MCP Server Builder
shareAI-lab/learn-claude-code
Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.
Bumps every @x402/ package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev dependencies used to test the SDK against x402, and the dependencies in every TypeScript x402…
$ npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install coinbase/cdp-sdk bump-x402-dependencies --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/bump-x402-dependencies .claude/skills/bump-x402-dependencies && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "bump-x402-dependencies" agent skill from https://github.com/coinbase/cdp-sdk/tree/main/.cursor/skills/bump-x402-dependencies into .claude/skills/bump-x402-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bump-x402-dependencies", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/coinbase/cdp-sdk/tree/main/.cursor/skills/bump-x402-dependenciesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install coinbase/cdp-sdk bump-x402-dependencies --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.cursor/skills/bump-x402-dependencies .agents/skills/bump-x402-dependencies && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "bump-x402-dependencies" agent skill from https://github.com/coinbase/cdp-sdk/tree/main/.cursor/skills/bump-x402-dependencies into .agents/skills/bump-x402-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bump-x402-dependencies", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install coinbase/cdp-sdk bump-x402-dependencies --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.cursor/skills/bump-x402-dependencies .cursor/skills/bump-x402-dependencies && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "bump-x402-dependencies" agent skill from https://github.com/coinbase/cdp-sdk/tree/main/.cursor/skills/bump-x402-dependencies into .cursor/skills/bump-x402-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bump-x402-dependencies", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/coinbase/cdp-sdk.git --path .cursor/skills/bump-x402-dependencies--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install coinbase/cdp-sdk bump-x402-dependencies --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.cursor/skills/bump-x402-dependencies .gemini/skills/bump-x402-dependencies && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "bump-x402-dependencies" agent skill from https://github.com/coinbase/cdp-sdk/tree/main/.cursor/skills/bump-x402-dependencies into .gemini/skills/bump-x402-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bump-x402-dependencies", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install coinbase/cdp-sdk bump-x402-dependenciesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .github/skills && cp -r skills-src/.cursor/skills/bump-x402-dependencies .github/skills/bump-x402-dependencies && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "bump-x402-dependencies" agent skill from https://github.com/coinbase/cdp-sdk/tree/main/.cursor/skills/bump-x402-dependencies into .github/skills/bump-x402-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bump-x402-dependencies", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install coinbase/cdp-sdk bump-x402-dependencies --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.cursor/skills/bump-x402-dependencies .opencode/skills/bump-x402-dependencies && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "bump-x402-dependencies" agent skill from https://github.com/coinbase/cdp-sdk/tree/main/.cursor/skills/bump-x402-dependencies into .opencode/skills/bump-x402-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bump-x402-dependencies", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
bump-x402-dependenciesBumps every @x402/ package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev dependencies used to test the SDK against x402, and the dependencies in every TypeScript x402…
Bump X402 Dependencies is an agent skill from coinbase/cdp-sdk. Bumps every @x402/ package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev dependencies used to test the SDK against x402, and the dependencies in every TypeScript x402 example) to the latest lockstep-released version, then verifies the SDK and all examples still build, lint, format, and typecheck. Use when the user asks to bump, update, or sync x402 (or @x402) dependencies/peer dependencies in cdp-sdk, or when a new x402 release needs to be picked up across the repo.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with x402, TypeScript and npm. The repository describes itself as: Client libraries for managing EVM and Solana wallets while relying on CDP to secure private keys. The licence is MIT.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 993de49. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CDP_API_KEY_IDCDP_API_KEY_SECRETCDP_WALLET_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Bump X402 Dependencies loads about 2.1k tokens when it runs. Until then it costs about 131 tokens; SKILL.md has 852 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from coinbase/cdp-sdk at commit 993de49, republished under its MIT licence (© coinbase). 852 words, ~2,060 tokens.
.claude/skills/bump-x402-dependencies/SKILL.md (or your agent's skills folder).@x402/* packages (core, evm, extensions, svm, axios, fetch,
mcp, express, hono, next) are released in lockstep: every package
publishes the same version number at the same time, always as X.Y.0.typescript/packages/cdp-sdk/package.json declares core/evm/extensions/svm
as optional peerDependencies, pinned with ^X.Y.0.typescript/package.json pins the same four packages plus fetch as
exact-version devDependencies (no ^) so the SDK's own test suite runs
against a known x402 version.@x402/* packages it
needs, pinned with ^X.Y.0:
examples/typescript/package.json (client examples) and each
examples/typescript/x402/servers/{express,hono,mcp,next}/package.json.extensions at
^2.17.0 while everything else is ^2.16.0), pnpm can install two copies of
a package at different versions. TypeScript then treats their exported
classes as structurally incompatible, producing errors like
Types have separate declarations of a private property 'xyz' in examples
that mix a CDP-provided type with an @x402/* type. Keeping every
occurrence on the same version avoids/fixes this class of bug.Resolve the target version. Don't guess — always resolve it fresh, since this skill is re-run every time x402 publishes a new release:
npm view @x402/core dist-tags.latestCross-check 2-3 other @x402/* packages actually in use (e.g. @x402/evm,
@x402/extensions) resolve to the same version. If they don't match, stop
and ask the user which version to target — the lockstep assumption doesn't
hold and blindly bumping could mix incompatible versions.
Find every occurrence. Run:
grep -rn '"@x402/' --include=package.json typescript examples 2>/dev/null | grep -v node_modulesAs of writing, this covers exactly these files/keys — but always trust the grep output over this list, since new examples may have been added since:
| File | Field | Prefix |
|---|---|---|
typescript/packages/cdp-sdk/package.json | peerDependencies: core, evm, extensions, svm | ^ |
typescript/package.json | devDependencies: core, evm, extensions, fetch, svm | exact (no ^) |
examples/typescript/package.json | dependencies: axios, core, evm, fetch, mcp, svm | ^ |
examples/typescript/x402/servers/express/package.json | dependencies: core, evm, express, extensions, svm | ^ |
examples/typescript/x402/servers/hono/package.json | dependencies: core, evm, extensions, hono, svm | ^ |
examples/typescript/x402/servers/mcp/package.json | dependencies: core, evm, mcp | ^ |
examples/typescript/x402/servers/next/package.json | dependencies: core, evm, extensions, next, svm | ^ |
Edit each occurrence. Replace only the version number in each
"@x402/<pkg>": "..." entry and preserve whatever prefix was already there
(^ vs. exact). Never touch unrelated dependencies, and never add @x402/*
packages to a file that didn't already depend on them.
Regenerate lockfiles (non-frozen install; this is expected to modify both lockfiles):
cd typescript && pnpm install
cd ../examples/typescript && pnpm installRegression-check the SDK:
cd typescript
pnpm build
pnpm lint
pnpm format:checkRegression-check the examples:
cd examples/typescript
pnpm build # typechecks root examples (evm/, solana/, quickstart/, x402/clients/, etc.)The root tsconfig.json excludes x402/servers, so each server workspace
has its own tsconfig.json. express, hono, and mcp have a
"build": "tsc" script; next has a "typecheck": "tsc --noEmit" script
(its "build" is next build). Run each:
cd x402/servers/express && pnpm build
cd ../hono && pnpm build
cd ../mcp && pnpm build
cd ../next && pnpm typecheckType-check next rather than next build it: a full next build collects
page data, which evaluates the route module and constructs the CDP
facilitator via createCdpFacilitatorClient() — that needs real
CDP_API_KEY_ID / CDP_API_KEY_SECRET and makes live CDP API calls, which
this job (and this skill's local regression check) intentionally avoids —
build-examples runs on every PR touching typescript/examples, not
just x402 ones, and shouldn't depend on network/CDP availability. tsc --noEmit catches the same type and dependency-version errors without
executing module code, and it's what the build-examples CI job runs.
(For reference, a real next build also needs PAY_TO set and its
next.config.ts sets turbopack.root / outputFileTracingRoot to the
repo root so Turbopack can resolve the workspace-linked
@coinbase/cdp-sdk — don't remove that config.)
If any regression check fails, don't just move on. An error like
Types have separate declarations of a private property '...' means some
@x402/* occurrence still doesn't match the rest — re-run step 2's grep
and diff versions across all files before investigating further.
Add a changeset if the SDK's peer dependencies changed. If
typescript/packages/cdp-sdk/package.json's peerDependencies changed,
add a changeset so the bump shows up in the next @coinbase/cdp-sdk
release notes:
---
"@coinbase/cdp-sdk": patch
---
Bump the `@x402/core`, `@x402/evm`, `@x402/extensions`, and `@x402/svm` peer dependencies to `^X.Y.0`.Save this as a new file under typescript/.changeset/ (any descriptive
filename, e.g. bump-x402-peer-deps.md), with X.Y.0 replaced by the
actual version. Use minor/major instead of patch if the x402 release
notes call out breaking changes.
Summarize and stop. Report old → new version per file and confirm every regression check passed. Leave all changes uncommitted for the user to review — do not commit or push unless explicitly asked.
build-examples
job runs, and are enough to catch the dependency-version-skew errors this
skill exists to fix. They don't require CDP credentials, so they're the
right default when you don't have any configured.CDP_API_KEY_ID / CDP_API_KEY_SECRET /
CDP_WALLET_SECRET) and a funded testnet wallet, also live-test the example
servers and clients against each other (pnpm start in each server
directory, then run a client example against it) before considering the
bump complete. This isn't required by the skill, but it's worth doing: a
prior x402 bump introduced a runtime-only regression (an MCP server hanging
on a second concurrent client) that type-checking never caught. CI's E2E
workflows do have real CDP credentials (a globally-set API key and wallet
secret — see .github/workflows/typescript_e2e_test.yml), so this kind of
check is reproducible there even without local credentials.package.json to
the table in step 2, give it its own tsconfig.json + "build": "tsc"
script (mirroring express/hono/mcp) so it gets type-checked at all,
wire that build into the build-examples CI job, and add its regression
check to step 6.© coinbase, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .cursor/skills/bump-x402-dependencies of coinbase/cdp-sdk.
Open the folder on GitHubat commit 993de49
Bump X402 Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Bump X402 Dependencies this skillcoinbase/cdp-sdk | 203 | — | ~2.1k | Automated safety check: Pass | MIT | |
| MCP Server BuildershareAI-lab/learn-claude-code | 78k | 4 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop | 5.4k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Link Workspace Packagesnomcopter/react-mosaic | 4.8k | 6 repos | ~760 | Automated safety check: Pass | Custom licence | |
| Logseq Plugin SDKlogseq/logseq | 45k | — | ~2.3k | Automated safety check: Pass | AGPL-3.0 | |
| Create Docsvictorgarciaesgi/nuxt-typed-router | 413 | 2 repos | ~2.8k | Automated safety check: Pass | MIT |
shareAI-lab/learn-claude-code
Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.
dmmulroy/anti-slop
Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.
nomcopter/react-mosaic
Link workspace packages in monorepos (npm, yarn, pnpm, bun).
logseq/logseq
Build, debug, or review Logseq plugins with the @logseq/libs SDK (TypeScript/JavaScript, iframe/shadow sandboxed).
victorgarciaesgi/nuxt-typed-router
Create complete documentation sites for projects. An agent skill from victorgarciaesgi/nuxt-typed-router.
pnpm/pnpm
Run the tests that cover a change in the pnpm repository, in the Rust workspace (pnpm/, pnpr/) or the TypeScript CLI (pnpm11/), and recognize the cases where a scoped run passes without testing…
coinbase/cdp-sdk
Write code that pays for an HTTP API returning 402 Payment Required, using the x402 protocol and a CDP-managed wallet.
coinbase/cdp-sdk
Write code that charges for an HTTP route with the x402 protocol and receives USDC in a CDP-managed wallet.
Works with
Bumps every @x402/ package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev dependencies used to test the SDK against x402, and the dependencies in every TypeScript x402…. Bump X402 Dependencies is an agent skill from coinbase/cdp-sdk. Bumps every @x402/ package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev dependencies used to test the SDK against x402, and the dependencies in every TypeScript x402 example) to the latest lockstep-released version, then verifies the SDK and all examples still build, lint, format, and typecheck.
Bump X402 Dependencies fits situations like: the user asks to bump; sync x402 (or @x40; dependencies/peer dependencies in cdp-sdk; A new x402 release needs to be picked up across the repo.
Run `npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a claude-code`. Or copy the skill folder (.cursor/skills/bump-x402-dependencies in coinbase/cdp-sdk) into .claude/skills/bump-x402-dependencies in your project. Claude Code loads it when a task matches its description.
Run `npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a codex`. Or copy the skill folder (.cursor/skills/bump-x402-dependencies in coinbase/cdp-sdk) into .agents/skills/bump-x402-dependencies in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bump-x402-dependencies, .gemini/skills/bump-x402-dependencies, .github/skills/bump-x402-dependencies and .opencode/skills/bump-x402-dependencies in your project.
Going by SKILL.md and its folder, Bump X402 Dependencies needs the command-line tools its instructions call (pnpm and npm) and credentials named CDP_API_KEY_ID, CDP_API_KEY_SECRET and CDP_WALLET_SECRET. Our summary lists: A credential in CDP_API_KEY_SECRET; A credential in CDP_WALLET_SECRET.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Bump X402 Dependencies is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Bump X402 Dependencies: MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), Install Anti-Slop Oxlint Rules (dmmulroy/anti-slop, 5.4k stars), Link Workspace Packages (nomcopter/react-mosaic, 4.8k stars) and Logseq Plugin SDK (logseq/logseq, 45k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
coinbase (a GitHub organization) maintains it in coinbase/cdp-sdk, which has 203 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 6, 2026.
Source: coinbase/cdp-sdk on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.