Skip to content
Back to skills

Create Mcp Integration

ASecurity

Adds an MCP server integration configuration to an existing plugin. NOT for scaffolding a brand-new plugin (use `create-plugin`) and NOT for Azure hosted agents (use `create-azure-agent`).

  • 7 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 2, 2026
ai-agentspythonbashazureapisecurity

Works with

  • api
  • mcp

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned October 3, 2026

npx -y skills add richfrem/agent-plugins-skills --skill create-mcp-integration --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Create Mcp Integration?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Create Mcp Integration
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/richfrem-create-mcp-integration-agent-plugins-skills/badge)](https://www.skillsdirectory.com/skills/richfrem-create-mcp-integration-agent-plugins-skills)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: create-mcp-integration
plugin: agent-scaffolders
description: >
  Adds an MCP server integration configuration to an existing plugin. NOT for scaffolding a brand-new plugin (use `create-plugin`) and NOT for Azure hosted agents (use `create-azure-agent`).
argument-hint: "[mcp-server-name or service]"
allowed-tools: Bash, Read, Write
---

# Create MCP Integration (create-mcp-integration)

Configures Model Context Protocol (MCP) server integrations within a plugin or workspace `.mcp.json`.

## Contents
- [Critical Constraints](#critical-constraints)
- [Quick start](#quick-start)
- [Workflow](#workflow)
- [Verification](#verification)
- [References](#references)

## Critical Constraints
- **Integration Scope**: Configuration of MCP servers only. For scaffolding new plugins, use `create-plugin`. For hosted cloud agents, use `create-azure-agent`.
- **Encrypted Transports**: Remote server endpoints must use `https://` or `wss://`; unencrypted plain HTTP/WS transports are forbidden.
- **Modern Transport Priority**: Prefer `streamable-http` or `stdio` transports over deprecated SSE implementations.
- **Credential Hygiene**: Store secrets strictly in environment variables; never embed raw API tokens or credentials inside `.mcp.json`.

## Quick start

```bash
python3 plugins/agent-scaffolders/scripts/scaffold.py \
  --type mcp \
  --name postgres-mcp \
  --path plugins/<plugin>
```

## Workflow

1. **Phase 1: Transport & Security Discovery**: Establish server archetype (`stdio`, `streamable-http`, `sse`), endpoint URL or binary command, and authentication mechanism.
2. **Phase 2: Tool Surface Definition**: Select target tool subsets, resource templates, and prompt templates to expose to the agent environment.
3. **Phase 3: Configuration Scaffolding**: Generate the `.mcp.json` server definition block with required environment variable placeholders and arguments.
4. **Phase 4: Schema & Connection Audit**: Validate JSON formatting and test connectivity using the environment MCP inspector.

## Verification

```bash
# Validate JSON formatting
python3 -c "import json; json.load(open('.mcp.json'))"

# Audit skill compliance
python3 plugins/agent-scaffolders/scripts/audit_skill.py plugins/agent-scaffolders/skills/create-mcp-integration --mode source
```

## References
- [fallback-tree.md](references/fallback-tree.md) - Fallback tree for scaffolding failures.
- [references/server-types.md](references/server-types.md) - MCP transport architecture standards.
- [references/authentication.md](references/authentication.md) - Safe credential and authentication patterns.
- [references/tool-usage.md](references/tool-usage.md) - Tool filtering and prompt exposure.
- [acceptance-criteria.md](references/acceptance-criteria.md) - Quality checklist for MCP integrations.

Files in this skill

  • SKILL.md1.4 KB
  • acceptance-criteria.md359 B
  • evals/evals.json881 B
  • evals/results.tsv417 B
  • fallback-tree.md1.4 KB
  • references/acceptance-criteria.md42 B
  • references/authentication.md37 B
  • references/examples/http-server.json48 B
  • references/examples/sse-server.json47 B
  • references/examples/stdio-server.json49 B
  • references/fallback-tree.md36 B
  • references/hitl-interaction-design.md46 B
  • references/pattern-decision-matrix.md46 B
  • references/patterns/action-forcing-output-with-deadline-attribution.md82 B
  • references/patterns/adversarial-objectivity-constraint.md69 B
  • references/patterns/anti-pattern-vaccination.md59 B
  • references/patterns/anti-symptom-triage.md54 B
  • references/patterns/artifact-embedded-execution-audit-trail.md74 B
  • references/patterns/artifact-generation-xss-compliance-gate.md74 B
  • references/patterns/artifact-lifecycle.md53 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…