Skip to content
Back to skills

Mcp Builder

ASecurity

Design and implement MCP servers—tools, resources, prompts, schemas, and error contracts for agent clients. Use when adding MCP integration or exposing capabilities to Cursor/Claude agents. Triggers: "MCP server", "MCP tool", "Model Context Protocol", "build MCP".

  • 25 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added May 27, 2026
data-aishelltestingsecurity

Works with

  • cursor
  • cli
  • mcp

Security analysis

A100/100

Scanned May 27, 2026

npx -y skills add charlieviettq/awesome-agent-skill --skill mcp-builder --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Mcp Builder?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Mcp Builder
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/charlieviettq-mcp-builder/badge)](https://www.skillsdirectory.com/skills/charlieviettq-mcp-builder)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: mcp-builder
description: >
  Design and implement MCP servers—tools, resources, prompts, schemas, and error
  contracts for agent clients. Use when adding MCP integration or exposing
  capabilities to Cursor/Claude agents.
  Triggers: "MCP server", "MCP tool", "Model Context Protocol", "build MCP".
---

# MCP builder

## Design principles

- **One capability per tool** — clear name, single purpose.
- **Strict schemas** — JSON Schema for inputs; document required vs optional.
- **Predictable errors** — machine-readable codes + human message; no stack traces to client by default.
- **Idempotent reads** — writes clearly labeled; confirm destructive ops in description.

## Server checklist

- [ ] `server` identity and version documented
- [ ] Tool list small and discoverable
- [ ] Input validation before side effects
- [ ] Timeouts and size limits on responses
- [ ] Auth documented (env vars, OAuth, local only)
- [ ] README: install, config, example tool calls

## Tool definition pattern

```json
{
  "name": "search_docs",
  "description": "Search internal docs by query. Read-only.",
  "inputSchema": {
    "type": "object",
    "properties": {
      "query": { "type": "string", "description": "Search terms" },
      "limit": { "type": "integer", "minimum": 1, "maximum": 50 }
    },
    "required": ["query"]
  }
}
```

## Testing

- Unit test handlers with fixture inputs.
- Integration test with MCP client or inspector.
- Verify error paths (invalid args, upstream failure).

## Security

- No broad filesystem or shell unless required and scoped.
- Sanitize paths; block path traversal.
- Do not return secrets in tool results.

## Related

Use `agent-tool-contracts` for cross-platform tool design beyond MCP.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…