agentsclimarketplace

Mcp server builder

Skill DROOdotFOO/agent-skills/skills/mcp-server-builder

Agent skills, autonomous agents, and MCP-companions for programming

Install
npx -y skills add DROOdotFOO/agent-skills --skill mcp-server-builder

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Scaffold MCP servers from OpenAPI specs. TRIGGER when: user asks to build an MCP server, convert an OpenAPI/Swagger spec to MCP tools, generate MCP tool definitions, or scaffold a FastMCP/TypeScript MCP project. DO NOT TRIGGER when: user is configuring an existing MCP server, writing MCP clients, or working with Claude API directly (use claude-api skill).

SKILL.md

2.7 KB, as published. Nobody here has run it

MCP Server Builder

Generate Model Context Protocol servers from OpenAPI specifications. Supports Python (FastMCP) and TypeScript targets.

What You Get

  • Working MCP server directory scaffolded from an OpenAPI spec
  • Typed tool definitions, auth wrappers, confirmation gates, and test stubs

Workflow

  1. Parse -- Read the OpenAPI spec (JSON or YAML), extract paths, operations, schemas, and auth requirements.
  2. Generate -- Map each operation to an MCP tool definition with typed input schemas. Apply naming conventions (verb_noun, snake_case).
  3. Secure -- Add auth wrappers, host allowlists, confirmation gates for destructive operations, and structured error payloads.
  4. Validate -- Run the manifest through lint checks: duplicate names, missing descriptions, invalid schemas, naming hygiene.
  5. Test -- Unit tests for schema transforms, contract tests for manifest snapshots, integration tests against a staging API.

Quality Gates (before publishing)

  • Every tool has a non-empty description
  • No duplicate tool names
  • All destructive operations require confirmation input
  • Secrets sourced from env vars only (none in schemas or defaults)
  • Host allowlist is explicit (no wildcards unless justified)
  • Manifest passes strict validation (validation.md)
  • Unit + contract tests pass
  • Integration test against at least one live endpoint

Top Pitfalls

MistakeFix
Leaking API keys in tool schemasUse env vars; never put secrets in inputSchema defaults
Generic tool names (get_data)Use API-specific prefixes (github_list_repos)
Missing error structureReturn {error: string, code: number}, not raw strings
Huge parameter objectsFlatten or split; MCP tools work best with focused inputs
No confirmation on DELETEAdd confirm: true input for destructive operations

Reading Guide

TopicFile
OpenAPI-to-MCP mapping, scaffold templatesscaffolding.md
Auth patterns, safety, error designauth-and-safety.md
Manifest validation and CI checksvalidation.md
Testing strategy (unit/contract/integration)testing.md

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.