What one command wires
Wire Amp to Vulnetix. Skills install to ~/.config/agents/skills and the MCP server supplies live vulnerability intelligence.
vulnetix agent install --agent amp
- Agent Skills: supported —
~/.config/agents/skills - Dependency guard: not wired by the installer —
hook contract not yet verified - MCP server: supported —
https://mcp.vulnetix.com/mcp
Where Amp reads skills
Agent Skills is an open standard, but hosts disagree about the directory. The installer writes the one Amp actually opens.
- Everywhere, for you:
~/.config/agents/skills - This repository:
.agents/skills
Add the MCP server
{
"mcpServers": {
"vulnetix": {
"url": "https://mcp.vulnetix.com/mcp",
"headers": { "Authorization": "ApiKey <orgId>:<key>" }
}
}
}
The ordinary case: nothing is wrong
Across 33 everyday commands the guard produced no output at all. Silence when the policy is satisfied is what makes a guard liveable; one that comments on every install gets switched off.
$
npm install
(no output — a lockfile install adds nothing new)
$
npm i left-pad
(no output — clean package, nothing to say)
$
git commit -m "add http client"
(no output)
19 ms per tool call. 0 of 33 everyday commands
produced a single line.