Claude PromptsBLOCK
MCP server for reusable prompt templates, multi-step workflow chains, and quality gates. Compose agentic workflows with an operator syntax; export as native skills to Claude Code, Cursor, OpenCode, and Gemini CLI.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Claude Prompts
The portable workflow layer beside your AI coding harness.
Your client executes with its own tools, agents, and context. Claude Prompts adds reusable prompt resources, composable chains, validation gates, and client-native skill export.
Quick Start · What You Get · Compose Workflows · Run Anywhere · Docs
What your AI client gives you — and what this server adds
1852bc931df4OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add claude-prompts -- npx -y [email protected]
Exposed tools (120)
116 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Analysis | read | Analytical prompts |
Analytical | read | Structured style |
Analyze | read | Understand the problem |
Analyzer | read | Analyzes content |
Authoring | read | |
BADEXIT | read | Invalid exit argument |
CAGEERF | read | Context-Analysis-Goals framework |
Clobber | read | should not land either |
Converter | read | Converts data |
Demo | read | |
Design | read | Plan the solution |
Docs | read | Ensure documentation |
Draft | read | Draft from prior work |
Escaped | read | Should never be written |
Formatter | read | Formats content |
G1 | read | D |
General | read | General prompts |
Implement | read | Build the solution |
Inline | read | |
Minimal | read | A minimal gate |
NOPERM | read | Command not executable (check permissions) |
NOTFOUND | read | Command not found (check PATH or spelling) |
One | read | first |
P1 | read | only phase |
Plain | read | second step |
Plan | read | Lay out the steps |
Preview | read | Preview test |
Probe | read | The only phase |
Prompt | read | desc |
ReACT | read | Test |
Research | read | Research a topic |
Review | write | Review the whole run |
SCAMPER | read | Creative framework |
SIGABRT | read | Abort |
SIGALRM | read | Alarm |
SIGFPE | read | Floating-point exception |
SIGHUP | read | Hangup |
SIGILL | read | Illegal instruction |
SIGINT | read | Interrupt (Ctrl+C) |
SIGKILL | read | Killed (likely OOM) |
SIGPIPE | read | Broken pipe |
SIGQUIT | read | Quit |
SIGSEGV | read | Segmentation fault |
SIGTERM | read | Terminated |
SIGXCPU | read | CPU time limit exceeded |
Sample | read | test |
Scripted | read | carries a prompt-local tool |
Shared | read | registry description |
Summarize | read | Summarize content |
Summarizer | read | Summarize findings |
Synthesize | read | Synthesize from a named output |
Test | read | Test |
Validator | read | Validates input |
Workflow | read | |
arg | read | test arg |
c1 | read | |
c2 | read | |
chain_prompt | read | a chain prompt |
content | read | Content |
custom-check | read | Verify edge cases |
data | read | Input |
demo | read | Demo prompt |
draft | read | draft step |
gc_chain | read | e2e chain whose own prompt includes gp-y and whose category supplies gp-cat |
gc_chain_own | read | e2e chain whose own prompt includes gp-y and whose last step includes gp-x |
gc_nest | read | e2e chain whose second step is the chain gc_chain |
gj-block | read | blocking e2e gate |
gj_chain | read | e2e chain with a blocking gate on every step |
gp-cat | read | blocking e2e gate a category supplies |
gp_b | read | e2e step whose prompt includes gp-x |
gp_chain | read | e2e chain whose own prompt includes gp-y |
gp_k | read | e2e step whose category supplies gp-cat |
gr-req | read | blocking e2e gate a request names |
hr_chain | write | e2e held-run chain |
input | read | Other input |
json_prompt | read | JSON payloads |
last_chain | read | e2e chain with an advisory gate on its last step |
multi | read | Allow multi-line payloads |
not_a_real_argument | read | x |
p288-block | read | blocking e2e gate |
p288_a | read | a step with an authored system message |
p288_b | read | a step with no system message |
p288_b_first | read | a chain whose gated first step has no system message |
p288_chain | read | a chain whose every step carries a blocking gate |
p87-plain | read | blocking, no retry_config: opens the single prompt a session |
production-ready | read | Include tests and error handling |
prompt_engine | read | |
qk203 | read | QK-203 |
red-team | read | Confirm exfil path |
references | read | Ensure references included |
rq203 | read | d |
single_prompt | read | a single prompt |
snippet | read | y |
sv-block | read | blocking e2e gate |
sv-drop | destructive | blocking e2e gate on a step a replace remainder drops |
sv_a | read | d |
sv_a148 | read | step carrying a chain-scoped inline definition |
sv_a164 | read | step carrying a chain-scoped inline definition |
sv_big | read | e2e chain as long as the node cap |
sv_chain | read | e2e chain with a blocking gate on every step |
sv_chain148 | read | chain whose steps carry a chain-scoped gate |
sv_chain164 | read | chain whose steps carry a chain-scoped gate |
sv_chain_other | read | a second chain the claiming server runs |
sv_dpair | read | e2e ungated chain of default-gated steps |
sv_late271 | read | e2e chain gated on its last step only |
sv_out | read | e2e step reading a named output |
sv_p193 | read | step for P6.193 |
sv_p193_chain | read | two steps |
sv_p672 | read | e2e chain of default-gated steps, the first blocking-gated |
sv_pair | read | e2e ungated two-step chain |
target_thing | read | what to act on |
task | write | Work to execute |
team | read | Team or org name |
test | read | test prompt |
test-coverage | read | Include unit tests |
text | read | Text to analyze |
thing | read | the thing |
topic | read | optional, undefaulted |
unused_arg | read | declared, never used |
work_kind | read | kind of work |
Trust audit
BLOCKgrade F · trust 47/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const data = yaml.load(readFileSync(yamlPath, 'utf-8'));
parsed = yaml.load(readFileSync(descriptorPath, 'utf8'));
const parsed = yaml.load(readFileSync(absolute, 'utf8'));
const manifest = yaml.load(readFileSync(path.join(dir, 'tool.yaml'), 'utf8')) as {const prompt = yaml.load(readFileSync(path.join(tool.promptDir, 'prompt.yaml'), 'utf8')) as {/^sh -c 'echo "[^"]*" >> \S+; export CLAUDE_PLUGIN_DATA="[^"]*"; exec (.*)'$/;
this.logger.info(`[Handoff] Minted token for session ${sessionId} (${session.chainId})`);' { "name": "red-team", "description": "Confirm exfil path" }, // Simple check',const baseUrl = `http://127.0.0.1:${port}`;await waitHealth(`http://127.0.0.1:${PORT_A}`);await waitHealth(`http://127.0.0.1:${PORT_B}`);const a = client(`http://127.0.0.1:${PORT_A}`);const b = client(`http://127.0.0.1:${PORT_B}`);secret = "sentinel-do-not-print"
sv-drop
.delivery-contract.json
.ignore
.mcpbignore
.node-version
.prettierignore
const rawDb = (engine as unknown as { db: { exec(sql: string): void } }).db;return new Function(
.createHash("sha1")const CLI = join(__dirname, '../../dist/cpm.js');
const CLI = join(__dirname, '../../dist/cpm.js');
Gates applied: no_behavioural_pass.
1852bc931df4full audit observations/trust-audit/mcp-server/minipuft__claude-prompts.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 1852bc931df4 | BLOCK | F | 47 | first audit |
Questions
What is the Claude Prompts MCP server?
MCP server for reusable prompt templates, multi-step workflow chains, and quality gates. Compose agentic workflows with an operator syntax; export as native skills to Claude Code, Cursor, OpenCode, and Gemini CLI.
What tools does Claude Prompts expose?
120 in total: 116 read-only, 3 that write, and 1 that can delete or overwrite (sv-drop). Every one is listed on this page with its risk.
Is Claude Prompts safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (47/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Claude Prompts need?
It reads AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN and MY_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Claude Prompts run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as claude-prompts at 5.1.1.
How current is this page?
The grade is for one exact copy of the source (1852bc931df4), read on 2026-10-07. The repository is watched and re-audited when it changes.