Vscode MCP Tool Development
tjx666/vscode-mcp
End-to-end workflow for adding, modifying, or debugging VSCode MCP tools in this repo — IPC zod schema and EventMap, bridge service registration, core ToolDefinition and tool constants, MCP/CLI…
Upgrade @modelcontextprotocol/server (the MCP TypeScript SDK v2) and prove the wire contract survived.
$ npx skills add awdr74100/figwright --skill mcp-sdk-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install awdr74100/figwright mcp-sdk-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/awdr74100/figwright.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/mcp-sdk-audit .claude/skills/mcp-sdk-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "mcp-sdk-audit" agent skill from https://github.com/awdr74100/figwright/tree/main/.claude/skills/mcp-sdk-audit into .claude/skills/mcp-sdk-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-sdk-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/awdr74100/figwright/tree/main/.claude/skills/mcp-sdk-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add awdr74100/figwright --skill mcp-sdk-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install awdr74100/figwright mcp-sdk-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awdr74100/figwright.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/mcp-sdk-audit .agents/skills/mcp-sdk-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "mcp-sdk-audit" agent skill from https://github.com/awdr74100/figwright/tree/main/.claude/skills/mcp-sdk-audit into .agents/skills/mcp-sdk-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-sdk-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awdr74100/figwright --skill mcp-sdk-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install awdr74100/figwright mcp-sdk-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awdr74100/figwright.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/mcp-sdk-audit .cursor/skills/mcp-sdk-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "mcp-sdk-audit" agent skill from https://github.com/awdr74100/figwright/tree/main/.claude/skills/mcp-sdk-audit into .cursor/skills/mcp-sdk-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-sdk-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/awdr74100/figwright.git --path .claude/skills/mcp-sdk-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add awdr74100/figwright --skill mcp-sdk-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install awdr74100/figwright mcp-sdk-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awdr74100/figwright.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/mcp-sdk-audit .gemini/skills/mcp-sdk-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "mcp-sdk-audit" agent skill from https://github.com/awdr74100/figwright/tree/main/.claude/skills/mcp-sdk-audit into .gemini/skills/mcp-sdk-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-sdk-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install awdr74100/figwright mcp-sdk-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add awdr74100/figwright --skill mcp-sdk-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/awdr74100/figwright.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/mcp-sdk-audit .github/skills/mcp-sdk-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "mcp-sdk-audit" agent skill from https://github.com/awdr74100/figwright/tree/main/.claude/skills/mcp-sdk-audit into .github/skills/mcp-sdk-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-sdk-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awdr74100/figwright --skill mcp-sdk-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install awdr74100/figwright mcp-sdk-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awdr74100/figwright.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/mcp-sdk-audit .opencode/skills/mcp-sdk-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "mcp-sdk-audit" agent skill from https://github.com/awdr74100/figwright/tree/main/.claude/skills/mcp-sdk-audit into .opencode/skills/mcp-sdk-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-sdk-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
mcp-sdk-auditUpgrade @modelcontextprotocol/server (the MCP TypeScript SDK v2) and prove the wire contract survived.
MCP SDK Audit is an agent skill from awdr74100/figwright. Upgrade @modelcontextprotocol/server (the MCP TypeScript SDK v2) and prove the wire contract survived. The SDK is a runtime dependency whose breakage lands on the wire, not in the type checker — so this sorts each release by which SDK source files it touched (Figwright uses only the server + stdio slice of a client/server/multi-runtime package family), then diffs what a real MCP client observes — negotiated protocol version, every tool JSON Schema, annotations, prompts — before and after the bump. Use whenever…
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol, TypeScript, Figma and Zod. The repository describes itself as: Free, two-way Figma MCP server. Turn designs into framework-aware code, and push code back to the canvas. Works with Claude Code, Cursor, Codex, and any MCP client. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c00638b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
pnpmghnodenpmgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm, gh, npm and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
MCP SDK Audit loads about 4.1k tokens when it runs. Until then it costs about 189 tokens; SKILL.md has 1,773 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from awdr74100/figwright at commit c00638b, republished under its MIT licence (© awdr74100). 1,773 words, ~4,124 tokens.
.claude/skills/mcp-sdk-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Absorbing a @modelcontextprotocol/server release into Figwright, end to end: audit → upgrade → prove
the wire contract is unchanged.
Do not reason about this the way figma-typings-audit reasons about plugin typings. That package
is types-only, so tsc is a real gate. This one is a runtime dependency: it serializes every
tool result, generates the JSON Schema for every tool, and negotiates the protocol version. A
release can leave every type identical and still change what clients see. pnpm typecheck will stay
green through it.
Unlike every other dependency here, this one has a dedicated gate — use it.
packages/mcp/test/e2e/mcp-wire.test.ts spawns the built dist over real stdio, speaks raw
JSON-RPC at it, and asserts the advertised contract against what the specs declare. It runs in
pnpm test. That gate answers did anything break; it does not answer what moved, which is what
an audit is for — Stage 5 covers the difference.
Know the one thing that gate cannot see. Its schema check compares the SDK's output against
test/tool-schema.ts's derivation, and both call the same z.toJSONSchema. That is independent of
the SDK — it catches an SDK that stops asking Zod the same question — but not of Zod: when Zod
changes what it answers, both sides move together and the equality still holds. An SDK bump that
also moves the resolved zod version (its range is ^4.2.0, so it shares the repo's copy) can
therefore reshape every client's schema with this gate green.
packages/mcp/test/json-schema-generation.test.ts covers that half by pinning each construct's
rendering by hand — if a bump moves the Zod version, read its diff too, and let probe.mjs name
which tools changed.
Target version: whatever the user named, otherwise the latest @modelcontextprotocol/server on npm.
grep '@modelcontextprotocol' packages/mcp/package.json # declared range
grep -m1 '@modelcontextprotocol/server@' pnpm-lock.yaml # what is installed
npm view @modelcontextprotocol/server version dist-tags --json # latest
gh api repos/modelcontextprotocol/typescript-sdk/releases --jq '.[0:15][] | "\(.tag_name)\t\(.published_at)"'Figwright is on v2 — the package family (@modelcontextprotocol/server + its transitive
/core, with /client, /node, /express, /hono, /fastify, /server-legacy, /codemod
alongside). It depends on exactly one of them.
Two things the releases list will show that are not upgrades for us:
1.30.0-style tags are the v1 legacy line (@modelcontextprotocol/sdk, source on the
long-lived v1.x branch). Figwright left it; a v1 tag is not our concern.@modelcontextprotocol/{client,express,fastify,hono,node,server-legacy,codemod}@X tags ship on
the same version number as server but are packages we do not install.If installed and target are equal, say so and stop.
The GitHub Releases body is an auto-generated list of PR titles, written for SDK contributors: it says what was changed, never who is affected. "stdio buffer limit" reads like it belongs to whoever runs stdio; the useful question is which package and which directory it landed in.
So use the notes only to get the PR numbers, then ask each PR what it touched:
gh api repos/modelcontextprotocol/typescript-sdk/releases --jq '.[] | select(.tag_name=="@modelcontextprotocol/server@<target>") | .body'
# then, per PR number in that body:
gh pr view <n> --repo modelcontextprotocol/typescript-sdk --json title,files \
--jq '"\(.title)\n " + (.files | map(.path) | join("\n "))'⚠️ Read the whole file list, never just the first entry. v2 splits one concern across packages
by design — a wire change routinely lands in packages/core-internal/src/wire/,
packages/server/src/server/, and packages/client/src/ at once. Judging a PR by its first file
is how the hunk that mattered gets missed.
Figwright imports exactly two entry points (packages/mcp/src/index.ts, src/prompts/*,
test/tool-schema.ts, test/e2e/mcp-wire.test.ts): @modelcontextprotocol/server and
@modelcontextprotocol/server/stdio. That narrow slice is what makes this audit cheap — most of any
given release is about parts of the family this server never loads.
| SDK path | Bearing on Figwright |
|---|---|
packages/server/src/server/mcp.ts, server.ts | Load-bearing. registerTool / registerPrompt / result serialization |
packages/server/src/server/serveStdio.ts, stdio.ts | Load-bearing. The entry point and the only transport this server runs |
packages/server/src/fromJsonSchema.ts, validators/ | Load-bearing and invisible. Turns each spec's Zod object into the JSON Schema every client reads |
packages/core-internal/src/wire/, types/ | Load-bearing. Protocol version constants, per-era codecs, CallToolResult, ToolAnnotations |
packages/core/src/ | Schema constants + types. We import types only through server's re-export; watch renames |
packages/client/** | Not ours — but it is what Claude Code / Cursor run against us, so a client-side limit still bites |
packages/server/src/server/streamableHttp.ts, perRequestTransport.ts, createMcpHandler.ts | Unused today (stdio only). Relevant only to a future HTTP transport — note, don't act |
packages/{express,fastify,hono,node,server-legacy}/**, **/auth/**, examples/** | Ignore |
The packages/client/** row is the subtle one: a limit added to the client's read path applies to
Figwright's responses, since the client is what reads them. get_screenshot returns inline
base64 and get_design_context returns large JSON, so client-side ceilings are a real exposure even
though Figwright ships no client.
The PR list is a claim about the release; the tarball is the release. Confirm they agree — and catch anything that reached the build without a listed PR:
cd "$SCRATCH" && mkdir -p mcp-sdk-audit && cd mcp-sdk-audit
npm pack @modelcontextprotocol/server@<installed> @modelcontextprotocol/server@<target> \
@modelcontextprotocol/core@<installed> @modelcontextprotocol/core@<target> \
--pack-destination .
for p in server core; do for v in <installed> <target>; do
mkdir -p "$p-$v" && tar -xzf "modelcontextprotocol-$p-$v.tgz" -C "$p-$v" --strip-components=1
done; done
# Partition each tree by CONTENT, not by filename. This one step produces both the
# coverage proof and the list of files that actually have to be read. Do it for core
# too — its chunks are content-hashed the same way.
for p in server core; do for v in <installed> <target>; do
(cd "$p-$v/dist" && find . -type f ! -name '*.map' -exec shasum -a 256 {} \; \
| sort -k2 > "../../hash-$p-$v.txt")
done; done
for p in server core; do
echo "== $p =="
comm -12 <(sort "hash-$p-<installed>.txt") <(sort "hash-$p-<target>.txt") | wc -l # identical — the proof
comm -3 <(sort "hash-$p-<installed>.txt") <(sort "hash-$p-<target>.txt") \
| awk '{print $NF}' | sort -u # changed — the read list
done🔴 Do not stop at diff -ru, and do not trust its file list — the gap it leaves is silent. v2
emits .mjs/.cjs siblings in a flat dist/ with content-hashed chunk names, so a chunk whose
hash moved (mcp-DXXb3Vv3.mjs → mcp-Dw2OlZ1f.mjs) appears only as two Only in ... lines and
its contents are never compared — while ReadBuffer, Protocol and registerTool all live in
those chunks, not in stdio.mjs. The hash partition is what makes the read list complete: pair each
changed chunk with its counterpart and diff it by name, explicitly.
diff -u server-<installed>/dist/<old-chunk>.mjs server-<target>/dist/<new-chunk>.mjsThe identical set is a real result, not bookkeeping: a release where ajvProvider-*, dialects-*,
validators/ and types-*.d.mts all hash identically has not touched JSON Schema generation by a
single byte. That is a static statement, so it is stronger than anything the probe can say.
⚠️ Two rename artifacts that read as false alarms:
- lines in index.mjs can be a whole region relocated into another chunk — the
2.1.0 release moved bearerAuth and oauthMetadata into the mcp chunk, which looks exactly like
deleting them until you find the matching + on the other side. Check before calling it a removal..cjs and .d.cts entries are siblings of the .mjs / .d.mts you already read; read one of each
pair, not both.Within what is left, dist/**/*.d.mts hunks are the type-level surface (what tsc would catch);
.mjs hunks with no .d.mts counterpart are the dangerous kind — behavior changed, signature
didn't. Comparing the two versions' export { … } lists (names only, aliases stripped) settles
whether the public surface lost anything, which the prose of a release note routinely omits.
Also diff package.json between the two versions: engines.node, dependencies (the pinned
@modelcontextprotocol/core version and zod's supported range) all move without appearing in the
source diff. v2 declares zod as a real dependency, not a peer — a range bump there can nest a
second zod copy beside the repo's own.
dist/**/*.d.mts that Figwright names. tsc covers these;
confirm in Stage 6 rather than reasoning about them.LATEST_PROTOCOL_VERSION, SUPPORTED_PROTOCOL_VERSIONS,
FIRST_MODERN_PROTOCOL_VERSION) — moving it changes what every connecting client sees, and
dropping an old entry can cut off an older client outright;$ref/allOf/additionalProperties shift has broken third-party clients
before (see project_moonshot_ref_immunity);serveStdio — which revision a given opening exchange lands on;engines.node vs the repo's ^20.19.0 || >=22.12.0, the zod
range against zod@^4, transitive advisories. Note what pnpm install flags.Bucket 2 is the whole reason this skill exists. Never claim a bucket-2 item is safe from the diff alone — Stage 5 settles it.
Two different questions, two tools. Run both.
The gate — did anything break?
pnpm build && pnpm vitest run packages/mcp/test/e2e/mcp-wire.test.tsIt asserts the advertised tool set, each tool's JSON Schema against a derivation that is independent
of the SDK (but not of Zod — see above), the dialect, annotations, prompts, a live tools/call, the
bad-argument path, and that a 2024-11-05 client is still served. Red here means the release moved
something that matters. If the bump also moved zod, run
pnpm vitest run packages/mcp/test/json-schema-generation.test.ts as a second gate.
The probe — what moved? A gate is a boolean; an audit has to name the change. probe.mjs boots
the same built server, snapshots everything a client can observe, and diffs two snapshots.
REPO=$(git rev-parse --show-toplevel)
pnpm build # the probe reads dist, not src
node "$REPO/.claude/skills/mcp-sdk-audit/probe.mjs" "$REPO" "$SCRATCH/mcp-sdk-audit/base.json"
# ...upgrade (Stage 6), pnpm build again, then:
node "$REPO/.claude/skills/mcp-sdk-audit/probe.mjs" "$REPO" "$SCRATCH/mcp-sdk-audit/after.json"
node "$REPO/.claude/skills/mcp-sdk-audit/probe.mjs" --diff "$SCRATCH/mcp-sdk-audit/base.json" "$SCRATCH/mcp-sdk-audit/after.json"Notes that matter:
pnpm build first, every time. The MCP server runs the built dist; probing a stale bundle
reports the previous SDK. (A stale dist left behind by an abandoned upgrade is also
unrunnable — it imports a package the current node_modules no longer has.)FIGWRIGHT_PORT, so neither
contends for 3055 or steals a connected plugin. Neither needs a plugin — ping answers without
one.main in a git worktree, pnpm install, build, probe, then come
back. probe.mjs reads the installed version out of the lockfile, so a v1 baseline needs that one
regex pointed at @modelcontextprotocol/sdk@.pnpm -C packages/mcp add @modelcontextprotocol/server@^<target>
pnpm typecheck && pnpm lint && pnpm format:check && pnpm knip && pnpm build && pnpm testThis and the lockfile are the only writes to the repo; everything before was read-only. All six gates green and an empty probe diff is the pass condition — neither alone is one, though the six now include the wire gate, which is what made them worth trusting.
Ordered by consequence:
Report only what the diff and the probe showed. Don't pad with plausible-sounding changes, and never claim a verification you didn't run.
Then AskUserQuestion over the items from 3 and 4 that would need work.
The gate and the probe prove the server speaks correctly to a test harness. They do not prove real clients are happy:
dist → pnpm build, then the user reconnects the MCP connection
(.mcp.json launches packages/mcp/dist/index.mjs).ping, then something with a real payload like
get_design_context) through the reconnected server with the plugin open.Say what was actually run. If the live step didn't happen, say that.
© awdr74100, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .claude/skills/mcp-sdk-audit of awdr74100/figwright.
Open the folder on GitHubat commit c00638b
MCP SDK Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| MCP SDK Audit this skillawdr74100/figwright | 1k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Vscode MCP Tool Developmenttjx666/vscode-mcp | 105 | — | ~1.5k | Automated safety check: Pass | Custom licence | |
| MCP Server Patternsaffaan-m/ECC | 276k | 5 repos | ~1k | Automated safety check: Pass | MIT | |
| MCP DeveloperJeffallan/claude-skills | 12k | — | ~1.5k | Automated safety check: Pass | MIT | |
| MCP Server Patternsaffaan-m/ECC | 276k | 1 repos | ~551 | Automated safety check: Pass | MIT | |
| Typescript MCP Server Generatorgithub/awesome-copilot | 40k | — | ~1.7k | Automated safety check: Pass | MIT |
tjx666/vscode-mcp
End-to-end workflow for adding, modifying, or debugging VSCode MCP tools in this repo — IPC zod schema and EventMap, bridge service registration, core ToolDefinition and tool constants, MCP/CLI…
affaan-m/ECC
Build MCP servers with Node/TypeScript SDK — tools, resources, prompts, Zod validation, stdio vs Streamable HTTP.
Jeffallan/claude-skills
Builds and debugs MCP servers and clients in TypeScript or Python, from tool and resource definitions to transport setup and inspector-based protocol checks.
affaan-m/ECC
使用Node/TypeScript SDK构建MCP服务器——工具、资源、提示、Zod验证、stdio与可流式HTTP对比。使用Context7或官方MCP文档获取最新API信息。
github/awesome-copilot
Generate a complete MCP server project in TypeScript using the MCP TypeScript SDK v2 (@modelcontextprotocol/server) with tools, resources, and proper configuration
lassejlv/loora
Build, edit, refine, troubleshoot, and review polished responsive product interfaces through the Loora MCP server and its structured Canvas schemas.
awdr74100/figwright
Upgrade @figma/plugin-typings and absorb what the new version exposes.
awdr74100/figwright
Build a Figma design from code or a description — the reverse of figma-codegen.
awdr74100/figwright
Generate framework-aware code from a Figma design. An agent skill from awdr74100/figwright.
Works with
Categories
Upgrade @modelcontextprotocol/server (the MCP TypeScript SDK v2) and prove the wire contract survived. MCP SDK Audit is an agent skill from awdr74100/figwright. Upgrade @modelcontextprotocol/server (the MCP TypeScript SDK v2) and prove the wire contract survived.
MCP SDK Audit fits situations like: the user wants @modelcontextprotocol/server; the other @modelcontextprotocol/ packages updated; asks what a new SDK version changes for the server; lands on a Renovate bump PR for that package.
Run `npx skills add awdr74100/figwright --skill mcp-sdk-audit -a claude-code`. Or copy the skill folder (.claude/skills/mcp-sdk-audit in awdr74100/figwright) into .claude/skills/mcp-sdk-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add awdr74100/figwright --skill mcp-sdk-audit -a codex`. Or copy the skill folder (.claude/skills/mcp-sdk-audit in awdr74100/figwright) into .agents/skills/mcp-sdk-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awdr74100/figwright --skill mcp-sdk-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-sdk-audit, .gemini/skills/mcp-sdk-audit, .github/skills/mcp-sdk-audit and .opencode/skills/mcp-sdk-audit in your project.
Going by SKILL.md and its folder, MCP SDK Audit needs JavaScript for the scripts in its folder and the command-line tools its instructions call (pnpm, gh, node, npm and git). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use gh, npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
MCP SDK Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with MCP SDK Audit: Vscode MCP Tool Development (tjx666/vscode-mcp, 105 stars), MCP Server Patterns (affaan-m/ECC, 276k stars), MCP Developer (Jeffallan/claude-skills, 12k stars) and MCP Server Patterns (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
awdr74100 (a GitHub user) maintains it in awdr74100/figwright, which has 1,003 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.
Source: awdr74100/figwright on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.