Connecting agent CLIs (MCP)

Define an MCP server once in ~/.secfoo/config.toml instead of wiring each agent CLI's own config separately. The most common use: an Atlassian/Confluence connector, so --confluence URLs on secfoo run actually resolve to real page content instead of just a link the agent can't follow.

Define the server once

secfoo config init      # writes a starter ~/.secfoo/config.toml if you don't have one

[[mcp_servers]]
name = "Atlassian-Rovo-MCP"
command = "npx"
args = ["-y", "mcp-remote", "https://mcp.atlassian.com/v1/sse"]

Or a remote server reached directly over HTTP/SSE, with an auth header:

[[mcp_servers]]
name = "internal-docs"
url = "https://mcp.internal.example.com/sse"
transport = "sse"
[mcp_servers.headers]
Authorization = "Bearer ${INTERNAL_MCP_TOKEN}"

Every field, including the full stdio-vs-sse/http shape, is in the Configuration reference.

Wiring it into your agent CLI

How a defined server actually reaches the agent depends on which one you're using — this is the part that's easy to miss, since it isn't the same for every agent:

claudeNothing to do. Picked up automatically on every secfoo run, scoped to that invocation only (via --mcp-config) — your global Claude config is never touched.
gemini, agent (Cursor)Run secfoo mcp sync --agent <id> once to register persistently in that tool's own config file. Re-run it after adding new servers to config.toml — already-registered ones are left alone, not duplicated.
agy (Antigravity)Not supported yet — its CLI has no MCP configuration mechanism as of this writing.
secfoo mcp sync --agent gemini
secfoo mcp sync --agent agent   # Cursor's agent id is "agent", not "cursor"

Checking what's configured

secfoo mcp list

Lists every server defined in config.toml by name, with its transport and target (command or URL) — useful for confirming a typo'd server name before you reference it, and for seeing at a glance what secfoo mcp sync will register.

Using it in a run

Once a Confluence-capable server is configured (and synced, for gemini/agent), point a run at real pages:

secfoo run --skill security-architecture-review --agent claude \
  --confluence https://yourteam.atlassian.net/wiki/spaces/ENG/pages/12345/Architecture

Without a working MCP connection, secfoo still passes the URL through to the agent — it just can't fetch the actual page content, so treat that as a signal the server isn't wired up for the agent you're using yet.

See secfoo mcp in the CLI reference.