Agent skill

MCP Server Spec

by mohitagw15856 in mohitagw15856/pm-claude-skills

Design an MCP server for a product — the tool surface, auth model, and safety boundaries that make it genuinely usable by AI agents.

MITAuto-check passedAgent Workflows

Install MCP Server Spec

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill mcp-server-spec -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills mcp-server-spec --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mcp-server-spec .claude/skills/mcp-server-spec && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mcp-server-spec
GitHub stars
1.4k
Token cost
~1.4k tokens
SKILL.md length
741 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Design an MCP server for a product — the tool surface, auth model, and safety boundaries that make it genuinely usable by AI agents.

  • Works in 7 steps: Start from agent tasks, not endpoints.… → Keep the toolset small. Every tool… → Write descriptions as routing surfaces.… → …
  • Asked to spec an MCP server
  • SKILL.md covers What This Skill Produces, Required Inputs, Design Method and Output Format, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

MCP Server Spec is an agent skill from mohitagw15856/pm-claude-skills. Design an MCP server for a product — the tool surface, auth model, and safety boundaries that make it genuinely usable by AI agents. Use when asked to spec an MCP server, expose a product to agents, design tools for Claude or other MCP clients, or review why an existing MCP server performs badly. Produces a complete server spec: a small task-shaped toolset with agent-tested descriptions, auth and scoping decisions, error design, and an explicit not-exposed list.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked to spec an MCP server
  • Expose a product to agents
  • Design tools for Claude
  • Other MCP clients

Example prompts

  • “/mcp-server-spec”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Start from agent tasks, not endpoints. List the 5-8 things an agent will actually be asked to do with this product ("file an expense"…
  2. Keep the toolset small. Every tool dilutes selection accuracy on every call. Target ≤10; past ~15, split into separately-loadable servers…
  3. Write descriptions as routing surfaces. The description is all the model sees when choosing. Formula per tool: what it does (one clause) ·…
  4. Design returns for context windows. Return the 6 fields an agent needs, not the 60 the API has; include stable IDs for chaining; paginate…
  5. Make errors instructive. An agent retries what it understands: "date must be YYYY-MM-DD" beats 400 Bad Request. Every error names the…
  6. Draw the safety boundary. Classify every capability: expose (read/create, low blast radius) · expose gated (destructive/outward-facing…
  7. Specify auth honestly. OAuth per end user (agent acts as the user, inherits their permissions) vs API key (service account — then per-tool…

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

MCP Server Spec loads about 1.4k tokens when it runs. Until then it costs about 121 tokens; SKILL.md has 741 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~121
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 741 words, ~1,396 tokens.

Download SKILL.mdSave it as .claude/skills/mcp-server-spec/SKILL.md (or your agent's skills folder).
name
mcp-server-spec
description
Design an MCP server for a product — the tool surface, auth model, and safety boundaries that make it genuinely usable by AI agents. Use when asked to spec an MCP server, expose a product to agents, design tools for Claude or other MCP clients, or review why an existing MCP server performs badly. Produces a complete server spec: a small task-shaped toolset with agent-tested descriptions, auth and scoping decisions, error design, and an explicit not-exposed list.

MCP Server Spec Skill

Every SaaS is shipping an MCP server; most dump their REST API as forty tools and wonder why agents flail. This skill designs the server as what it actually is: a user interface for a non-human user — few tools, task-shaped, with descriptions written for a model deciding under uncertainty.

What This Skill Produces

  • A toolset design: 3-10 tools mapped to agent tasks, not API endpoints
  • Per-tool specs: name, description (the routing surface), parameters, returns, error behaviour
  • Auth & scoping decisions: how credentials flow, what a token can never do
  • An explicit not-exposed list with reasons — the most load-bearing section
  • A test plan: the agent-eval loop that proves the toolset works

Required Inputs

Ask for (if not already provided):

  • The product and what users hire it for (the top 5 jobs, not the feature list)
  • The existing API surface (endpoints or capability list) if one exists
  • Who the agent acts for — the end user's own account? a service account? multi-tenant?
  • The riskiest actions the product supports (deletes, sends, payments, permission changes)

Design Method

  1. Start from agent tasks, not endpoints. List the 5-8 things an agent will actually be asked to do with this product ("file an expense", "find last quarter's report", "summarise ticket history"). Each becomes one tool — even if it spans four API calls internally. An endpoint-mirrored toolset makes the agent do your orchestration; a task-shaped one does it for them.
  2. Keep the toolset small. Every tool dilutes selection accuracy on every call. Target ≤10; past ~15, split into separately-loadable servers by workflow. Merge list/get/search variants behind one tool with parameters where natural.
  3. Write descriptions as routing surfaces. The description is all the model sees when choosing. Formula per tool: what it does (one clause) · when to use it and when to use the sibling tool instead · what it returns. Test: could a model pick correctly between your two closest tools from descriptions alone?
  4. Design returns for context windows. Return the 6 fields an agent needs, not the 60 the API has; include stable IDs for chaining; paginate with explicit has_more; keep any response under ~2k tokens by default with an opt-in for detail.
  5. Make errors instructive. An agent retries what it understands: "date must be YYYY-MM-DD" beats 400 Bad Request. Every error names the parameter at fault and the fix.
  6. Draw the safety boundary. Classify every capability: expose (read/create, low blast radius) · expose gated (destructive/outward-facing — require an explicit confirmation parameter and document that clients should surface approval) · never expose (auth changes, deletes without recovery, bulk exports of other users' data). The never-list ships in the spec with reasons.
  7. Specify auth honestly. OAuth per end user (agent acts as the user, inherits their permissions) vs API key (service account — then per-tool scoping matters more). State token lifetime, revocation, and what happens mid-session on expiry.
Show full SKILL.md (267 more words)Show less

Output Format

MCP Server Spec: [product]

Agent jobs served: [the 5-8 tasks] · Tool count: [n] · Auth: [model + scoping]

Tools

ToolDescription (as shipped)Key paramsReturnsRisk class

Gated actions: [which tools require confirmation params, and the expected client behaviour]

Never exposed: [capability → reason] (one line each; this list is reviewed like an API contract)

Error design: [the error shape + 3 example messages]

Test plan: [10-15 realistic agent prompts spanning the jobs; run against a real client; a tool whose description gets misselected twice gets rewritten, not documented around]

Quality Checks

  • Every tool maps to an agent task; no tool exists because "the endpoint was there"
  • Any two sibling tools are distinguishable from their descriptions alone
  • Default responses fit comfortably in a context window (≤~2k tokens)
  • Every destructive or outward-facing action is gated or on the never-list
  • Errors name the offending parameter and the fix
  • The spec includes the agent-eval test plan, not just the schema

Anti-Patterns

  • Do not mirror the REST API — 40 endpoint-tools is the #1 way MCP servers fail
  • Do not write descriptions for developers ("wraps the /v2/items endpoint") — write them for a model choosing a tool
  • Do not return full API payloads — context windows are the scarce resource
  • Do not expose destructive actions ungated because "the client will be careful"
  • Do not skip the never-exposed list — an MCP server without one hasn't been threat-modelled
  • Do not ship without running the agent test plan — schema-valid and agent-usable are different properties

Example Trigger Phrases

  • "Spec an MCP server."
  • "Expose a product to agents."
  • "Design tools for Claude."
  • "Review why an existing MCP server performs badly."

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/mcp-server-spec of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

MCP Server Spec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

MCP Server Spec compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
MCP Server Spec this skillmohitagw15856/pm-claude-skills1.4k—~1.4kAutomated safety check: PassMIT
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Context Mode Output Sandboxmksglu/context-mode26k—~4.1kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    Agent WorkflowsAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about MCP Server Spec

What does MCP Server Spec do?

Design an MCP server for a product — the tool surface, auth model, and safety boundaries that make it genuinely usable by AI agents. MCP Server Spec is an agent skill from mohitagw15856/pm-claude-skills. Design an MCP server for a product — the tool surface, auth model, and safety boundaries that make it genuinely usable by AI agents.

When should I use MCP Server Spec?

MCP Server Spec fits situations like: asked to spec an MCP server; expose a product to agents; design tools for Claude; other MCP clients.

How do I install MCP Server Spec in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill mcp-server-spec -a claude-code`. Or copy the skill folder (skills/mcp-server-spec in mohitagw15856/pm-claude-skills) into .claude/skills/mcp-server-spec in your project. Claude Code loads it when a task matches its description.

How do I install MCP Server Spec in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill mcp-server-spec -a codex`. Or copy the skill folder (skills/mcp-server-spec in mohitagw15856/pm-claude-skills) into .agents/skills/mcp-server-spec in your project. Codex loads it when a task matches its description.

Can I use MCP Server Spec in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill mcp-server-spec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-server-spec, .gemini/skills/mcp-server-spec, .github/skills/mcp-server-spec and .opencode/skills/mcp-server-spec in your project.

What does MCP Server Spec need to run?

SKILL.md names no scripts, command-line tools or credentials: MCP Server Spec is instructions for the agent only.

Does MCP Server Spec access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is MCP Server Spec safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does MCP Server Spec use?

MCP Server Spec is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does MCP Server Spec use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to MCP Server Spec?

Skills that share tags, products or a category with MCP Server Spec: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Crush Configuration (charmbracelet/crush, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains MCP Server Spec?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.