Connecting agent CLIs (MCP)
Define an MCP server once in ~/.secfoo/config.toml instead of wiring each agent CLI's own config separately. The most common use: an Atlassian/Confluence connector, so --confluence URLs on secfoo run actually resolve to real page content instead of just a link the agent can't follow.
Define the server once
secfoo config init # writes a starter ~/.secfoo/config.toml if you don't have one
[[mcp_servers]]
name = "Atlassian-Rovo-MCP"
command = "npx"
args = ["-y", "mcp-remote", "https://mcp.atlassian.com/v1/sse"]
Or a remote server reached directly over HTTP/SSE, with an auth header:
[[mcp_servers]]
name = "internal-docs"
url = "https://mcp.internal.example.com/sse"
transport = "sse"
[mcp_servers.headers]
Authorization = "Bearer ${INTERNAL_MCP_TOKEN}"
Every field, including the full stdio-vs-sse/http shape, is in the Configuration reference.
Wiring it into your agent CLI
How a defined server actually reaches the agent depends on which one you're using — this is the part that's easy to miss, since it isn't the same for every agent:
secfoo run, scoped to that invocation only (via --mcp-config) — your global Claude config is never touched.secfoo mcp sync --agent <id> once to register persistently in that tool's own config file. Re-run it after adding new servers to config.toml — already-registered ones are left alone, not duplicated.secfoo mcp sync --agent gemini
secfoo mcp sync --agent agent # Cursor's agent id is "agent", not "cursor"
Checking what's configured
secfoo mcp list
Lists every server defined in config.toml by name, with its transport and target (command or URL) — useful for confirming a typo'd server name before you reference it, and for seeing at a glance what secfoo mcp sync will register.
Using it in a run
Once a Confluence-capable server is configured (and synced, for gemini/agent), point a run at real pages:
secfoo run --skill security-architecture-review --agent claude \
--confluence https://yourteam.atlassian.net/wiki/spaces/ENG/pages/12345/Architecture
Without a working MCP connection, secfoo still passes the URL through to the agent — it just can't fetch the actual page content, so treat that as a signal the server isn't wired up for the agent you're using yet.
See secfoo mcp in the CLI reference.