Build Mcp ServerSAFE
Official, Anthropic-managed directory of high quality Claude Code Plugins.
Overview
Official, Anthropic-managed directory of high quality Claude Code Plugins.
76137dccbc88OBSERVED · 2026-10-02Install
Commands as the repository documents them. They are shown, not run.
npm init -y
npm install @modelcontextprotocol/sdk zod express
npm install -D typescript @types/express @types/node tsx
pip install fastmcp
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| claude-desktop | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: build-mcp-server description: This skill should be used when the user asks to "build an MCP server", "create an MCP", "make an MCP integration", "wrap an API for Claude", "expose tools to Claude", "make an MCP app", or discusses building something with the Model Context Protocol. It is the entry point for MCP server development — it interrogates the user about their use case, determines the right deployment model (remote HTTP, MCPB, local stdio), picks a tool-design pattern, and hands off to specialized skills. version: 0.1.0 --- # Build an MCP Server You are guiding a developer through designing and building an MCP server that works seamlessly with Claude. MCP servers come in many forms — picking the wrong shape early causes painful rewrites later. Your first job is **discovery, not code**. **Load Claude-specific context first.** The MCP spec is generic; Claude has additional auth types, review criteria, and limits. Before answering questions or scaffolding, fetch `https://claude.com/docs/llms-full.txt` (the full export of the Claude connector docs) so your guidance reflects Claude's actual constraints. Do not start scaffolding until you have answers to the questions in Phase 1. If the user's opening message already answers them, acknowledge that and skip straight to the recommendation. --- ## Phase 1 — Interrogate the use case Ask these questions conversationally (batch them into one message, don't interrogate one-at-a-time). Adapt wording to what the user has already told you. ### 1. What does it connect to? | If it connects to... | Likely direction | |---|---| | A cloud API (SaaS, REST, GraphQL) | Remote HTTP server | | A local process, filesystem, or desktop app | MCPB or local stdio | | Hardware, OS-level APIs, or user-specific state | MCPB | | Nothing external — pure logic / computation | Either — default to remote | ### 2. Who will use it? - **Just me / my team, on our machines** → Local stdio is acceptable (easiest to prototype) - **Anyone who installs it** → Remote HTTP (strongly preferred) or MCPB (if it *must* be local) - **Users of Claude desktop who want UI widgets** → MCP app (remote or MCPB) ### 3. How many distinct actions does it expose? This determines the tool-design pattern — see Phase 3. - **Under ~15 actions** → one tool per action - **Dozens to hundreds of actions** (e.g. wrapping a large API surface) → search + execute pattern ### 4. Does a tool need mid-call user input or rich display? - **Simple structured input** (pick from list, enter a value, confirm) → **Elicitation** — spec-native, zero UI code. *Host support is rolling out* (Claude Code ≥2.1.76) — always pair with a capability check and fallback. See `references/elicitation.md`. - **Rich/visual UI** (charts, custom pickers with search, live dashboards) → **MCP app widgets** — iframe-based, needs `@modelcontextprotocol/ext-apps`. See `build-mcp-app` skill. - **Neither** → plain tool returning text/JSON. ### 5. What auth does the upstream service use? - None / API key → straightforward - OAuth 2.0 → you'll need a remote server with CIMD (preferred) or DCR support; see `references/auth.md` --- ## Phase 2 — Recommend a deployment model Based on the answers, recommend **one** path. Be opinionated. The ranked options: ### ⭐ Remote streamable-HTTP MCP server (default recommendation) A hosted service speaking MCP over streamable HTTP. This is the **recommended path** for anything wrapping a cloud API. **Why it wins:** - Zero install friction — users add a URL, done - One deployment serves all users; you control upgrades - OAuth flows work properly (the server can handle redirects, DCR, token storage) - Works across Claude desktop, Claude Code, Claude.ai, and third-party MCP hosts **Choose this unless** the server *must* touch the user's local machine. → **Fastest deploy:** Cloudflare Workers — `references/deploy-cloudflare-workers.md` (zero to live URL in two commands) → **Portable Node/Python:** `references/remote-http-scaffold.md` (Express or FastMCP, runs on any host) ### Elicitation (structured input, no UI build) If a tool just needs the user to confirm, pick an option, or fill a short form, **elicitation** does it with zero UI code. The server sends a flat JSON schema; the host renders a native form. Spec-native, no extra packages. **Caveat:** Host support is new (Claude Code shipped it in v2.1.76; Desktop unconfirmed). The SDK throws if the client doesn't advertise the capability. Always check `clientCapabilities.elicitation` first and have a fallback — see `references/elicitation.md` for the canonical pattern. This is the right spec-correct approach; host coverage will catch up. Escalate to `build-mcp-app` widgets when you need: nested/complex data, scrollable/searchable lists, visual previews, live updates. ### MCP app (remote HTTP + interactive UI) Same as above, plus **UI resources** — interactive widgets rendered in chat. Rich pickers with search, charts, live dashboards, visual previews. Built once, renders in Claude *and* ChatGPT. **Choose this when** elicitation's flat-form constraints don't fit — you need custom layout, large searchable lists, visual content, or live updates. Usually remote, but can be shipped as MCPB if the UI needs to drive a local app. → Hand off to the **`build-mcp-app`** skill. ### MCPB (bundled local server) A local MCP server **packaged with its runtime** so users don't need Node/Python installed. The sanctioned way to ship local servers. **Choose this when** the server *must* run on the user's machine — it reads local files, drives a desktop app, talks to localhost services, or needs OS-level access. → Hand off to the **`build-mcpb`** skill. ### Local stdio (npx / uvx) — *not recommended for distribution* A script launched via `npx` / `uvx` on the user's machine. Fine for **personal tools and prototypes**. Painful to distribute: users need the right runtime, you can't push updates, and the only distribution channel is Clau
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
**Token passthrough is explicitly forbidden.** Don't accept a token, then forward it upstream. If your server needs to call another service, exchange the token or use its own credentials.
**Stateless vs stateful:** The snippet above creates a fresh transport per request (stateless). Fine for most API-wrapping servers. If tools need to share state across calls in a session (rare), use a
Gates applied: no_behavioural_pass.
76137dccbc88full audit observations/trust-audit/skill/anthropics__build-mcp-server.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | 76137dccbc88 | SAFE | B | 89 | first audit |
Questions
What does the Build Mcp Server skill do?
Official, Anthropic-managed directory of high quality Claude Code Plugins.
Is Build Mcp Server safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Build Mcp Server access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Build Mcp Server work with?
Its documentation mentions claude-code and claude-desktop. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (76137dccbc88), read on 2026-10-02. The repository is watched, and a new audit runs when it changes — this is the first audit.