Agent skill

Readonly MCP Wrapper

by mohitagw15856 in mohitagw15856/pm-claude-skills

A skill your agent uses when asked to expose a folder of notes or docs to Claude or another AI client, build an MCP server over Markdown or JSON files, let an agent read my knowledge base safely, or…

MITAuto-check: notesAgent Workflows

Install Readonly MCP Wrapper

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill readonly-mcp-wrapper -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills readonly-mcp-wrapper --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/readonly-mcp-wrapper .claude/skills/readonly-mcp-wrapper && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
readonly-mcp-wrapper
GitHub stars
1.4k
Token cost
~1.3k tokens
SKILL.md length
650 words
Files
2 (incl. references)
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when asked to expose a folder of notes or docs to Claude or another AI client, build an MCP server over Markdown or JSON files, let an agent read my knowledge base safely, or…

  • Works in 5 steps: Server code → Tool definitions → Client configuration → …
  • Asked to expose a folder of notes
  • SKILL.md covers Required Inputs, Output Structure, Quality Checks and Anti-Patterns, plus 1 more section
  • Runs JavaScript scripts from its folder; calls claude

What it does

Readonly MCP Wrapper is an agent skill from mohitagw15856/pm-claude-skills. Use when asked to expose a folder of notes or docs to Claude or another AI client, build an MCP server over Markdown or JSON files, let an agent read my knowledge base safely, or wrap documentation as MCP tools. Produces a read-only MCP server over a folder of Markdown or JSON files: server code using stdio transport, tool definitions, a client configuration snippet, and a safety section confirming no write, delete or network tools are exposed. To design an MCP server for a whole product, use mcp-server-spec.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files.

It sits in Agent Workflows, covering MCP servers and Structured output and tool calling. It works with Model Context Protocol. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked to expose a folder of notes
  • Another AI client
  • Build an MCP server over Markdown
  • Let an agent read my knowledge base safely

Example prompts

  • “/readonly-mcp-wrapper”

Requirements

  • Python 3
  • Node.js

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Server code
  2. Tool definitions
  3. Client configuration
  4. Safety section
  5. Test script

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Readonly MCP Wrapper loads about 1.3k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 134 tokens; SKILL.md has 650 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~134
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:76
    lder.** Allow-list file types; keys and `.env` files live in the same trees as docs.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 650 words, ~1,266 tokens.

Download SKILL.mdSave it as .claude/skills/readonly-mcp-wrapper/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
readonly-mcp-wrapper
description
Use when asked to expose a folder of notes or docs to Claude or another AI client, build an MCP server over Markdown or JSON files, let an agent read my knowledge base safely, or wrap documentation as MCP tools. Produces a read-only MCP server over a folder of Markdown or JSON files: server code using stdio transport, tool definitions, a client configuration snippet, and a safety section confirming no write, delete or network tools are exposed. To design an MCP server for a whole product, use mcp-server-spec.
version
1.0.0

Read-only MCP Wrapper

The fastest way to give an AI assistant a project's knowledge (docs, notes, specs, exported data) is a small MCP server that can list, search and read files, and can do nothing else. Most hand-rolled servers drift into risk: a "helpful" write tool, a path that escapes the folder through .. or a symlink, or logs printed to stdout that corrupt the protocol. This skill generates a server that is read-only by construction, from the tested template in references/server-template.mjs.

Required Inputs

Ask for these if not provided:

  • The folder to serve, and roughly how many files and how large
  • File types: Markdown, JSON, or both (other types are excluded by default)
  • The client: Claude Code, Claude Desktop, Cursor, or another MCP client
  • Runtime: Node is the default; ask if the user needs Python instead
  • Anything inside the folder that must never be served (drafts, private notes), to exclude by path

Output Structure

1. Server code

A complete file based on references/server-template.mjs, adapted to the inputs:

  • stdio transport: newline-delimited JSON-RPC 2.0 on stdin and stdout; all logging on stderr
  • handles initialize, ping, tools/list and tools/call; ignores notifications; returns -32601 for anything else
  • the served root resolved once with realpath; every requested path resolved and checked to stay inside it, so .. and symlinks cannot escape
  • an allow-list of extensions and a per-file size cap
  • exclusions from the inputs applied in the file walk
2. Tool definitions

A table and the JSON schemas:

ToolInputReturnsRead-only hint
list_documentsnonerelative pathstrue
search_documentsquery (2+ characters), optional limit up to 50path and excerpt per matchtrue
read_documentpath from list_documentsfull texttrue

Errors are returned as tool results with isError: true and a message that never includes the absolute path.

3. Client configuration

The exact snippet for the named client, with an absolute path placeholder, for example for Claude Code:

bash
claude mcp add my-docs -- node /absolute/path/server.mjs /absolute/path/to/folder

and the mcpServers JSON block for Claude Desktop or Cursor.

4. Safety section

A short statement the user can paste into their README, confirming:

  • the server exposes exactly three tools, all read-only
  • there is no code that writes, deletes, renames or moves files
  • there is no network code: no HTTP client, no sockets, no child processes
  • paths cannot escape the served folder, including through symlinks
  • only allow-listed file types under the size cap are returned

Then the commands that prove it: a grep over the server for write, delete, network and process APIs that should return nothing, and the test below.

Show full SKILL.md (237 more words)Show less
5. Test script

Piped JSON-RPC requests that check: initialize succeeds; the three tools are listed; a document can be listed, searched and read; ../ traversal is refused; a symlink pointing outside is refused; a disallowed extension is refused; an unknown tool returns an error.

Quality Checks

  • Exactly three tools are exposed, each with readOnlyHint: true
  • The server contains no write, delete, rename, network or child-process calls
  • Nothing but protocol messages is written to stdout
  • Traversal with .. and symlinks pointing outside the folder are both refused
  • Only allow-listed extensions under the size cap are served
  • Error messages never reveal the absolute path of the served folder
  • The client snippet uses absolute paths and the exact command for the named client
  • The test script covers every refusal case listed above

Anti-Patterns

  • "Just one write tool." The moment an agent can write, the safety story changes; build a separate server for that.
  • console.log for debugging. It corrupts the stdio protocol; log to stderr.
  • Checking paths with string prefixes only. startsWith(root) without realpath lets symlinks escape.
  • Serving everything in the folder. Allow-list file types; keys and .env files live in the same trees as docs.

Example Trigger Phrases

  • "Make an MCP server so Claude can read my Obsidian notes, read-only."
  • "Expose this docs folder to Cursor as MCP tools."
  • "Build a safe MCP server over a folder of JSON files."
  • "I want my agent to search our specs but never change them."

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/readonly-mcp-wrapper of mohitagw15856/pm-claude-skills.

  • SKILL.md
  • references/server-template.mjs

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Readonly MCP Wrapper next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Readonly MCP Wrapper compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Readonly MCP Wrapper this skillmohitagw15856/pm-claude-skills1.4k—~1.3kAutomated safety check: NotesMIT
MCP Server Builder with mcp-usemcp-use/mcp-use11k—~923Automated safety check: PassApache-2.0
Documentation Serverandrea9293/mcp-documentation-server343—~2.3kAutomated safety check: PassMIT
MCP Auditgetsentry/toolkit918—~1.5kAutomated safety check: PassCustom licence
MCP Server Builderborghei/Claude-Skills886—~1.9kAutomated safety check: PassMIT
Spring AI MCP Server Patternsgiuseppe-trisciuoglio/developer-kit356—~2.7kAutomated safety check: NotesMIT

Similar skills

  • Builds, modifies, debugs, migrates and verifies TypeScript MCP servers and MCP Apps with the mcp-use framework, treating the installed package's types as the source of truth.

    11k GitHub stars~923 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Documentation Server

    andrea9293/mcp-documentation-server

    A skill your agent uses when you need to store, retrieve, search, or manage documents in a local knowledge base with semantic search and hybrid (vector + full-text) retrieval.

    343 GitHub stars~2.3k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • MCP Audit

    getsentry/toolkit

    Official

    Audit MCP servers for protocol compliance, metadata drift, and compatibility regressions.

    918 GitHub stars~1.5k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    borghei/Claude-Skills

    Build MCP (Model Context Protocol) servers with tool definitions, resource providers, prompt templates, and transports.

    886 GitHub stars~1.9k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Spring AI MCP Server Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides Spring Boot MCP server patterns that create Model Context Protocol servers with Spring AI by defining tool handlers, exposing resources, configuring prompt templates, and setting up…

    356 GitHub stars~2.7k tokensUpdated 29 days ago
    Agent WorkflowsAuto-check: notes
  • Agent Tool Builder

    omer-metin/skills-for-antigravity

    Tools are how AI agents interact with the world. An agent skill from omer-metin/skills-for-antigravity.

    162 GitHub stars~705 tokensUpdated 8 mo ago
    AI & LLM EngineeringAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Readonly MCP Wrapper

What does Readonly MCP Wrapper do?

A skill your agent uses when asked to expose a folder of notes or docs to Claude or another AI client, build an MCP server over Markdown or JSON files, let an agent read my knowledge base safely, or…. Readonly MCP Wrapper is an agent skill from mohitagw15856/pm-claude-skills. Use when asked to expose a folder of notes or docs to Claude or another AI client, build an MCP server over Markdown or JSON files, let an agent read my knowledge base safely, or wrap documentation as MCP tools.

When should I use Readonly MCP Wrapper?

Readonly MCP Wrapper fits situations like: asked to expose a folder of notes; another AI client; build an MCP server over Markdown; let an agent read my knowledge base safely.

How do I install Readonly MCP Wrapper in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill readonly-mcp-wrapper -a claude-code`. Or copy the skill folder (skills/readonly-mcp-wrapper in mohitagw15856/pm-claude-skills) into .claude/skills/readonly-mcp-wrapper in your project. Claude Code loads it when a task matches its description.

How do I install Readonly MCP Wrapper in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill readonly-mcp-wrapper -a codex`. Or copy the skill folder (skills/readonly-mcp-wrapper in mohitagw15856/pm-claude-skills) into .agents/skills/readonly-mcp-wrapper in your project. Codex loads it when a task matches its description.

Can I use Readonly MCP Wrapper in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill readonly-mcp-wrapper -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/readonly-mcp-wrapper, .gemini/skills/readonly-mcp-wrapper, .github/skills/readonly-mcp-wrapper and .opencode/skills/readonly-mcp-wrapper in your project.

What does Readonly MCP Wrapper need to run?

Going by SKILL.md and its folder, Readonly MCP Wrapper needs JavaScript for the scripts in its folder and the command-line tools its instructions call (claude). Our summary lists: Python 3; Node.js.

Does Readonly MCP Wrapper access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Readonly MCP Wrapper safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Readonly MCP Wrapper use?

Readonly MCP Wrapper is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Readonly MCP Wrapper use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Readonly MCP Wrapper?

Skills that share tags, products or a category with Readonly MCP Wrapper: MCP Server Builder with mcp-use (mcp-use/mcp-use, 11k stars), Documentation Server (andrea9293/mcp-documentation-server, 343 stars), MCP Audit (getsentry/toolkit, 918 stars) and MCP Server Builder (borghei/Claude-Skills, 886 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Readonly MCP Wrapper?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,433 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 8, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.