Claude Wrap Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Claude Wrap Mcp (Agent Skill) and scored it 92/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 2 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server that lets any MCP-capable agent (Claude Code, Claude Desktop, Cursor, …) spawn and drive Claude Code sessions — effectively turning Claude Code into an orchestratable sub-agent fleet. Built on the claude-wrap library.
claude-wrap pulls the native node-ptyaddon, so a prebuilt binary or a C/C++ toolchain is needed at install time.
windows is Windows-first**.
npm install -g claude-wrap-mcp
# then, in Claude Code:
claude mcp add claude-wrap -- claude-wrap-mcpOr via JSON config (.mcp.json / claude_desktop_config.json):
{
"mcpServers": {
"claude-wrap": { "command": "npx", "args": ["-y", "claude-wrap-mcp"] }
}
}Once published, it's also discoverable in the MCP Registry as io.github.Alex-Kaff/claude-wrap-mcp.
| Tool | What it does |
|---|---|
claude_spawn | Start a headless session in an absolute cwd. Returns a sessionId. |
claude_ask | Send a prompt, wait for idle, return transcript tail + parsed state. Returns status:"busy" on timeout (not an error). |
claude_send | Send raw input (text / line / key) without waiting — for long tasks; then poll. |
claude_status | Parsed state: busy, mode, tokens, pending permission prompt, todos, tool calls. |
claude_snapshot | The rendered transcript lines. |
claude_list | All sessions — in-process (spawned here) and external (discovered windows). |
claude_resolve_permission | approve / deny a pending permission prompt. |
claude_stop | Shut down an in-process session. |
Permission prompts are surfaced, not auto-bypassed: when claude_ask / claude_status report a pending permissionPrompt, resolve it with claude_resolve_permission.
claude-wrap ClaudeManager anddrives headless sessions directly — full parsed state and lifecycle.
are discovered via the registry and driven over their pipe; parsed operations are delegated to the claude-wrap-inject bin. Best-effort; claude_stop is declined for instances this server did not spawn.
pnpm install
pnpm --filter claude-wrap-mcp build # tsup -> dist/ (ESM + .d.ts, shebang on the bin)
pnpm --filter claude-wrap-mcp test # vitest, in-memory MCP client against fakes
pnpm --filter claude-wrap-mcp inspect # @modelcontextprotocol/inspector on the built serverMIT © Alex Kaffetzakis
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.