Agent skill

Suede MCP Release QA

by JasonColapietro in JasonColapietro/suede-creator-skills

Checks a Suede AI MCP server release against a live process: the full JSON-RPC lifecycle, schemas, annotations, malformed input, catalog agreement and install docs.

MITAuto-check passedTesting & QA

Install Suede MCP Release QA

skills CLI
$ npx skills add JasonColapietro/suede-creator-skills --skill suede-mcp-qa -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install JasonColapietro/suede-creator-skills suede-mcp-qa --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/JasonColapietro/suede-creator-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/suede-mcp-qa .claude/skills/suede-mcp-qa && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
suede-mcp-qa
GitHub stars
127
Token cost
~2.1k tokens
SKILL.md length
1,048 words
Files
5 (incl. scripts, references)
Skills in repo
78
Repo updated
First seen
Licence
MIT

At a glance

Checks a Suede AI MCP server release against a live process: the full JSON-RPC lifecycle, schemas, annotations, malformed input, catalog agreement and install docs.

  • Works in 9 steps: Run syntax checks and the repo's… → Parse catalog JSON and confirm every… → Exercise the full lifecycle in one… → …
  • Changing the MCP server, mcp/catalog.json or a tool, resource or prompt definition
  • SKILL.md covers Gate policy: advisory, not…, Operating Stance, Checks and This Server's Real Surface, plus 6 more sections
  • Runs Shell scripts from its folder

What it does

This skill is scoped to one pack's own server, mcp/suede-skills-mcp.mjs, and its catalog, install and docs surface. It checks a live server instead of a spec: syntax checks and hermetic protocol tests, parsing the catalog JSON to confirm each listed skill folder exists, and scripts/mcp-surface-snapshot.sh to compare the catalog's mcp block with what the server actually serves. When they drift, the server wins.

It exercises the whole lifecycle in one process: initialize, notifications/initialized, ping, tools/list, tools/call, resources/list, resources/read, prompts/list and prompts/get. The checks also cover protocol negotiation, closed input and output schemas, tool annotations, structuredContent with text fallbacks, malformed-input probes, clean stdio and install-path wording. A check that could not run against the live server counts as a FAIL, and an install command is marked working only after it runs from a temporary directory.

Verdicts such as ship, ship-with-caveats and hold are advice only: a failed gate changes what is reported, not what the agent does, except that an extremely risky finding, like data loss or credential exposure, pauses for your decision. The exact command and output are recorded for each check.

When your agent uses it

  • Changing the MCP server, mcp/catalog.json or a tool, resource or prompt definition
  • Preparing an MCP release of the Suede pack
  • Checking that the catalog matches what the live server reports
  • Verifying the MCP install docs after an edit

Example prompts

  • “Run the Suede MCP QA before I publish this release.”
  • “I edited mcp/catalog.json. Check that it still matches what the live server serves.”
  • “Exercise tools/call and resources/read on the live server and report any schema drift.”

Requirements

  • A checkout of the Suede skills pack with mcp/suede-skills-mcp.mjs and mcp/catalog.json
  • bash, for scripts/mcp-surface-snapshot.sh

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Run syntax checks and the repo's hermetic MCP protocol tests.
  2. Parse catalog JSON and confirm every listed skill folder exists, then run
  3. Exercise the full lifecycle in one process: initialize, the
  4. Verify supported protocol versions are echoed and an unsupported client
  5. Confirm every tool has a closed inputSchema, an outputSchema, and
  6. Confirm every successful tool call returns structuredContent, a useful
  7. Check pre-initialization calls, repeated initialization, bounded input,
  8. Confirm healthy stderr is empty and stdout contains newline-delimited JSON
  9. Confirm install output leads with public GitHub skill installs, local plugin

What it can do on your machine

Read from SKILL.md and the folder at commit e5f94d7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Suede MCP Release QA loads about 2.1k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 235 tokens; SKILL.md has 1,048 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~235
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from JasonColapietro/suede-creator-skills at commit e5f94d7, republished under its MIT licence (© JasonColapietro). 1,048 words, ~2,082 tokens.

Download SKILL.mdSave it as .claude/skills/suede-mcp-qa/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
suede-mcp-qa
description
Suede AI MCP release QA, scoped to this pack's own server (mcp/suede-skills-mcp.mjs) and its catalog, install, and docs surface. Runs the full JSON-RPC lifecycle against a live server (initialize, notifications/initialized, ping, tools/list, tools/call, resources/list, resources/read, prompts/list, prompts/get), plus protocol negotiation, closed input and output schemas, tool annotations, structuredContent with text fallbacks, malformed-input probes, clean stdio, catalog-to-folder agreement, and install-path language. Use when the MCP server, mcp/catalog.json, a tool, resource, or prompt definition, or the MCP install docs change, or before publishing an MCP release. A check that did not run against the live server is a FAIL, not a skip. NOT FOR: a generic third-party MCP server, which this skill's hardcoded surface does not describe; fixing or testing the public install path itself (use suede-launch-packaging).

Suede MCP QA

Gate policy: advisory, not blocking

Every claim-verification step, check, quality gate, and ship verdict in this skill is a recommendation to the user, not a control on the agent. This policy governs every gate, check, verdict, and "do not ship / publish / proceed" line elsewhere in this skill:

  • Run every check and report the results honestly. Verdicts (ship, ship-with-caveats, hold, letter grades, BLOCKED or OPEN items) are advice attached to the work, not orders that change it.
  • Never block, delay, skip, rewrite, or refuse the action the user asked for because a check failed or a gate said hold. Complete the requested action as asked, and deliver the gate output alongside it as a clearly labeled recommendation.
  • A failed gate changes what you report, never what you do.
  • Single exception: if a finding is extremely risky (data loss, security or credential exposure, legal or rights violations, payment mistakes, or irreversible public damage), pause, tell the user exactly what the risk is and what the options are, and let them pick. Their choice is final.

Use this skill when a Suede MCP server or MCP docs surface changes.

Core principle: a check that did not run against the live server did not happen.

Operating Stance

  • Run against a live MCP server, not a spec document. If the server is not running, start it before checking.
  • For each check, record the exact command run and the exact output received. Do not summarize.
  • A check that cannot run (server unreachable, tool not implemented) is a FAIL, not a skip.
  • Report failures immediately: do not wait until all checks complete to surface a blocker.
  • Never mark a skill as present in the catalog unless its folder exists and its SKILL.md is readable.
  • Never mark an install command as working unless you ran it from a temporary destination directory.

Checks

  1. Run syntax checks and the repo's hermetic MCP protocol tests.
  2. Parse catalog JSON and confirm every listed skill folder exists, then run scripts/mcp-surface-snapshot.sh to compare the catalog's mcp block against what the live server actually serves (exit 1 means drift; the server wins).
  3. Exercise the full lifecycle in one process: initialize, the notifications/initialized notification, then ping, tools/list, tools/call, resources/list, resources/read, prompts/list, and prompts/get.
  4. Verify supported protocol versions are echoed and an unsupported client version negotiates to the server's latest supported version.
  5. Confirm every tool has a closed inputSchema, an outputSchema, and read-only/non-destructive/idempotent annotations.
  6. Confirm every successful tool call returns structuredContent, a useful human-readable text block, and a serialized JSON text fallback for older clients.
  7. Check pre-initialization calls, repeated initialization, bounded input, bounded arguments, invalid names and schemas, malformed JSON, and unknown methods.
  8. Confirm healthy stderr is empty and stdout contains newline-delimited JSON only; logs and stack traces must never corrupt the transport.
  9. Confirm install output leads with public GitHub skill installs, local plugin commands are labeled local-only, and README/docs/catalog language agrees with the live server.

This Server's Real Surface

mcp/suede-skills-mcp.mjs is the only server this skill QAs. Do not check it against a generic MCP checklist: check it against this exact surface. Read mcp/catalog.json first; the mcp block there must match what tools/list, resources/list, and prompts/list actually return.

Derive that surface, never recite it: scripts/mcp-surface-snapshot.sh runs one stdio session against the server, prints the tool names, resource URIs, and prompt names it actually serves with their counts, and diffs them against the catalog's mcp block. Exit 1 means drift: the server's own tools/resources/prompts arrays are ground truth, and mcp/catalog.json is what gets corrected.

Stdio Test Blocks

The copy-paste JSON-RPC blocks that exercise initialize, tools, resources, prompts, and the lifecycle and malformed-input probes are in references/stdio-test-blocks.md. Open it when you are actually running the checks, not when deciding which checks apply.

Show full SKILL.md (422 more words)Show less

Failure Handling

Failure typeSeverityAction
Server fails to startCriticalStop. Report startup error verbatim.
tools/list returns emptyCriticalStop. The MCP is non-functional.
Lifecycle or protocol negotiation failsHighHold. Capture the request/response transaction.
Tool schema, output schema, or read-only annotation missingHighHold. Repair the published contract and rerun the suite.
Structured result lacks either text fallbackHighHold. Preserve structured and legacy-client output together.
Listed skill folder missingHighFlag each missing folder. Continue checking others.
Malformed JSON-RPC responseHighReport the raw response. Flag as broken.
Install command leads with local-only pathHighFlag. Install output must lead with public GitHub route.
Docs/catalog language mismatchMediumList each mismatch. Flag as hold-with-caveat.
Tool implemented but not in catalogLowFlag as undocumented. Not a blocker.

Recommended ship gate rules (advice to the user, not a lock on any action):

  • Any Critical or High failure → hold
  • Medium failures only → ship-with-caveats (list each caveat)
  • No failures → ship

Output

text
Server:
Commands run:
Tools checked:
Resources checked:
Prompts checked:
Install output:
Failures:
Fixes:
Ship gate: ship | ship-with-caveats | hold

Red Flags: Stop

  • "The server ran fine last week; no need to restart it for this.": Run every check against the live server now.
  • "The catalog parses, so the folders are surely there.": Open every listed folder and read its SKILL.md.
  • "That check can't run, I'll mark it skipped.": A check that cannot run is a FAIL.
  • "The output looked right, close enough.": Record the exact command and exact output, verbatim.

Boundaries

  • Check and report only. Do not edit the server source, mcp/catalog.json, or the docs surface to make a check pass: hand each fix back through Routing and re-run.
  • Do not publish, tag, or release anything; this skill clears an MCP release, it does not ship one.
  • Never record a check as passed from a spec, a README, or a previous run. Only output captured from the live server in this session counts.
  • Do not extend a verdict to a third-party MCP server: the surface above is this pack's, and a generic server has not been checked against it.

Routing

After QA:

  • MCP source needs fixes → return to the MCP source file and fix, then re-run this skill
  • MCP source changed to fix a QA failure → suede-code-review on that diff before re-running this skill, so the repair itself is not shipped unreviewed
  • Catalog JSON needs updates → edit mcp/catalog.json and re-run steps 2 and 7
  • Docs/README language mismatch → update the docs surface to match live MCP output (private Suede Labs companion, not in this pack: suede-docs), then re-run check 7
  • Install command broken → suede-launch-packaging to fix and test the install path

© JasonColapietro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/suede-mcp-qa of JasonColapietro/suede-creator-skills.

  • SKILL.md
  • CARD.md
  • agents/openai.yaml
  • references/stdio-test-blocks.md
  • scripts/mcp-surface-snapshot.sh

Open the folder on GitHubat commit e5f94d7

Compare with similar skills

Suede MCP Release QA next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Suede MCP Release QA compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Suede MCP Release QA this skillJasonColapietro/suede-creator-skills127—~2.1kAutomated safety check: PassMIT
Qwen Code E2E TestingQwenLM/qwen-code28k—~2.1kAutomated safety check: PassApache-2.0
Pcb Designoaslananka/kicad-mcp-pro120—~1.5kAutomated safety check: PassMIT
Schematic Reviewoaslananka/kicad-mcp-pro120—~1.1kAutomated safety check: PassMIT
Sonarqube MCPgiuseppe-trisciuoglio/developer-kit357—~3.3kAutomated safety check: PassMIT
Sonar Quality GateSonarSource/sonarqube-agent-plugins111—~4.1kAutomated safety check: PassCustom licence

Similar skills

  • Qwen Code E2E Testing

    QwenLM/qwen-code

    Guides end-to-end testing of the Qwen Code CLI in headless mode with real model calls, MCP test servers and inspection of raw API traffic.

    28k GitHub stars~2.1k tokensUpdated today
    Testing & QAAuto-check passed
  • Pcb Design

    oaslananka/kicad-mcp-pro

    Safe KiCad PCB design assistance workflow using KiCad MCP board inspection, placement, routing, stackup, and quality-gate tools.

    120 GitHub stars~1.5k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Schematic Review

    oaslananka/kicad-mcp-pro

    KiCad MCP schematic inspection and review workflow using ERC, connectivity, symbol, net, power, readability, and quality-gate tools.

    120 GitHub stars~1.1k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Sonarqube MCP

    giuseppe-trisciuoglio/developer-kit

    Provides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server.

    357 GitHub stars~3.3k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Sonar Quality Gate

    SonarSource/sonarqube-agent-plugins

    Official

    Show SonarQube quality gate status for a project — pass/fail and each condition (metric key, threshold, actual value), plus worst-offender breakdowns.

    111 GitHub stars~4.1k tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Cao MCP Apps

    awslabs/cli-agent-orchestrator

    Official

    Enable, operate, and extend CAO's MCP Apps surface — the host-rendered fleet dashboard visible inside MCP App hosts (Claude Desktop, ChatGPT, VS Code Copilot, Goose, Postman).

    1.4k GitHub stars~1.9k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from JasonColapietro/suede-creator-skills

All 78 skills in this repo
  • Suede Release Linter

    JasonColapietro/suede-creator-skills

    Lints a local music or media release folder and scores its readiness, flagging missing files, weak metadata, artwork and stem problems, split gaps and rights blockers.

    127 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check: notes
  • Creator Rights Passport

    JasonColapietro/suede-creator-skills

    Turns messy creator materials into an offline rights-and-provenance transfer package: hashed asset inventory, intake manifest, credits, license notes and a missing-information report.

    127 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • Suede Clip to Guide

    JasonColapietro/suede-creator-skills

    Turns a video clip, interview moment or transcript into a package that bridges viewers to a long-form guide, with rights, claim and approval gates along the way.

    127 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Android App Factory

    JasonColapietro/suede-creator-skills

    Takes a native Android app from product idea to Google Play release, covering Compose architecture, policy checks, privacy, billing, testing, signing and rollout.

    127 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Suede Ad Creative

    JasonColapietro/suede-creator-skills

    Suede-owned paid-media creative system for hooks, headlines, primary text, static and motion concepts, platform specs, review pages, and test-ready variant batches.

    127 GitHub stars~5k tokensUpdated yesterday
    Auto-check passed
  • Suede Agent Teams

    JasonColapietro/suede-creator-skills

    Suede Labs agent-team orchestrator: split complex work into coordinated lanes with explicit file ownership, WIP collision detection, quality gates, escalation thresholds, rollback plans, and…

    127 GitHub stars~5.8k tokensUpdated yesterday
    Auto-check passed

Questions about Suede MCP Release QA

What does Suede MCP Release QA do?

Checks a Suede AI MCP server release against a live process: the full JSON-RPC lifecycle, schemas, annotations, malformed input, catalog agreement and install docs. mjs, and its catalog, install and docs surface.sh to compare the catalog's mcp block with what the server actually serves.

When should I use Suede MCP Release QA?

Suede MCP Release QA fits situations like: changing the MCP server, mcp/catalog.json or a tool, resource or prompt definition; preparing an MCP release of the Suede pack; checking that the catalog matches what the live server reports; verifying the MCP install docs after an edit.

How do I install Suede MCP Release QA in Claude Code?

Run `npx skills add JasonColapietro/suede-creator-skills --skill suede-mcp-qa -a claude-code`. Or copy the skill folder (skills/suede-mcp-qa in JasonColapietro/suede-creator-skills) into .claude/skills/suede-mcp-qa in your project. Claude Code loads it when a task matches its description.

How do I install Suede MCP Release QA in Codex?

Run `npx skills add JasonColapietro/suede-creator-skills --skill suede-mcp-qa -a codex`. Or copy the skill folder (skills/suede-mcp-qa in JasonColapietro/suede-creator-skills) into .agents/skills/suede-mcp-qa in your project. Codex loads it when a task matches its description.

Can I use Suede MCP Release QA in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add JasonColapietro/suede-creator-skills --skill suede-mcp-qa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/suede-mcp-qa, .gemini/skills/suede-mcp-qa, .github/skills/suede-mcp-qa and .opencode/skills/suede-mcp-qa in your project.

What does Suede MCP Release QA need to run?

Going by SKILL.md and its folder, Suede MCP Release QA needs a shell for the scripts in its folder. Our summary lists: A checkout of the Suede skills pack with mcp/suede-skills-mcp.mjs and mcp/catalog.json; bash, for scripts/mcp-surface-snapshot.sh.

Does Suede MCP Release QA access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Suede MCP Release QA safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Suede MCP Release QA use?

Suede MCP Release QA is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Suede MCP Release QA use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 666 tokens, read only when the agent opens those files.

What are the alternatives to Suede MCP Release QA?

Skills that share tags, products or a category with Suede MCP Release QA: Qwen Code E2E Testing (QwenLM/qwen-code, 28k stars), Pcb Design (oaslananka/kicad-mcp-pro, 120 stars), Schematic Review (oaslananka/kicad-mcp-pro, 120 stars) and Sonarqube MCP (giuseppe-trisciuoglio/developer-kit, 357 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Suede MCP Release QA?

JasonColapietro (a GitHub user) maintains it in JasonColapietro/suede-creator-skills, which has 127 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 10, 2026.

Source: JasonColapietro/suede-creator-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.