Official agent skill

MCPB Local MCP Server Packaging

by anthropics in anthropics/claude-plugins-official

Bundles a local MCP server together with its runtime into one installable file, so a user doesn't need Node or Python set up themselves.

OfficialApache-2.0Auto-check passedAgent Workflows

Install MCPB Local MCP Server Packaging

skills CLI
$ npx skills add anthropics/claude-plugins-official --skill build-mcpb -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install anthropics/claude-plugins-official build-mcpb --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/anthropics/claude-plugins-official.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/mcp-server-dev/skills/build-mcpb .claude/skills/build-mcpb && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
build-mcpb
GitHub stars
38k
Token cost
~1.9k tokens
SKILL.md length
549 words
Files
3 (incl. references)
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Bundles a local MCP server together with its runtime into one installable file, so a user doesn't need Node or Python set up themselves.

  • Packaging an MCP server that needs to run on the user's own machine
  • SKILL.md covers What an MCPB bundle contains, Manifest, Server code: same as local stdio and Build pipeline, plus 4 more sections
  • Calls npx, npm and pip; reaches raw.githubusercontent.com
  • Distributing a local MCP server to someone without Node or Python installed

What it does

This skill applies to packaging an MCP server that must run on the user's own machine — reading local files, driving a desktop app, or talking to localhost services — rather than one that only calls cloud APIs, which it suggests building as a remote HTTP server instead since this packaging format is described as the secondary distribution path. A bundle is a zip archive containing a manifest with identity, entry point, and configuration schema, next to the actual server code.

The manifest's launch field is the literal command, arguments, and environment used to start the server as a stdio process, using placeholders for bundle-relative paths and for install-time settings such as a folder picker or a value stored in the OS keychain. From the server code's own point of view, it behaves exactly like any local stdio MCP server — nothing in the tool logic itself is specific to this packaging.

When your agent uses it

  • Packaging an MCP server that needs to run on the user's own machine
  • Distributing a local MCP server to someone without Node or Python installed
  • Bundling an MCP server that reads local files or controls a desktop app

Example prompts

  • “Package this filesystem MCP server as an installable bundle.”
  • “Set up a manifest for an MCP server that needs a folder picker at install time.”
  • “Bundle my local MCP server so it runs without needing Node installed.”

What it can do on your machine

Read from SKILL.md and the folder at commit b8e53f1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • npm
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • raw.githubusercontent.com

    Also links to:

    • claude.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

MCPB Local MCP Server Packaging loads about 1.9k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 549 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from anthropics/claude-plugins-official at commit b8e53f1, republished under its Apache-2.0 licence (© anthropics). 549 words, ~1,949 tokens.

Download SKILL.mdSave it as .claude/skills/build-mcpb/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
build-mcpb
description
This skill should be used when the user wants to "package an MCP server", "bundle an MCP", "make an MCPB", "ship a local MCP server", "distribute a local MCP", discusses ".mcpb files", mentions bundling a Node or Python runtime with their MCP server, or needs an MCP server that interacts with the local filesystem, desktop apps, or OS and must be installable without the user having Node/Python set up.
version
0.1.0

Build an MCPB (Bundled Local MCP Server)

MCPB is a local MCP server packaged with its runtime. The user installs one file; it runs without needing Node, Python, or any toolchain on their machine. It's the sanctioned way to distribute local MCP servers.

MCPB is the secondary distribution path. Anthropic recommends remote MCP servers for directory listing — see https://claude.com/docs/connectors/building/what-to-build.

Use MCPB when the server must run on the user's machine — reading local files, driving a desktop app, talking to localhost services, OS-level APIs. If your server only hits cloud APIs, you almost certainly want a remote HTTP server instead (see build-mcp-server). Don't pay the MCPB packaging tax for something that could be a URL.


What an MCPB bundle contains

my-server.mcpb              (zip archive)
├── manifest.json           ← identity, entry point, config schema, compatibility
├── server/                 ← your MCP server code
│   ├── index.js
│   └── node_modules/       ← bundled dependencies (or vendored)
└── icon.png

The host reads manifest.json, launches server.mcp_config.command as a stdio MCP server, and pipes messages. From your code's perspective it's identical to a local stdio server — the only difference is packaging.


Manifest

json
{
  "$schema": "https://raw.githubusercontent.com/anthropics/mcpb/main/schemas/mcpb-manifest-v0.4.schema.json",
  "manifest_version": "0.4",
  "name": "local-files",
  "version": "0.1.0",
  "description": "Read, search, and watch files on the local filesystem.",
  "author": { "name": "Your Name" },
  "server": {
    "type": "node",
    "entry_point": "server/index.js",
    "mcp_config": {
      "command": "node",
      "args": ["${__dirname}/server/index.js"],
      "env": {
        "ROOT_DIR": "${user_config.rootDir}"
      }
    }
  },
  "user_config": {
    "rootDir": {
      "type": "directory",
      "title": "Root directory",
      "description": "Directory to expose. Defaults to ~/Documents.",
      "default": "${HOME}/Documents",
      "required": true
    }
  },
  "compatibility": {
    "claude_desktop": ">=1.0.0",
    "platforms": ["darwin", "win32", "linux"]
  }
}

server.type — node, python, or binary. Informational; the actual launch comes from mcp_config.

server.mcp_config — the literal command/args/env to spawn. Use ${__dirname} for bundle-relative paths and ${user_config.<key>} to substitute install-time config. There's no auto-prefix — the env var names your server reads are exactly what you put in env.

user_config — install-time settings surfaced in the host's UI. type: "directory" renders a native folder picker. sensitive: true stores in OS keychain. See references/manifest-schema.md for all fields.


Server code: same as local stdio

The server itself is a standard stdio MCP server. Nothing MCPB-specific in the tool logic.

typescript
import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
import { StdioServerTransport } from "@modelcontextprotocol/sdk/server/stdio.js";
import { z } from "zod";
import { readFile, readdir } from "node:fs/promises";
import { join } from "node:path";
import { homedir } from "node:os";

// ROOT_DIR comes from what you put in manifest's server.mcp_config.env — no auto-prefix
const ROOT = (process.env.ROOT_DIR ?? join(homedir(), "Documents"));

const server = new McpServer({ name: "local-files", version: "0.1.0" });

server.registerTool(
  "list_files",
  {
    description: "List files in a directory under the configured root.",
    inputSchema: { path: z.string().default(".") },
    annotations: { readOnlyHint: true },
  },
  async ({ path }) => {
    const entries = await readdir(join(ROOT, path), { withFileTypes: true });
    const list = entries.map(e => ({ name: e.name, dir: e.isDirectory() }));
    return { content: [{ type: "text", text: JSON.stringify(list, null, 2) }] };
  },
);

server.registerTool(
  "read_file",
  {
    description: "Read a file's contents. Path is relative to the configured root.",
    inputSchema: { path: z.string() },
    annotations: { readOnlyHint: true },
  },
  async ({ path }) => {
    const text = await readFile(join(ROOT, path), "utf8");
    return { content: [{ type: "text", text }] };
  },
);

const transport = new StdioServerTransport();
await server.connect(transport);

Sandboxing is entirely your job. There is no manifest-level sandbox — the process runs with full user privileges. Validate paths, refuse to escape ROOT, allowlist spawns. See references/local-security.md.

Before hardcoding ROOT from a config env var, check if the host supports roots/list — the spec-native way to get user-approved directories. See references/local-security.md for the pattern.


Build pipeline

Node
bash
npm install
npx esbuild src/index.ts --bundle --platform=node --outfile=server/index.js
# or: copy node_modules wholesale if native deps resist bundling
npx @anthropic-ai/mcpb pack

mcpb pack zips the directory and validates manifest.json against the schema.

Python
bash
pip install -t server/vendor -r requirements.txt
npx @anthropic-ai/mcpb pack

Vendor dependencies into a subdirectory and prepend it to sys.path in your entry script. Native extensions (numpy, etc.) must be built for each target platform — avoid native deps if you can.


Show full SKILL.md (207 more words)Show less

MCPB has no sandbox — security is on you

Unlike mobile app stores, MCPB does NOT enforce permissions. The manifest has no permissions block — the server runs with full user privileges. references/local-security.md is mandatory reading, not optional. Every path must be validated, every spawn must be allowlisted, because nothing stops you at the platform level.

If you came here expecting filesystem/network scoping from the manifest: it doesn't exist. Build it yourself in tool handlers.

If your server's only job is hitting a cloud API, stop — that's a remote server wearing an MCPB costume. The user gains nothing from running it locally, and you're taking on local-security burden for no reason.


MCPB + UI widgets

MCPB servers can serve UI resources exactly like remote MCP apps — the widget mechanism is transport-agnostic. A local file picker that browses the actual disk, a dialog that controls a native app, etc.

Widget authoring is covered in the build-mcp-app skill; it works the same here. The only difference is where the server runs.


Testing

bash
# Interactive manifest creation (first time)
npx @anthropic-ai/mcpb init

# Run the server directly over stdio, poke it with the inspector
npx @modelcontextprotocol/inspector node server/index.js

# Validate manifest against schema, then pack
npx @anthropic-ai/mcpb validate
npx @anthropic-ai/mcpb pack

# Sign for distribution
npx @anthropic-ai/mcpb sign dist/local-files.mcpb

# Install: drag the .mcpb file onto Claude Desktop

Test on a machine without your dev toolchain before shipping. "Works on my machine" failures in MCPB almost always trace to a dependency that wasn't actually bundled.


Reference files

  • references/manifest-schema.md — full manifest.json field reference
  • references/local-security.md — path traversal, sandboxing, least privilege

© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/mcp-server-dev/skills/build-mcpb of anthropics/claude-plugins-official.

  • SKILL.md
  • references/local-security.md
  • references/manifest-schema.md

Open the folder on GitHubat commit b8e53f1

Compare with similar skills

MCPB Local MCP Server Packaging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

MCPB Local MCP Server Packaging compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
MCPB Local MCP Server Packaging this skillanthropics/claude-plugins-official38k—~1.9kAutomated safety check: PassApache-2.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Context Mode Output Sandboxmksglu/context-mode26k—~4.1kAutomated safety check: PassCustom licence
Warp GUI to Agent CLI Migrationwarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    Agent WorkflowsAuto-check passed
  • Installs and configures MemPalace as a private local palace, a shared-brain hub or a client of an existing hub, including MCP registration and version-correct initialization.

    59k GitHub stars~2.2k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from anthropics/claude-plugins-official

All 29 skills in this repo
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 10 repos~4.1k tokens
    Auto-check: notes
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 7 repos~2.8k tokens
    Auto-check passed
  • Plugin Settings Pattern

    anthropics/claude-plugins-official

    Official

    Shows how Claude Code plugins keep per-project settings and state in .claude/plugin-name.local.md files with YAML frontmatter and a markdown body.

    38k GitHub starsUsed in 7 repos~3k tokens
    Auto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Auto-check passed
  • Claude Code Command Development

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code slash commands: Markdown files with YAML frontmatter, arguments, file references, bash context and interactive prompts.

    38k GitHub starsUsed in 10 repos~4.8k tokens
    Auto-check passed
  • Claude Code Plugin Structure

    anthropics/claude-plugins-official

    Official

    Explains the directory layout, plugin.json manifest and component organization of a Claude Code plugin, including auto-discovery and portable paths.

    38k GitHub starsUsed in 10 repos~3.4k tokens
    Auto-check passed

Categories

Questions about MCPB Local MCP Server Packaging

What does MCPB Local MCP Server Packaging do?

Bundles a local MCP server together with its runtime into one installable file, so a user doesn't need Node or Python set up themselves. This skill applies to packaging an MCP server that must run on the user's own machine — reading local files, driving a desktop app, or talking to localhost services — rather than one that only calls cloud APIs, which it suggests building as a remote HTTP server instead since this packaging format is described as the secondary distribution path. A bundle is a zip archive containing a manifest with identity, entry point, and configuration schema, next to the actual server code.

When should I use MCPB Local MCP Server Packaging?

MCPB Local MCP Server Packaging fits situations like: packaging an MCP server that needs to run on the user's own machine; distributing a local MCP server to someone without Node or Python installed; bundling an MCP server that reads local files or controls a desktop app.

How do I install MCPB Local MCP Server Packaging in Claude Code?

Run `npx skills add anthropics/claude-plugins-official --skill build-mcpb -a claude-code`. Or copy the skill folder (plugins/mcp-server-dev/skills/build-mcpb in anthropics/claude-plugins-official) into .claude/skills/build-mcpb in your project. Claude Code loads it when a task matches its description.

How do I install MCPB Local MCP Server Packaging in Codex?

Run `npx skills add anthropics/claude-plugins-official --skill build-mcpb -a codex`. Or copy the skill folder (plugins/mcp-server-dev/skills/build-mcpb in anthropics/claude-plugins-official) into .agents/skills/build-mcpb in your project. Codex loads it when a task matches its description.

Can I use MCPB Local MCP Server Packaging in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-plugins-official --skill build-mcpb -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/build-mcpb, .gemini/skills/build-mcpb, .github/skills/build-mcpb and .opencode/skills/build-mcpb in your project.

What does MCPB Local MCP Server Packaging need to run?

Going by SKILL.md and its folder, MCPB Local MCP Server Packaging needs the command-line tools its instructions call (npx, npm and pip).

Does MCPB Local MCP Server Packaging access the network?

SKILL.md names 2 domains. In commands or code: raw.githubusercontent.com; the agent is likely to contact it when it follows the instructions. As links in the text: claude.com. This is read from the text; nothing was executed.

Is MCPB Local MCP Server Packaging safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does MCPB Local MCP Server Packaging use?

MCPB Local MCP Server Packaging is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does MCPB Local MCP Server Packaging use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to MCPB Local MCP Server Packaging?

Skills that share tags, products or a category with MCPB Local MCP Server Packaging: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), Crush Configuration (charmbracelet/crush, 29k stars) and Context Mode Output Sandbox (mksglu/context-mode, 26k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains MCPB Local MCP Server Packaging?

anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-plugins-official, which has 37,597 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 9, 2026.

Source: anthropics/claude-plugins-official on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.