Agent skill

MCP Server Development

by Hack23 in Hack23/cia

Model Context Protocol server development, MCP tool patterns, MCP configuration best practices, GitHub MCP integration

Apache-2.0Auto-check passedAgent Workflows

Install MCP Server Development

skills CLI
$ npx skills add Hack23/cia --skill mcp-server-development -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia mcp-server-development --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/mcp-server-development .claude/skills/mcp-server-development && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mcp-server-development
GitHub stars
239
Token cost
~1.3k tokens
SKILL.md length
323 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Model Context Protocol server development, MCP tool patterns, MCP configuration best practices, GitHub MCP integration

  • Works in 5 steps: Never embed secrets in… → Scope tools narrowly — each tool should… → Validate all inputs against JSON Schema… → …
  • Tasks that involve MCP servers
  • SKILL.md covers Purpose, When to Use, MCP Architecture Overview and MCP Configuration Best Practices, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

MCP Server Development is an agent skill from Hack23/cia. Model Context Protocol server development, MCP tool patterns, MCP configuration best practices, GitHub MCP integration

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol and GitHub. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve MCP servers

Example prompts

  • “/mcp-server-development”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Never embed secrets in copilot-mcp-config.json — use environment references
  2. Scope tools narrowly — each tool should do one thing well
  3. Validate all inputs against JSON Schema before processing
  4. Return structured data — prefer typed objects over free-form strings
  5. Include error details in tool responses for debugging

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

MCP Server Development loads about 1.3k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 323 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 323 words, ~1,273 tokens.

Download SKILL.mdSave it as .claude/skills/mcp-server-development/SKILL.md (or your agent's skills folder).
name
mcp-server-development
description
Model Context Protocol server development, MCP tool patterns, MCP configuration best practices, GitHub MCP integration
license
Apache-2.0

MCP Server Development Skill

Purpose

Guide the development and configuration of Model Context Protocol (MCP) servers for the CIA platform, enabling AI-powered tooling integration with GitHub Copilot and other MCP-compatible clients.

When to Use

  • ✅ Creating new MCP server tools for political data access
  • ✅ Configuring .github/copilot-mcp-config.json for new integrations
  • ✅ Designing tool schemas for structured data retrieval
  • ✅ Implementing MCP transports (stdio, SSE, HTTP)
  • ✅ Integrating GitHub MCP tools with CI/CD workflows

Do NOT use for:

  • ❌ Standard REST API development (use api-integration skill)
  • ❌ UI component development (use vaadin-component-design skill)

MCP Architecture Overview

┌─────────────────┐     ┌──────────────┐     ┌─────────────────┐
│  MCP Client     │────▶│  MCP Server  │────▶│  Data Sources   │
│  (Copilot/IDE)  │◀────│  (Tools)     │◀────│  (Riksdag API)  │
└─────────────────┘     └──────────────┘     └─────────────────┘
        │                       │
        │ JSON-RPC 2.0         │ Tool Definitions
        │ over stdio/SSE       │ Input/Output Schemas

MCP Configuration Best Practices

GitHub Copilot MCP Config
json
{
  "mcpServers": {
    "cia-political-data": {
      "type": "stdio",
      "command": "node",
      "args": ["dist/mcp-server.js"],
      "env": {
        "CIA_DATA_DIR": "${workspaceFolder}/data"
      }
    }
  }
}
Key Configuration Rules
  1. Never embed secrets in copilot-mcp-config.json — use environment references
  2. Scope tools narrowly — each tool should do one thing well
  3. Validate all inputs against JSON Schema before processing
  4. Return structured data — prefer typed objects over free-form strings
  5. Include error details in tool responses for debugging

MCP Tool Design Patterns

Tool Definition Schema
typescript
interface McpToolDefinition {
  name: string;           // e.g., "get_politician_votes"
  description: string;    // Clear, concise purpose
  inputSchema: {
    type: "object";
    properties: Record<string, JsonSchema>;
    required: string[];
  };
}
CIA-Specific Tool Examples
typescript
// Politician lookup tool
const getPoliticianTool = {
  name: "get_politician_profile",
  description: "Retrieve profile and voting record for a Swedish Parliament member",
  inputSchema: {
    type: "object",
    properties: {
      personId: { type: "string", description: "Riksdagen person ID" },
      includeVotes: { type: "boolean", default: false }
    },
    required: ["personId"]
  }
};

// Document search tool
const searchDocumentsTool = {
  name: "search_riksdag_documents",
  description: "Search Swedish Parliament documents by keyword, type, and date range",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string" },
      docType: { type: "string", enum: ["motion", "proposition", "betankande"] },
      fromDate: { type: "string", format: "date" },
      toDate: { type: "string", format: "date" }
    },
    required: ["query"]
  }
};
Error Handling Pattern
typescript
async function handleToolCall(name: string, args: unknown): Promise<McpResult> {
  try {
    const validated = validateInput(name, args);
    const result = await executeQuery(validated);
    return { content: [{ type: "text", text: JSON.stringify(result) }] };
  } catch (error) {
    return {
      content: [{ type: "text", text: `Error: ${error.message}` }],
      isError: true
    };
  }
}

GitHub MCP Integration

Available GitHub MCP Tools

The CIA project uses GitHub MCP server for:

  • Repository management — branches, commits, file operations
  • Issue tracking — create, update, search issues
  • Pull request workflows — reviews, comments, merges
  • Actions integration — trigger workflows, check status
  • Security scanning — code scanning alerts, Dependabot
Best Practices for GitHub MCP
  1. Use specific queries — avoid broad searches that return too many results
  2. Paginate results — always handle pagination for large result sets
  3. Cache responses — reduce API calls for frequently accessed data
  4. Handle rate limits — implement exponential backoff

Security Considerations

  • Input validation — sanitize all tool inputs before processing
  • Authentication — use token-based auth, never hardcode credentials
  • Authorization — scope tool access to minimum required permissions
  • Logging — log tool invocations for audit trails, never log sensitive data
  • Transport security — use encrypted transports for remote MCP servers

ISMS Alignment

ControlRequirement
ISO 27001 A.8.9Configuration management for MCP servers
NIST CSF PR.DS-2Data-in-transit protection for MCP transport
CIS Control 16Application software security for MCP tools

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/mcp-server-development of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

MCP Server Development next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

MCP Server Development compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
MCP Server Development this skillHack23/cia239—~1.3kAutomated safety check: PassApache-2.0
Skill Seekers Builderyusufkaraaslan/Skill_Seekers15k—~760Automated safety check: PassMIT
MCP Apps Builderawslabs/cli-agent-orchestrator1.4k—~1.7kAutomated safety check: PassApache-2.0
Releasejgravelle/jcodemunch-mcp2.7k—~6.5kAutomated safety check: PassCustom licence
Open PRArcadeAI/arcade-mcp1k—~2.9kAutomated safety check: PassMIT
MCP Clientcoleam00/second-brain-skills832—~1kAutomated safety check: PassNone

Similar skills

  • Skill Seekers Builder

    yusufkaraaslan/Skill_Seekers

    Detects the type of a knowledge source and uses the Skill Seekers MCP tools to turn docs, repos, PDFs or videos into packaged AI skills.

    15k GitHub stars~760 tokensUpdated 7 days ago
    Agent WorkflowsAuto-check passed
  • MCP Apps Builder

    awslabs/cli-agent-orchestrator

    Official

    Load the official MCP Apps builder skills (create-mcp-app, migrate-oai-app, add-app-to-server, convert-web-app) from github.com/modelcontextprotocol/ext-apps.

    1.4k GitHub stars~1.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Release

    jgravelle/jcodemunch-mcp

    Publishing a jMunch release (jcodemunch-mcp, jdocmunch-mcp, jdatamunch-mcp, jragmunch-cli), reviewing/merging/closing PRs, and responding to the community.

    2.7k GitHub stars~6.5k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Open PR

    ArcadeAI/arcade-mcp

    Prepare arcade-mcp changes for review by verifying intended behavior, filling the repository PR template, and creating or updating the PR.

    1k GitHub stars~2.9k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • MCP Client

    coleam00/second-brain-skills

    Universal MCP client for connecting to any MCP server with progressive disclosure.

    832 GitHub stars~1k tokensUpdated 8 mo ago
    Agent WorkflowsAuto-check passed
  • Project Release

    swimmwatch/cloakbrowser-mcp

    Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work.

    161 GitHub stars~1.9k tokensUpdated 5 days ago
    Agent WorkflowsAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Categories

Questions about MCP Server Development

What does MCP Server Development do?

Model Context Protocol server development, MCP tool patterns, MCP configuration best practices, GitHub MCP integration. MCP Server Development is an agent skill from Hack23/cia.

When should I use MCP Server Development?

MCP Server Development fits situations like: tasks that involve MCP servers.

How do I install MCP Server Development in Claude Code?

Run `npx skills add Hack23/cia --skill mcp-server-development -a claude-code`. Or copy the skill folder (.github/skills/mcp-server-development in Hack23/cia) into .claude/skills/mcp-server-development in your project. Claude Code loads it when a task matches its description.

How do I install MCP Server Development in Codex?

Run `npx skills add Hack23/cia --skill mcp-server-development -a codex`. Or copy the skill folder (.github/skills/mcp-server-development in Hack23/cia) into .agents/skills/mcp-server-development in your project. Codex loads it when a task matches its description.

Can I use MCP Server Development in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill mcp-server-development -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-server-development, .gemini/skills/mcp-server-development, .github/skills/mcp-server-development and .opencode/skills/mcp-server-development in your project.

What does MCP Server Development need to run?

SKILL.md names no scripts, command-line tools or credentials: MCP Server Development is instructions for the agent only.

Does MCP Server Development access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is MCP Server Development safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does MCP Server Development use?

MCP Server Development is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does MCP Server Development use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to MCP Server Development?

Skills that share tags, products or a category with MCP Server Development: Skill Seekers Builder (yusufkaraaslan/Skill_Seekers, 15k stars), MCP Apps Builder (awslabs/cli-agent-orchestrator, 1.4k stars), Release (jgravelle/jcodemunch-mcp, 2.7k stars) and Open PR (ArcadeAI/arcade-mcp, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains MCP Server Development?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.