building-mcp-servers — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited building-mcp-servers (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Create MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. The quality of an MCP server is measured by how well it enables LLMs to accomplish real-world tasks.
Creating a high-quality MCP server involves four main phases:
#### 1.1 Understand Modern MCP Design
API Coverage vs. Workflow Tools: Balance comprehensive API endpoint coverage with specialized workflow tools. When uncertain, prioritize comprehensive API coverage.
Tool Naming and Discoverability: Use consistent prefixes (e.g., github_create_issue, github_list_repos) and action-oriented naming.
Context Management: Design tools that return focused, relevant data. Support filtering/pagination.
Actionable Error Messages: Error messages should guide agents toward solutions with specific suggestions.
#### 1.2 Study MCP Protocol Documentation
Start with the sitemap: https://modelcontextprotocol.io/sitemap.xml
Fetch pages with .md suffix (e.g., https://modelcontextprotocol.io/specification/draft.md).
Key pages: Specification overview, transport mechanisms, tool/resource/prompt definitions.
#### 1.3 Study Framework Documentation
Recommended stack:
Load framework documentation:
SDK Documentation:
https://raw.githubusercontent.com/modelcontextprotocol/typescript-sdk/main/README.mdhttps://raw.githubusercontent.com/modelcontextprotocol/python-sdk/main/README.md#### 1.4 Plan Your Implementation
Review the service's API documentation. List endpoints to implement, starting with most common operations.
#### 2.1 Set Up Project Structure
See language-specific guides:
#### 2.2 Implement Core Infrastructure
Create shared utilities:
#### 2.3 Implement Tools
For each tool:
Input Schema:
Output Schema:
outputSchema where possiblestructuredContent in responsesTool Description:
Annotations:
readOnlyHint, destructiveHint, idempotentHint, openWorldHint#### 3.1 Code Quality
Review for: DRY principle, consistent error handling, full type coverage, clear descriptions.
#### 3.2 Build and Test
TypeScript:
npm run build
npx @modelcontextprotocol/inspectorPython:
python -m py_compile your_server.py
# Test with MCP InspectorCreate 10 evaluation questions to test LLM effectiveness with your server.
Requirements for each question:
Output Format:
<evaluation>
<qa_pair>
<question>Your question here</question>
<answer>Expected answer</answer>
</qa_pair>
</evaluation>See Evaluation Guide for complete guidelines.
FastMCP validates Host headers. For Docker, configure:
from mcp.server.fastmcp import FastMCP
from mcp.server.transport_security import TransportSecuritySettings
transport_security = TransportSecuritySettings(
allowed_hosts=[
"127.0.0.1:*", "localhost:*", "[::1]:*",
"mcp-server:*", # Docker container name
"0.0.0.0:*",
],
)
mcp = FastMCP("my_server", transport_security=transport_security)Add /health endpoint via middleware (see references for full example).
Run: python3 scripts/verify.py
Expected: ✓ building-mcp-servers skill ready
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.