MCP Server Builder
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
Design, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests.
$ npx skills add seb1n/awesome-ai-agent-skills --skill mcp-server-building -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills mcp-server-building --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-engineering/mcp-server-building .claude/skills/mcp-server-building && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "mcp-server-building" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-engineering/mcp-server-building into .claude/skills/mcp-server-building/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-server-building", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-engineering/mcp-server-buildingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add seb1n/awesome-ai-agent-skills --skill mcp-server-building -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills mcp-server-building --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agent-engineering/mcp-server-building .agents/skills/mcp-server-building && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "mcp-server-building" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-engineering/mcp-server-building into .agents/skills/mcp-server-building/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-server-building", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add seb1n/awesome-ai-agent-skills --skill mcp-server-building -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills mcp-server-building --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agent-engineering/mcp-server-building .cursor/skills/mcp-server-building && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "mcp-server-building" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-engineering/mcp-server-building into .cursor/skills/mcp-server-building/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-server-building", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/seb1n/awesome-ai-agent-skills.git --path agent-engineering/mcp-server-building--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add seb1n/awesome-ai-agent-skills --skill mcp-server-building -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills mcp-server-building --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agent-engineering/mcp-server-building .gemini/skills/mcp-server-building && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "mcp-server-building" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-engineering/mcp-server-building into .gemini/skills/mcp-server-building/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-server-building", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install seb1n/awesome-ai-agent-skills mcp-server-buildingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add seb1n/awesome-ai-agent-skills --skill mcp-server-building -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/agent-engineering/mcp-server-building .github/skills/mcp-server-building && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "mcp-server-building" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-engineering/mcp-server-building into .github/skills/mcp-server-building/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-server-building", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add seb1n/awesome-ai-agent-skills --skill mcp-server-building -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills mcp-server-building --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agent-engineering/mcp-server-building .opencode/skills/mcp-server-building && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "mcp-server-building" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-engineering/mcp-server-building into .opencode/skills/mcp-server-building/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-server-building", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
mcp-server-buildingDesign, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests.
MCP Server Building is an agent skill from seb1n/awesome-ai-agent-skills. Design, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests. Use when creating a new MCP server, exposing an API or data source through MCP, reviewing an MCP server design, adding or revising MCP tools, or preparing an MCP server for production.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts, reference files and assets (for example `agents/openai.yaml`, `assets/server-design-template.md` and `references/server-design-checklist.md`).
It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: 103 ready-to-use AI agent skills for Claude Code, OpenAI Codex, Gemini CLI, Cursor, GitHub Copilot, Windsurf, and other Agent Skills-compatible tools. Complete SKILL.md… The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 75865a5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
MCP Server Building loads about 2.5k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 101 tokens; SKILL.md has 1,205 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from seb1n/awesome-ai-agent-skills at commit 75865a5, republished under its MIT licence (© seb1n). 1,205 words, ~2,481 tokens.
.claude/skills/mcp-server-building/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Build the smallest server that exposes the required capability safely. Treat protocol conformance, business authorization, and model behavior as separate concerns; all three need independent controls.
Collect or infer, and label assumptions for, these inputs:
stdio or remote HTTP transport requirementsAsk only for missing facts that materially change the architecture. Consult the current MCP specification and SDK documentation before relying on version-sensitive behavior.
Deliver:
Use assets/server-design-template.md when a design artifact is useful. Use scripts/validate_tool_manifest.py to lint a JSON tool manifest before implementation or review.
Translate the user job into a narrow set of resources, prompts, and tools. Prefer one clear operation per tool. Exclude administrative or broad pass-through operations unless the use case requires them.
Identify every effect; a tool can have more than one. Record reads, creates, updates, deletes, execution, external communication, financial transactions, access changes, and network egress separately. Classify every data flow, including public, internal, confidential, restricted, personal, financial, health, and credential data. Do not compress this inventory into a single "read" or "write" label.
Draw the path from MCP host to server to downstream service. State which component authenticates the actor, which authorizes the operation, where credentials live, and which data is untrusted.
Do not rely on the model, the tool description, or a client-side confirmation as the sole authorization control. Enforce object-, tenant-, and action-level authorization at the server or downstream service.
outputSchema and return matching structuredContent; do not substitute a prose description of the result shape.Read references/server-design-checklist.md for contract, transport, and test details.
Use an official or well-maintained SDK compatible with the selected protocol revision. For new work, verify the current stable revision before coding; as of 2026-08-09 it is 2026-07-28. That revision is stateless at the protocol layer: implement server/discover, carry version/client capabilities in per-request _meta, include required routing headers for Streamable HTTP, and do not introduce initialize, notifications/initialized, or Mcp-Session-Id. Support a legacy handshake only on an explicitly tested older-revision compatibility path.
Return the required resultType on every result. Implement input_required plus retry-bound inputResponses/requestState for Multi Round-Trip Requests when mid-call input is needed. Return deterministic, cacheable listings with revision-required cache metadata.
Apply deadlines, bounded concurrency, safe retries with jitter, connection cleanup, and structured logging. Emit correlation IDs and outcome metadata without logging tokens, secrets, full prompts, or sensitive records.
Declare an authorization mode for every tool, including an explicit public mode for genuinely unauthenticated tools. For local stdio, source credentials from an approved environment or secret store; never embed them in arguments, source, or logs. For remote HTTP, follow the current MCP authorization specification, HTTPS requirements, exact redirect and issuer validation, token audience validation, short-lived credentials, and least-privilege scopes.
Never pass an MCP client token unchanged to an upstream API. Obtain a separate downstream token with the correct audience. Bind approvals to the exact action and parameters for consequential tools.
Run all of the following that apply:
validate_tool_manifest.py; treat warnings as review prompts and never present a passing lint as protocol conformance or safety certification2026-07-28: server/discover, per-request protocol/client metadata, required Streamable HTTP header/body agreement, listing, invocation, resultType, cancellation, and unsupported-version handling with a compatible clientttlMs and cacheScope on cacheable list/read results, and input_required retry behavior when MRTR is usedReport observed evidence. Do not claim compatibility with clients or protocol versions that were not exercised.
Release behind a feature flag or allowlist when possible. Define health checks, latency/error metrics, audit events, and alert thresholds. Preserve a last-known-good configuration and reversible migration path.
If unsafe behavior appears, disable the affected tool, stop the server if necessary, revoke or rotate credentials, preserve redacted evidence, restore the previous version, and retest before re-enabling access.
Expose inventory-search-items and inventory-get-stock for a support agent. Restrict store IDs to the actor's assigned region, cap search results, redact supplier costs, and verify that a wrong-region object returns a generic forbidden error. Deliver a manifest, implementation, inspector transcript, and negative authorization tests.
Expose support-draft-ticket-update separately from support-apply-ticket-update. Make the apply tool require a short-lived approval bound to ticket ID, proposed patch hash, and actor. Add idempotency handling, an audit event, a timeout test, and a rollback path for the deployment.
Finish only when names and structural schemas match implementation, all effect and data classes are explicit, every tool declares an authorization mode, every consequential effect has a deterministic authority check, current-revision and any legacy paths have been exercised separately, evidence is recorded, and unverified assumptions plus residual risks are explicit.
© seb1n, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in agent-engineering/mcp-server-building of seb1n/awesome-ai-agent-skills.
Open the folder on GitHubat commit 75865a5
MCP Server Building next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| MCP Server Building this skillseb1n/awesome-ai-agent-skills | 206 | — | ~2.5k | Automated safety check: Pass | MIT | |
| MCP Server Builderanthropics/skills | 180k | 63 repos | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| MCP Server BuildershareAI-lab/learn-claude-code | 78k | 5 repos | ~1.2k | Automated safety check: Pass | MIT | |
| MCP Integration for Pluginsanthropics/claude-plugins-official | 38k | 11 repos | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Crush Configurationcharmbracelet/crush | 29k | — | ~3.7k | Automated safety check: Pass | Custom licence | |
| Context Mode Output Sandboxmksglu/context-mode | 26k | — | ~4.1k | Automated safety check: Pass | Custom licence |
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
shareAI-lab/learn-claude-code
Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.
anthropics/claude-plugins-official
Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.
charmbracelet/crush
Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.
mksglu/context-mode
Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.
warpdotdev/warp
Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.
seb1n/awesome-ai-agent-skills
Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings.
seb1n/awesome-ai-agent-skills
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…
seb1n/awesome-ai-agent-skills
Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows.
seb1n/awesome-ai-agent-skills
Inspect, extract, OCR, create, merge, split, reorder, rotate, annotate, fill, redact, compress, secure, and verify PDF documents while preserving source files and visual fidelity.
seb1n/awesome-ai-agent-skills
Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk.
seb1n/awesome-ai-agent-skills
Inspect, profile, clean, reconcile, analyze, visualize, and verify spreadsheet data while preserving formulas, formatting, types, and source files.
Works with
Categories
Design, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests. MCP Server Building is an agent skill from seb1n/awesome-ai-agent-skills. Design, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests.
MCP Server Building fits situations like: creating a new MCP server; exposing an API; data source through MCP; reviewing an MCP server design.
Run `npx skills add seb1n/awesome-ai-agent-skills --skill mcp-server-building -a claude-code`. Or copy the skill folder (agent-engineering/mcp-server-building in seb1n/awesome-ai-agent-skills) into .claude/skills/mcp-server-building in your project. Claude Code loads it when a task matches its description.
Run `npx skills add seb1n/awesome-ai-agent-skills --skill mcp-server-building -a codex`. Or copy the skill folder (agent-engineering/mcp-server-building in seb1n/awesome-ai-agent-skills) into .agents/skills/mcp-server-building in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add seb1n/awesome-ai-agent-skills --skill mcp-server-building -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-server-building, .gemini/skills/mcp-server-building, .github/skills/mcp-server-building and .opencode/skills/mcp-server-building in your project.
Going by SKILL.md and its folder, MCP Server Building needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
MCP Server Building is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with MCP Server Building: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Crush Configuration (charmbracelet/crush, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
seb1n (a GitHub user) maintains it in seb1n/awesome-ai-agent-skills, which has 206 GitHub stars. The repository holds 101 skills in this directory. The repository was last updated on August 9, 2026.
Source: seb1n/awesome-ai-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.