Skip to content
Back to skills

Mcp Server

ASecurity

Scaffold an MCP server that exposes tools over stdio or HTTP for an LLM agent to call

  • 3 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 3, 2026
ai-agentspythongoapisecurity

Works with

  • cli
  • api
  • mcp

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill mcp-server --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Mcp Server?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Mcp Server
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-mcp-server/badge)](https://www.skillsdirectory.com/skills/black141312-mcp-server)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: mcp-server
description: Scaffold an MCP server that exposes tools over stdio or HTTP for an LLM agent to call
category: agent-llm
---

# MCP Server

Reach for this when you need to expose local capabilities (files, APIs, DB queries) to an agent via the Model Context Protocol instead of hand-rolling a custom integration.

1. Pick a transport: stdio for local/CLI use (the default, simplest), or HTTP/SSE for a remote or multi-client server.
2. Init the project and add the MCP SDK (`@modelcontextprotocol/sdk` for TS, `mcp` for Python); create a server with a name and version.
3. Register each tool with a unique name, a one-line description, and a JSON-Schema (or zod/pydantic) input schema — keep inputs flat and typed.
4. Implement each tool handler to do the work, then return content as a list of typed parts (text/json); never return raw exceptions.
5. Wire the transport and start the loop (stdio: read/write over stdin/stdout; HTTP: bind a port and mount the session handler).
6. Register the server in the client config (command + args for stdio, URL for HTTP) and smoke-test that tools list and a sample call both succeed.

## Rules
- For stdio, NEVER write logs or prints to stdout — it corrupts the protocol stream; log to stderr or a file.
- Tool names must be stable and unique; renaming one breaks any agent that hardcoded it.
- Validate and sanitize every input inside the handler; schema validation is a hint, not a security boundary.
- Return structured errors (a result with `isError: true` and a message) so the agent can recover, rather than throwing.
- Keep each tool single-purpose and side-effect-explicit; mark destructive tools clearly in the description.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…