --mcp still answers about ~). A tool call refused with "memory limit reached", or an answer carrying _memory_stop in its envelope, means the memory guard cut or refused the work on a tree too large for the machine: point path= at a smaller root, or raise the limit with --max-memory=<N>[K|M|G] (or RIPWIRE_MAX_MEMORY) on the server's command line. The default (65% of RAM) is silent on real projects.

The read verbs + fetch_body (and when each beats the CLI form)

Every verb takes path (the repo root; memory_recall takes the docs/memory dir). For a split service+client checkout, pass paths: [dir1, dir2, ...] instead — the additive multi-root array (path and paths together is a usage error; the 3 edit verbs accept it too, and land a write in the correct root's real file via its label). The server keeps ONE cached workspace per canonical root set: a paths list is deduped and ordered before it's used as the cache key, so calling with the same roots in a different order still hits the warm cache instead of re-parsing; a genuinely different root set gets its own cache entry, not a shared/stale one.

Line-seeded addressing — @FILE:LINE in any resolver-backed selector. Holding a LOCATION (a diff hunk, a compiler error, a stack frame) instead of a name? Pass @src/foo.cpp:120 (1-based line) as the selector and it resolves to the innermost definition enclosing that line — accepted by find_symbol / find_referencing_symbols / impact / edit_check / path_between (from/to) / connect (each entry) / lego (type) / fetch_body (handle), and by uses (which serves the enclosing definition's NAME — its sites stay name-matched, of= echoes the seed as typed). A bad seed — malformed spec, unmatched or ambiguous path, line past EOF, a line no definition spans, two definitions sharing the line — is refused with the same specific diagnosis the CLI's --at/selector arms speak, never guessed. The NAME-matching scan verbs (owners, mentions) do not resolve seeds; a resolvable seed there refuses by naming the definition it resolves to, so the retry is in the message. CLI twin: --at=FILE:LINE (the bare enclosing-chain report) and @FILE:LINE in any SYM selector; contract gate: test/atcheck.sh + test/mcpverbscheck.sh §7.

VerbCLI twinAsk it for
analyzeripwire <dir>the ranked XML map
for (task)--for=TASKthe task lens: signatures + cx/in metrics framed for reuse. Auto-routes the ranker — pass a symbol NAME verbatim as task to get name-exact retrieval (recall@1 ~99%); a conceptual phrase uses subtoken+body. Root carries route= as a code (name-exact(X) / subtoken+body[:broad|:declined]).
find_symbol (symbol)--callers + --calleeslocate a symbol with its callers AND callees in one call — each symbol carries a handle
find_referencing_symbols (symbol)--callers=SYMjust who references/calls it — also handle-bearing
grep (pattern)--grep=STRparallel literal scan + enclosing symbol + matched line
cochange (file)--cochange=FILEthe lockstep git partners of one file
memory_recall (task, top_k + budget_tokens optional)--recall=TASK [--top-k=N] [--max-tokens=N]full bodies of the few relevant docs/memory notes, bounded by the SAME default 8000-token body ceiling as the CLI (the header discloses max_tokens= and every cut). budget_tokens raises the ceiling explicitly when you want everything; top_k (default 8) shapes how many docs
situational_awareness (diff/files optional)--situblast radius, tests_to_run, forgotten co-change partners (the Shotgun Surgery check), hotspot alert — as JSON; defaults to git diff HEAD. In tests_to_run, situational_awareness uses test; explore and edit receipts use p. The field is a path string OR an array of paths beside n — several runner-less tests sharing their attributes, served as one row — and every row carries run or run_unknown: true
mentions (symbol)--mentions=SYMwhich markdown plans/designs discuss a symbol
owners (symbol optional)--owners[=SYM]bus-factor: recency-weighted author ownership
lego (type)--lego=TYPEan interface's method contract + every implementor (own-language)
fetch_body (handle)--expand=SYMthe FULL source of one symbol's definition, addressed by a handle from a prior read verb
batch (queries)--batch=FILEa one-turn context sweep: up to 16 heterogeneous read sub-queries (for/grep/impact/uses/callers/callees/mentions/…) answered in ONE round-trip, merged in order and deduped (<dup-of q="i"/>); a failing sub-query is an inline ok="0" entry, never a whole-batch failure. Reach for it when a task needs several lookups at once.

The flagship-reflex verbs (added 2026-07 so an MCP-only agent gets the same reflexes as the CLI) — these are the moments an agent most often skips the tool for; reach for the verb, not a grep:

VerbCLI twinThe moment
exemplar (kind or task)--exemplarBEFORE you write a fn/class/… — the repo's best-in-class instance to imitate, chosen by ROLE (fan-in / cognitive-cx / tested), with its body
quality_delta (path)--quality-deltaBEFORE you call it DONE — only what the working tree made WORSE vs the baseline (auto-compares vs git-HEAD; a non-empty regressions array is the exit-2-equivalent)
quality_baseline (path)--quality-baselinepin the quality floor (writes the HEAD-stamped .ripwire_quality_baseline) — a side-effect verb
impact (symbol, limit/offset optional)--impact=SYM [--limit=N --offset=M]"is it safe to change X" — the TRANSITIVE blast radius (beats find_referencing_symbols, which is 1-hop). reaches= is the true radius; the listing shows 40 by rank unless you raise it, and a paged answer carries has_more/next_offset so a loop can terminate
uses (symbol)--uses=SYMthe resolvable USE-SITES — call/read/write/import/extends, not just calls (count=0 is a real answer; counts_floor="1" — a floor, never a total)
path_between (from, to)--path=A,Bdoes A reach B, and the shortest call path (named path_between — path is the root-arg key)
connect (symbols)--connect=A,B,Cthe minimal subgraph joining N (>2) task symbols — the shared-caller join a directed path_between can't see
explore (task, budget_tokens + partition optional)--pack-task=TASK [--partition=N]ONE-call task orientation — routed ranking + full bodies + 1-hop callers + field notes + tests_to_run, ALL under one deterministic byte budget (default 6000 tokens). Replaces the for → fetch_body → find_referencing_symbols → memory_recall dance. Also dispatchable as pack_task (same handler; explore is the one advertised in tools/list — the discovery-friendly name). partition: 2..16 turns it into the FAN-OUT form for a multi-agent orchestrator: a shared common core plus N minimally-overlapping per-agent slices carved along the call graph's communities, so N sub-agents stop re-deriving one map — budget_tokens then means ONE agent's budget (core + its slice). Read overlap_max / split / partitions vs requested on the wrapper before trusting the slices
from_trace (trace, budget_tokens optional)--from-trace=FILEpaste a stack trace / sanitizer report / compiler error → the frames mapped onto indexed symbols, ranked INNERMOST-first, with the innermost in-corpus symbol's FULL body. trace = the raw trace TEXT (no stdin/file arg over MCP — paste it, don't hand-translate it into a query)
edit_check (symbol)--edit-check=SYMjust edited a symbol? did its CONTRACT (params/publicness) change vs git HEAD, and which 1-hop callers are now PROVABLY incompatible? Fast targeted check — for the same question over a whole diff use quality_delta instead

MCP beats the CLI when you're mid-task and will ask more than once: the server keeps the parsed {ingest, graph, rank} in memory, so after the first parse every verb answers warm (~ms, no shell round-trip). The CLI still wins for what no verb exposes — --expand/--outline, --around, --deps/--hotspots/--clones, --graph-query, --arch, --pr-context, --scip, --lint-rules, --export, and the two remaining B11 verbs with no MCP twin — --merge-scout (multi-ref UX doesn't map cleanly onto a single JSON-RPC call) and --note-add/--notes (a write verb; adding it needs the same safety-contract thinking the 3 edit verbs got) — shell out for all of these even with the server running; the on-disk warm cache keeps them fast too.

Team/CI: commit the warm cache as an index artifact. ripwire <dir> --index-out=BASE cold-parses once, writes BASE.lean.ripwirecache + BASE.rich.ripwirecache (--for/--exemplar/--metrics need RICH), then exits with no map. Generate on main, commit or CI-cache it, restore with --cache=BASE.lean.ripwirecache (or .rich.) in PR jobs so only changed files re-parse — a same-arch SPEED cache that self-heals to a cold parse if stale or cross-arch (correct, slower). See README "The committable index artifact".

Show full SKILL.md (1,022 more words)Show less

Remote transport: --listen (Streamable HTTP) — opt-in, security posture is the feature

By default --mcp speaks JSON-RPC over stdio (one co-located agent). For a team sharing one warm index, --listen=HOST:PORT serves the same verbs over Streamable HTTP (protocol 2025-11-25) instead — byte-identical JSON-RPC, only the transport differs, single-threaded against one warm index.

The security posture is the whole point (a 2026 survey found ~200K MCP servers naively bridged to the open internet with no auth — ripwire is built so it cannot become one by default): loopback-only by default; a routable host needs both the explicit host flag and a bearer token or the server refuses to start; no TLS built in (reverse-proxy it); one listener pins to ONE workspace at startup; and the 3 edit verbs are refused over remote unless you pass --allow-remote-edits (which also forces the token). Full flag/env reference, the curl recipe, and each refusal's exact wire behavior → mcp-reference.md.

Editor transport: --lsp (navigation LSP server) — read-only, Phase 1

--mcp answers agents and --listen serves a team; --lsp answers editors: a read-only, navigation-focused LSP 3.x server over stdio — lifecycle (initialize/shutdown/exit) plus definition, references, documentSymbol (member variables merged into the outline), workspace symbol, and hover. Same warm index as --mcp — no second parser, no second process. Saved-state answers only: an unsaved buffer is absent from the index, not mispositioned, and every count is a floor, not a total (the hover text says so in place, since JSON-RPC results have no metadata channel). UTF-8 positions; refuses to combine with --mcp/--listen — one protocol per stdin. The PoC plan and its locked decisions live in docs/LSP.md.

The lazy-body posture: names/signatures by default, bodies by handle on request

find_symbol and find_referencing_symbols attach a stable handle to every symbol object they return (the focus symbol, each caller, each callee) — but not the body. Call fetch_body{path, handle} only when you actually need to read the source, instead of the server sending bodies you didn't ask for. This is the kit-style default-lean posture (measured ~90% cut on comparable extract-symbol calls) and matches the 2025-11-25 MCP spec's move to stateless HANDLE semantics.

  • Handle format: sym#<idHash>@<contentHash>, both 16 lowercase hex (FNV-1a-64) — idHash from the symbol's STABLE canonical id (path::scope::name, never the per-run NodeId), contentHash pinning the file's bytes at mint time.
  • Fetch when you're about to reason about the logic, not just to confirm the symbol exists — the name/kind/file/line a read verb already gives you is often enough to decide relevance or pick a call site.
  • Staleness is automatic and free: a content-hash mismatch (file changed since mint) makes fetch_body refuse rather than serve a body against shifted byte offsets — call a read verb again for a fresh handle. A malformed/unresolvable handle refuses the same way, never a silent wrong-symbol body.
  • Handles are content-addressed, not pinned literals: both halves are derived hashes, so a handle you copied out of a prior session or a doc is almost certainly stale — call find_symbol/ find_referencing_symbols fresh each session and read the handle it hands back.

The per-session legend: read ripwire://legend-dict once

Every answer defines its own attributes until the session reads the MCP resource ripwire://legend-dict (initialize names it). After that read, the verbs that take legend (and for) answer rows first and end with <about … legend="ref" dict= dictv=/>, which carries the root attributes; a definition arrives once per session, in a comment after the rows of the first answer that needs it. Lost the definitions (a compacted context)? Read ripwire://legend-dict/full for all of them, or print them with ripwire --legend-dict. legend:"compact" on one call keeps that answer's legend inline. The HTTP transport (--listen) keeps every legend inline.

The 3 MCP edit verbs — the warm-server counterpart to the preferred CLI

replace_symbol_body, insert_before_symbol, insert_after_symbol — the last 3 of the 30 (see above), ripwire's MCP WRITE verbs. The preferred shell front door is ripwire ROOT --replace-symbol-body=SYM --edit-payload=FILE|- (or the matching insert flag); use MCP when the server is already warm or a client has no shell. Both fronts call the same safety engine. Each locates a symbol's definition in the parsed index and splices text at its byte span: replace_symbol_body swaps signature-through-closing-brace verbatim, insert_before_symbol/insert_after_symbol splice text at the def's first/final byte (auto-adding the separating newline so you don't have to guess).

The receipt already answers "what now?" — it carries lines={start,end} for the applied text, edit_check (status / callers / incompatible / each broken caller's call lines) and tests_to_run with the run recipe: the same answers a separate edit_check verb and --affected would give, computed on the index the edit just refreshed. Do not spend two more calls on them. post_check:false (CLI --no-post-check) opts out — reach for it only when the next thing you do is another edit to the same tree.

Read mcp-reference.md before calling one of these 3 (full args table + the exact newline rule + the safety contract for not-found / ambiguous / stale-index / insane-span failures + the atomic-write guarantee) or when you need server internals (--mcp implies --stable, _index staleness stamps, warm content-hash rebuilds, working-set PageRank personalization, the background qsnap HEAD-warm on large workspaces). Short version: every edit-verb failure leaves the file byte-for-byte unchanged, writes are atomic (tmp + rename(2)), and the server never goes stale silently — it rebuilds warm from mtime checks before every verb call. Lead with this MCP form when the body already came from fetch_body this session; after a CLI --expand, keep the zero-standing-schema CLI path and use --edit-payload=-. Several harnesses' native Edit tool needs a fresh Read of the file immediately before the edit, even when you already have the body from elsewhere in the session — these verbs check their own staleness hash instead of requiring one, so under any harness the file gets read at most once, never twice.

Workspace pin (stdio, D3/D4): when the server was started ripwire <root> --mcp, an omitted path on ANY verb (read or edit) defaults to that startup root; the 3 edit verbs above additionally REFUSE (file byte-identical, same contract as every other refusal above) if an explicit path resolves outside it — path outside workspace; start the server on that root or pass an absolute in-root path. Read verbs stay unrestricted at any path. A bare ripwire --mcp with no startup root is unchanged: every verb still requires its own path.

© redhat-et, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/ripwire-mcp of redhat-et/ripwire.

  • SKILL.md
  • mcp-reference.md

Open the folder on GitHubat commit 60dd3b3

Compare with similar skills

Ripwire MCP next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ripwire MCP compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ripwire MCP this skillredhat-et/ripwire2.4k—~5.4kAutomated safety check: NotesApache-2.0
MCP Server Builderanthropics/skills180k64 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Fastmcp Client CLIPrefectHQ/fastmcp28k1 repos~823Automated safety check: PassApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 64 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Fastmcp Client CLI

    PrefectHQ/fastmcp

    Query and invoke tools on MCP servers using fastmcp list and fastmcp call.

    28k GitHub starsUsed in 1 repo~823 tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from redhat-et/ripwire

All 19 skills in this repo
  • Ripwire Output Emission

    redhat-et/ripwire

    Rules for writing and converting formatted output in ripwire's C++ source with its emit helpers, keeping every printed byte identical to the old printf output.

    2.4k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Ripwire Change Check

    redhat-et/ripwire

    Checks whether a working-tree diff or a pull request is safe to merge: blast radius, tests to run, contract breaks, branch conflicts and stranded work.

    2.4k GitHub stars~4.3k tokensUpdated today
    Auto-check: notes
  • Ripwire Graph Query

    redhat-et/ripwire

    Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.

    2.4k GitHub stars~1.1k tokensUpdated today
    Auto-check: notes
  • Ripwire Subsystem Handoff

    redhat-et/ripwire

    Produces a short brief for handing a code subsystem to a teammate or fresh session, using ripwire to rank symbols, expand bodies and surface design docs.

    2.4k GitHub stars~1.8k tokensUpdated today
    Auto-check: notes
  • Ripwire Code Navigation

    redhat-et/ripwire

    Answers questions about a named symbol, such as its callers, what it calls, the path between two symbols or the downstream impact of changing it, using the ripwire CLI.

    2.4k GitHub stars~4.8k tokensUpdated today
    Auto-check: notes
  • Contributor guide for reading clang optimization remarks while editing ripwire's own C++, deciding between a source change and a build change such as LTO or PGO.

    2.4k GitHub stars~3.1k tokensUpdated today
    Auto-check: notes

Categories

Questions about Ripwire MCP

What does Ripwire MCP do?

Wire ripwire into an agent as an MCP server — ripwire wrap AGENT (Claude Code, Cursor, Codex, Gemini…) — and choose the server verb mid-task. Ripwire MCP is an agent skill from redhat-et/ripwire. Wire ripwire into an agent as an MCP server — ripwire wrap AGENT (Claude Code, Cursor, Codex, Gemini…) — and choose the server verb mid-task.

When should I use Ripwire MCP?

Ripwire MCP fits situations like: tasks that involve MCP servers.

How do I install Ripwire MCP in Claude Code?

Run `npx skills add redhat-et/ripwire --skill ripwire-mcp -a claude-code`. Or copy the skill folder (skills/ripwire-mcp in redhat-et/ripwire) into .claude/skills/ripwire-mcp in your project. Claude Code loads it when a task matches its description.

How do I install Ripwire MCP in Codex?

Run `npx skills add redhat-et/ripwire --skill ripwire-mcp -a codex`. Or copy the skill folder (skills/ripwire-mcp in redhat-et/ripwire) into .agents/skills/ripwire-mcp in your project. Codex loads it when a task matches its description.

Can I use Ripwire MCP in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add redhat-et/ripwire --skill ripwire-mcp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ripwire-mcp, .gemini/skills/ripwire-mcp, .github/skills/ripwire-mcp and .opencode/skills/ripwire-mcp in your project.

What does Ripwire MCP need to run?

Going by SKILL.md and its folder, Ripwire MCP needs the command-line tools its instructions call (git). Its frontmatter pre-approves these tools: Bash, Read.

Does Ripwire MCP access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ripwire MCP safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ripwire MCP use?

Ripwire MCP is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ripwire MCP use?

About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ripwire MCP?

Skills that share tags, products or a category with Ripwire MCP: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Fastmcp Client CLI (PrefectHQ/fastmcp, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ripwire MCP?

redhat-et (a GitHub organization) maintains it in redhat-et/ripwire, which has 2,419 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 8, 2026.

Source: redhat-et/ripwire on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.