Post-init orientation for an MCP server built on @cyanheads/mcp-ts-core.

Apache-2.0Auto-check: notesAgent Workflows

Install Setup

skills CLI
$ npx skills add cyanheads/pubmed-mcp-server --skill setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cyanheads/pubmed-mcp-server setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cyanheads/pubmed-mcp-server.git skills-src && mkdir -p .claude/skills && cp -r skills-src/framework-skills/setup .claude/skills/setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
setup
GitHub stars
155
Token cost
~3.3k tokens
SKILL.md length
1,210 words
Files
1
Skills in repo
30
Repo updated
First seen
Licence
Apache-2.0

At a glance

Post-init orientation for an MCP server built on @cyanheads/mcp-ts-core.

  • Works in 3 steps: Clean up what you don't need. If your… → Rename and replace what you keep. The… → Definitions register directly in…
  • Onboarding to an existing project for the first time
  • SKILL.md covers Context, Agent Protocol File, Project Structure and Scaffolded Echo Definitions, plus 6 more sections
  • Calls bun and bunx

What it does

Setup is an agent skill from cyanheads/pubmed-mcp-server. Post-init orientation for an MCP server built on @cyanheads/mcp-ts-core. Use after running @cyanheads/mcp-ts-core init to understand the project structure, conventions, and skill sync model. Also use when onboarding to an existing project for the first time.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers and Project scaffolding. It works with Model Context Protocol. The repository describes itself as: Search PubMed/Europe PMC, fetch articles and full text (PMC/EPMC/Unpaywall), citations, MeSH terms via MCP. STDIO or Streamable HTTP. The licence is Apache-2.0.

When your agent uses it

  • Onboarding to an existing project for the first time
  • Tasks that involve MCP servers
  • Tasks that involve Project scaffolding

Example prompts

  • “/setup”

Requirements

  • Docker

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Clean up what you don't need. If your server has no prompts, delete the echo prompt and its registration in src/index.ts. Same for…
  2. Rename and replace what you keep. The echo definitions and their tests show the pattern — swap them out for your real…
  3. Definitions register directly in src/index.ts. The init scaffold uses direct imports — no barrel files yet. As the definition count grows…

What it can do on your machine

Read from SKILL.md and the folder at commit 5a417fb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • bunx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use bunx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Setup loads about 3.3k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 1,210 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:37
    # Copy to .env and fill in

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cyanheads/pubmed-mcp-server at commit 5a417fb, republished under its Apache-2.0 licence (© cyanheads). 1,210 words, ~3,284 tokens.

Download SKILL.mdSave it as .claude/skills/setup/SKILL.md (or your agent's skills folder).
name
setup
description
Post-init orientation for an MCP server built on @cyanheads/mcp-ts-core. Use after running `@cyanheads/mcp-ts-core init` to understand the project structure, conventions, and skill sync model. Also use when onboarding to an existing project for the first time.
metadata.author
cyanheads
metadata.version
1.12
metadata.audience
external
metadata.type
workflow

Context

This skill assumes bunx @cyanheads/mcp-ts-core init [name] has already run. The CLI created the project's CLAUDE.md and AGENTS.md for different agents, copied external skills to framework-skills/, and scaffolded the directory structure with echo definitions as starting points. This skill covers what was created and what to do next.

Agent Protocol File

The init CLI generates both CLAUDE.md and AGENTS.md with identical content — CLAUDE.md is read by Claude Code, AGENTS.md by Codex, Cursor, Windsurf, and other agents. Keep both. Shipping both keeps the project agent-agnostic, and they're cheap to hold in sync: edit one, then cp CLAUDE.md AGENTS.md (the framework keeps its own pair byte-identical the same way, enforced by check-docs-sync). Only delete one if you're certain the project will never be opened by the other family of agents.

For the full framework docs, read node_modules/@cyanheads/mcp-ts-core/CLAUDE.md (or its identical twin AGENTS.md) once per session. It contains the exports catalog, tool/resource/prompt contracts, error codes, context API, and common import patterns.

Project Structure

What init actually creates:

text
CLAUDE.md                                       # Agent protocol — Claude Code
AGENTS.md                                       # Agent protocol — other agents (Codex, Cursor, etc.)
package.json                                    # Starter deps + scripts (placeholders substituted on init)
tsconfig.json                                   # Typecheck config — covers src/ and tests/, emits nothing
tsconfig.build.json                             # Build config — emits src/ to dist/, tests excluded
vitest.config.ts                                # Test runner config
biome.json                                      # Lint + format config
devcheck.config.json                            # Which devcheck steps to run
Dockerfile                                      # Starter multi-stage image
.dockerignore
.env.example                                    # Copy to .env and fill in
.gitignore
.github/ISSUE_TEMPLATE/                         # Bug / feature-request issue forms
.vscode/                                        # Recommended extensions + editor settings
server.json                                     # MCP Registry publishing metadata
changelog/template.md                           # Format reference for per-version changelog files
scripts/                                        # Framework scripts (build, devcheck and its checks, lint-mcp, lint-packaging, Docker install-otel and prune-musl-packages, release-github, …), re-synced by `maintenance`
framework-skills/                               # External skills copied from the package (source of truth)
src/
  index.ts                                      # createApp() entry point
  mcp-server/
    tools/definitions/
      echo.tool.ts                              # Standard tool starter
      echo-app.app-tool.ts                      # UI-enabled app tool starter (pairs with echo-app-ui resource)
    resources/definitions/
      echo.resource.ts                          # Standard resource starter
      echo-app-ui.app-resource.ts               # UI resource paired with echo-app app tool
    prompts/definitions/
      echo.prompt.ts                            # Prompt starter
tests/
  tools/echo.tool.test.ts                       # Starter tests (one per echo definition)
  resources/echo.resource.test.ts
  prompts/echo.prompt.test.ts
  smoke/definitions.smoke.test.ts               # Every shipped definition executed once
  integration/echo-contract.int.test.ts         # The echo tool driven through the production surfaces
  fuzz/echo-tool.fuzz.test.ts                   # Property-based coverage, via the fast-check dev dep

Add these as needed:

text
src/
  worker.ts                                     # createWorkerHandler() — only for Cloudflare Workers
  config/
    server-config.ts                            # Server-specific env vars (own Zod schema)
  services/
    [domain]/
      [domain]-service.ts                       # Init/accessor pattern
      types.ts

Scaffolded Echo Definitions

The init creates five echo definitions plus matching starter tests:

FileDemonstrates
echo.tool.tsStandard MCP tool: input/output Zod schemas, handler, format
echo-app.app-tool.tsMCP App tool — same as a tool, but emits a UI (ui_app:// link) for clients that render MCP Apps
echo.resource.tsStandard MCP resource with a parameterised URI template
echo-app-ui.app-resource.tsUI resource served to MCP App clients; paired with echo-app.app-tool.ts
echo.prompt.tsPrompt template (pure message generator)
tests/**/echo.*.test.tsStarter tests using createMockContext — edit alongside the definitions

After init:

  1. Clean up what you don't need. If your server has no prompts, delete the echo prompt and its registration in src/index.ts. Same for resources, or the app-tool pair if you're not targeting UI-capable clients.
  2. Rename and replace what you keep. The echo definitions and their tests show the pattern — swap them out for your real tools/resources/prompts.
  3. Definitions register directly in src/index.ts. The init scaffold uses direct imports — no barrel files yet. As the definition count grows, the add-tool/add-resource/add-prompt skills introduce definitions/index.ts barrels per the framework convention.

See the add-tool, add-app-tool, add-resource, add-prompt, add-service, and add-test skills for the scaffolding patterns when you start adding real definitions.

Conventions

ConventionRule
File nameskebab-case
Tool/resource/prompt namessnake_case, prefixed with server name (e.g. tasks_fetch_list)
File suffixes.tool.ts, .resource.ts, .prompt.ts, .app-tool.ts (UI-enabled), .app-resource.ts (paired UI resource)
Imports (framework)@cyanheads/mcp-ts-core and subpaths
Imports (server code)@/ path alias for src/

Skill Sync

Copy all project skills into your agent's skill directory so they're available as context. framework-skills/ is the source of truth. It is deliberately not skills/: Claude Code and Codex auto-load a plugin's root skills/, and these are development skills, not skills for the agents that install the server — leave skills/ for those.

Don't edit framework-skills/*/SKILL.md or framework-skills/*/references/*. These are external skill files synced from @cyanheads/mcp-ts-core — the maintenance skill overwrites them on package updates, so local edits get lost. Project-specific agent context belongs in CLAUDE.md / AGENTS.md.

For Claude Code:

bash
mkdir -p .claude/skills && cp -R framework-skills/* .claude/skills/

For other agents (Codex, Cursor, Windsurf, etc.) — copy to the equivalent directory (e.g., .codex/skills/, .cursor/skills/).

This step is the bootstrap — it creates the agent directory. From then on, use the maintenance skill to refresh it after package updates (Phase B). Maintenance only refreshes directories that already exist; it won't create a new agent directory on your behalf.

Project Scaffolding

Complete these one-time setup tasks:

  1. Install dependencies — bun install

  2. Update dependencies to latest — bun update --latest. The scaffolded package.json pins minimum versions from when the framework was published; updating ensures you start with the latest compatible releases.

  3. Initialize git — use your git tools: init the repo, stage all files, and commit with message chore: scaffold from @cyanheads/mcp-ts-core

  4. Verify the substituted server name — when init runs without a [name] argument, the package name defaults to the cwd directory name. If that's not what you want as the published server name, update package.json, CLAUDE.md/AGENTS.md, and server.json to your actual server name.

  5. Populate the publishing identity — the scaffold ships identity fields empty on purpose, so the first devcheck run is a to-do list rather than a green light. These fail the gate until they are set:

    FileGated fieldsGate
    server.jsonname (reverse-DNS, e.g. io.github.<owner>/<server>), description, repository.urllint:mcp
    .claude-plugin/plugin.jsondescriptionlint:packaging
    .codex-plugin/plugin.jsondescription, interface.shortDescription, interface.longDescriptionlint:packaging

    Fill the rest of the same blocks while you are in them — package.json description and repository.url, both plugin manifests' author / homepage / repository / keywords, the Codex manifest's interface.developerName / category / websiteURL, and manifest.json description / author.name. Nothing gates them, and every install surface reads them.

    When the server takes a user-supplied value (an API key, a contact email, an instance URL), wire it into the plugin manifests the way each client delivers it — never as "KEY": "" in env, which lint:packaging rejects because the empty value replaces the user's exported key and is read as unset. In .claude-plugin/plugin.json, declare the option under userConfig (type, title, description; sensitive: true for keys and tokens; required: true or default: "") and set "KEY": "${user_config.<option>}" in env. In .codex-plugin/mcp.json, list the variable name in env_vars. Mirror the user_config block you write in manifest.json.

    A server that will never be published or installed as a plugin can drop the plugin-manifest gate instead — set "packaging": { "pluginManifests": false } in devcheck.config.json.

  6. Verify the scaffold builds clean — bun run devcheck. Fix any issues before starting real work.

Show full SKILL.md (332 more words)Show less

Changelog Convention

changelog/template.md ships as a format reference — never edit, rename, or move it. For each release, author a per-version file at changelog/<major.minor>.x/<version>.md (e.g. changelog/0.1.x/0.1.0.md) with YAML frontmatter (summary: + optional breaking: / security:) and grouped sections (Added / Changed / Fixed / Removed). Then regenerate the rollup with bun run changelog:build — CHANGELOG.md is an auto-generated navigation index, never hand-edited. See the release-and-publish skill for the full release flow.

Next Steps

The included skills form a rough progression — not a rigid sequence, but the typical flow through a new server:

  1. design-mcp-server — map the domain into tools, resources, and services before writing any definitions
  2. add-tool / add-app-tool / add-resource / add-prompt / add-service — scaffold each piece as you go
  3. add-test — pair tests with each definition (or retrofit later)
  4. field-test — exercise the built surface with real and adversarial inputs; produces a report of issues and pain points
  5. security-pass — audit handlers for MCP-specific security gaps: output injection, scope blast radius, input sinks, tenant isolation
  6. polish-docs-meta — finalize README, metadata, and agent protocol before shipping
  7. release-and-publish — post-wrapup ship workflow: verification gate, push commits and tags, publish to npm/MCP Registry/GHCR
  8. maintenance — after bun update --latest, investigate upstream changelogs and re-sync skills

Skip or reorder as the project calls for it. The agent protocol's "What's Next?" section is the authoritative map once the first session is over.

Checklist

  • Agent protocol files kept — both CLAUDE.md and AGENTS.md present and in sync (or the unused one deliberately deleted)
  • bun install run
  • Dependencies updated (bun update --latest)
  • Git repo initialized and initial commit made (chore: scaffold from @cyanheads/mcp-ts-core)
  • Substituted server name verified in package.json, agent protocol file, and server.json
  • Publishing identity populated (server.json, package.json, plugin manifests, manifest.json) — or the plugin-manifest gate opted out
  • Framework docs read (node_modules/@cyanheads/mcp-ts-core/CLAUDE.md or AGENTS.md)
  • Unused echo definitions cleaned up (and unregistered from src/index.ts)
  • Skills copied to agent directory (cp -R framework-skills/* .claude/skills/ or equivalent)
  • Project structure understood (definitions directories, entry point)
  • bun run devcheck passes
  • Next: if new server, move on to design-mcp-server to plan the tool surface

© cyanheads, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in framework-skills/setup of cyanheads/pubmed-mcp-server.

Open the folder on GitHubat commit 5a417fb

Compare with similar skills

Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Setup this skillcyanheads/pubmed-mcp-server155—~3.3kAutomated safety check: NotesApache-2.0
Chatgpt AppsHaohao-end/openagent8071 repos~4.9kAutomated safety check: PassApache-2.0
MCP Scaffoldtimothywarner-org/claude-code224—~940Automated safety check: PassMIT
AI Bomcdxgen/cdxgen1.1k—~2.5kAutomated safety check: PassApache-2.0
UI Widget Developermicrosoft/work-iq1k—~6.1kAutomated safety check: NotesCustom licence
MCP Server Builderalirezarezvani/claude-skills28k—~985Automated safety check: PassMIT

Similar skills

  • Chatgpt Apps

    Haohao-end/openagent

    Build, scaffold, refactor, and troubleshoot ChatGPT Apps SDK applications that combine an MCP server and widget UI.

    807 GitHub starsUsed in 1 repo~4.9k tokens
    Agent WorkflowsAuto-check passed
  • MCP Scaffold

    timothywarner-org/claude-code

    Scaffold production-ready Python MCP servers using FastMCP. An agent skill from timothywarner-org/claude-code.

    224 GitHub stars~940 tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • UI Widget Developer

    microsoft/work-iq

    Official

    Build MCP servers for Copilot Chat using the OpenAI Apps SDK or MCP Apps SDK widget rendering support (any language).

    1k GitHub stars~6.1k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • MCP Server Builder

    alirezarezvani/claude-skills

    Design and ship production-ready MCP (Model Context Protocol) servers from OpenAPI contracts instead of hand-written tool wrappers.

    28k GitHub stars~985 tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • Openspec Aware

    Chorus-AIDLC/Chorus

    OpenSpec-mode authoring for Chorus PM workflows in Hermes. An agent skill from Chorus-AIDLC/Chorus.

    1.2k GitHub stars~7.2k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes

More from cyanheads/pubmed-mcp-server

All 30 skills in this repo
  • Add App Tool

    cyanheads/pubmed-mcp-server

    Scaffold an MCP App tool + UI resource pair. An agent skill from cyanheads/pubmed-mcp-server.

    155 GitHub stars~3.2k tokensUpdated 4 days ago
    Auto-check passed
  • Add Prompt

    cyanheads/pubmed-mcp-server

    Scaffold a new MCP prompt template. An agent skill from cyanheads/pubmed-mcp-server.

    155 GitHub stars~1.6k tokensUpdated 4 days ago
    Auto-check passed
  • Add Resource

    cyanheads/pubmed-mcp-server

    Scaffold a new MCP resource definition. An agent skill from cyanheads/pubmed-mcp-server.

    155 GitHub stars~3k tokensUpdated 4 days ago
    Auto-check passed
  • Add Service

    cyanheads/pubmed-mcp-server

    Scaffold a new service integration. An agent skill from cyanheads/pubmed-mcp-server.

    155 GitHub stars~3.6k tokensUpdated 4 days ago
    Auto-check passed
  • Add Test

    cyanheads/pubmed-mcp-server

    Scaffold a test file for an existing tool, resource, or service.

    155 GitHub stars~4.1k tokensUpdated 4 days ago
    Auto-check passed
  • API Auth

    cyanheads/pubmed-mcp-server

    Authentication, authorization, and multi-tenancy patterns for @cyanheads/mcp-ts-core.

    155 GitHub stars~2.7k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Setup

What does Setup do?

Post-init orientation for an MCP server built on @cyanheads/mcp-ts-core. Setup is an agent skill from cyanheads/pubmed-mcp-server. Post-init orientation for an MCP server built on @cyanheads/mcp-ts-core.

When should I use Setup?

Setup fits situations like: onboarding to an existing project for the first time; tasks that involve MCP servers; tasks that involve Project scaffolding.

How do I install Setup in Claude Code?

Run `npx skills add cyanheads/pubmed-mcp-server --skill setup -a claude-code`. Or copy the skill folder (framework-skills/setup in cyanheads/pubmed-mcp-server) into .claude/skills/setup in your project. Claude Code loads it when a task matches its description.

How do I install Setup in Codex?

Run `npx skills add cyanheads/pubmed-mcp-server --skill setup -a codex`. Or copy the skill folder (framework-skills/setup in cyanheads/pubmed-mcp-server) into .agents/skills/setup in your project. Codex loads it when a task matches its description.

Can I use Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cyanheads/pubmed-mcp-server --skill setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/setup, .gemini/skills/setup, .github/skills/setup and .opencode/skills/setup in your project.

What does Setup need to run?

Going by SKILL.md and its folder, Setup needs the command-line tools its instructions call (bun and bunx). Our summary lists: Docker.

Does Setup access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Setup safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Setup use?

Setup is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Setup use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Setup?

Skills that share tags, products or a category with Setup: Chatgpt Apps (Haohao-end/openagent, 807 stars), MCP Scaffold (timothywarner-org/claude-code, 224 stars), AI Bom (cdxgen/cdxgen, 1.1k stars) and UI Widget Developer (microsoft/work-iq, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Setup?

cyanheads (a GitHub user) maintains it in cyanheads/pubmed-mcp-server, which has 155 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 4, 2026.

Source: cyanheads/pubmed-mcp-server on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.