mcp-builder skill (anthropics/skills)
- Install
- SKILL.md (verbatim)
- Overview
- π High-Level Workflow
- Phase 1: Deep Research and Planning
- Phase 2: Implementation
- Phase 3: Review and Test
- Phase 4: Create Evaluations
- π Documentation Library
- Core MCP Documentation (Load First)
- SDK Documentation (Load During Phase 1/2)
- Language-Specific Implementation Guides (Load During Phase 2)
- Evaluation Guide (Load During Phase 4)
- Other files in this skill
- reference/mcpbestpractices.md (verbatim)
- Quick Reference
- Server Naming
- Tool Naming
- Response Formats
- Pagination
- Transport
- Server Naming Conventions
- Tool Naming and Design
- Tool Naming
- Tool Design
- Response Formats
- JSON Format (responseformat="json")
- Markdown Format (responseformat="markdown", typically default)
- Pagination
- Transport Options
- Streamable HTTP
- stdio
- Transport Selection
- Security Best Practices
- Authentication and Authorization
- Input Validation
- Error Handling
- DNS Rebinding Protection
- Tool Annotations
- Error Handling
- Testing Requirements
- Documentation Requirements
What it does. Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK). Part of anthropics/skills (Anthropic official skills) (anthropics/skills).
| Upstream | anthropics/skills |
| Skill file | skills/mcp-builder/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE.txt) |
| Author | Anthropic |
| Fetched | 2026-09-10 |
Install
- Claude Code:
/plugin marketplace add anthropics/skillsthen install the skill; other agents:npx skills add anthropics/skills --skill mcp-builder. - Raw file:
curl -sL https://raw.githubusercontent.com/anthropics/skills/HEAD/skills/mcp-builder/SKILL.md
SKILL.md (verbatim)
name: mcp-builder
description: Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).
license: Complete terms in LICENSE.txt
MCP Server Development Guide
Overview
Create MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. The quality of an MCP server is measured by how well it enables LLMs to accomplish real-world tasks.
Process
π High-Level Workflow
Creating a high-quality MCP server involves four main phases:
Phase 1: Deep Research and Planning
1.1 Understand Modern MCP Design
API Coverage vs. Workflow Tools: Balance comprehensive API endpoint coverage with specialized workflow tools. Workflow tools can be more convenient for specific tasks, while comprehensive coverage gives agents flexibility to compose operations. Performance varies by clientβsome clients benefit from code execution that combines basic tools, while others work better with higher-level workflows. When uncertain, prioritize comprehensive API coverage.
Tool Naming and Discoverability:
Clear, descriptive tool names help agents find the right tools quickly. Use consistent prefixes (e.g., github_create_issue, github_list_repos) and action-oriented naming.
Context Management: Agents benefit from concise tool descriptions and the ability to filter/paginate results. Design tools that return focused, relevant data. Some clients support code execution which can help agents filter and process data efficiently.
Actionable Error Messages: Error messages should guide agents toward solutions with specific suggestions and next steps.
1.2 Study MCP Protocol Documentation
Navigate the MCP specification:
Start with the sitemap to find relevant pages: https://modelcontextprotocol.io/sitemap.xml
Then fetch specific pages with .md suffix for markdown format (e.g., https://modelcontextprotocol.io/specification/draft.md).
Key pages to review:
- Specification overview and architecture
- Transport mechanisms (streamable HTTP, stdio)
- Tool, resource, and prompt definitions
1.3 Study Framework Documentation
Recommended stack:
- Language: TypeScript (high-quality SDK support and good compatibility in many execution environments e.g. MCPB. Plus AI models are good at generating TypeScript code, benefiting from its broad usage, static typing and good linting tools)
- Transport: Streamable HTTP for remote servers, using stateless JSON (simpler to scale and maintain, as opposed to stateful sessions and streaming responses). stdio for local servers.
Load framework documentation:
- MCP Best Practices: π View Best Practices - Core guidelines
For TypeScript (recommended):
- TypeScript SDK: Use WebFetch to load
https://raw.githubusercontent.com/modelcontextprotocol/typescript-sdk/main/README.md - β‘ TypeScript Guide - TypeScript patterns and examples
For Python:
- Python SDK: Use WebFetch to load
https://raw.githubusercontent.com/modelcontextprotocol/python-sdk/main/README.md - π Python Guide - Python patterns and examples
1.4 Plan Your Implementation
Understand the API: Review the service's API documentation to identify key endpoints, authentication requirements, and data models. Use web search and WebFetch as needed.
Tool Selection: Prioritize comprehensive API coverage. List endpoints to implement, starting with the most common operations.
Phase 2: Implementation
2.1 Set Up Project Structure
See language-specific guides for project setup:
- β‘ TypeScript Guide - Project structure, package.json, tsconfig.json
- π Python Guide - Module organization, dependencies
2.2 Implement Core Infrastructure
Create shared utilities:
- API client with authentication
- Error handling helpers
- Response formatting (JSON/Markdown)
- Pagination support
2.3 Implement Tools
For each tool:
Input Schema:
- Use Zod (TypeScript) or Pydantic (Python)
- Include constraints and clear descriptions
- Add examples in field descriptions
Output Schema:
- Define
outputSchemawhere possible for structured data - Use
structuredContentin tool responses (TypeScript SDK feature) - Helps clients understand and process tool outputs
Tool Description:
- Concise summary of functionality
- Parameter descriptions
- Return type schema
Implementation:
- Async/await for I/O operations
- Proper error handling with actionable messages
- Support pagination where applicable
- Return both text content and structured data when using modern SDKs
Annotations:
readOnlyHint: true/falsedestructiveHint: true/falseidempotentHint: true/falseopenWorldHint: true/false
Phase 3: Review and Test
3.1 Code Quality
Review for:
- No duplicated code (DRY principle)
- Consistent error handling
- Full type coverage
- Clear tool descriptions
3.2 Build and Test
TypeScript:
- Run
npm run buildto verify compilation - Test with MCP Inspector:
npx @modelcontextprotocol/inspector
Python:
- Verify syntax:
python -m py_compile your_server.py - Test with MCP Inspector
See language-specific guides for detailed testing approaches and quality checklists.
Phase 4: Create Evaluations
After implementing your MCP server, create comprehensive evaluations to test its effectiveness.
Load β Evaluation Guide for complete evaluation guidelines.
4.1 Understand Evaluation Purpose
Use evaluations to test whether LLMs can effectively use your MCP server to answer realistic, complex questions.
4.2 Create 10 Evaluation Questions
To create effective evaluations, follow the process outlined in the evaluation guide:
- Tool Inspection: List available tools and understand their capabilities
- Content Exploration: Use READ-ONLY operations to explore available data
- Question Generation: Create 10 complex, realistic questions
- Answer Verification: Solve each question yourself to verify answers
4.3 Evaluation Requirements
Ensure each question is:
- Independent: Not dependent on other questions
- Read-only: Only non-destructive operations required
- Complex: Requiring multiple tool calls and deep exploration
- Realistic: Based on real use cases humans would care about
- Verifiable: Single, clear answer that can be verified by string comparison
- Stable: Answer won't change over time
4.4 Output Format
Create an XML file with this structure:
<evaluation>
<qa_pair>
<question>Find discussions about AI model launches with animal codenames. One model needed a specific safety designation that uses the format ASL-X. What number X was being determined for the model named after a spotted wild cat?</question>
<answer>3</answer>
</qa_pair>
<!-- More qa_pairs... -->
</evaluation>
Reference Files
π Documentation Library
Load these resources as needed during development:
Core MCP Documentation (Load First)
- MCP Protocol: Start with sitemap at
https://modelcontextprotocol.io/sitemap.xml, then fetch specific pages with.mdsuffix - π MCP Best Practices - Universal MCP guidelines including:
- Server and tool naming conventions
- Response format guidelines (JSON vs Markdown)
- Pagination best practices
- Transport selection (streamable HTTP vs stdio)
- Security and error handling standards
SDK Documentation (Load During Phase 1/2)
- Python SDK: Fetch from
https://raw.githubusercontent.com/modelcontextprotocol/python-sdk/main/README.md - TypeScript SDK: Fetch from
https://raw.githubusercontent.com/modelcontextprotocol/typescript-sdk/main/README.md
Language-Specific Implementation Guides (Load During Phase 2)
π Python Implementation Guide - Complete Python/FastMCP guide with:
- Server initialization patterns
- Pydantic model examples
- Tool registration with
@mcp.tool - Complete working examples
- Quality checklist
β‘ TypeScript Implementation Guide - Complete TypeScript guide with:
- Project structure
- Zod schema patterns
- Tool registration with
server.registerTool - Complete working examples
- Quality checklist
Evaluation Guide (Load During Phase 4)
- β
Evaluation Guide - Complete evaluation creation guide with:
- Question creation guidelines
- Answer verification strategies
- XML format specifications
- Example questions and answers
- Running an evaluation with the provided scripts
Other files in this skill
- LICENSE.txt
- reference/evaluation.md
- reference/mcp_best_practices.md
- reference/node_mcp_server.md
- reference/python_mcp_server.md
- scripts/connections.py
- scripts/evaluation.py
- scripts/example_evaluation.xml
- scripts/requirements.txt
reference/mcp_best_practices.md (verbatim)
MCP Server Best Practices
Quick Reference
Server Naming
- Python:
{service}_mcp(e.g.,slack_mcp) - Node/TypeScript:
{service}-mcp-server(e.g.,slack-mcp-server)
Tool Naming
- Use snake_case with service prefix
- Format:
{service}_{action}_{resource} - Example:
slack_send_message,github_create_issue
Response Formats
- Support both JSON and Markdown formats
- JSON for programmatic processing
- Markdown for human readability
Pagination
- Always respect
limitparameter - Return
has_more,next_offset,total_count - Default to 20-50 items
Transport
- Streamable HTTP: For remote servers, multi-client scenarios
- stdio: For local integrations, command-line tools
- Avoid SSE (deprecated in favor of streamable HTTP)
Server Naming Conventions
Follow these standardized naming patterns:
Python: Use format {service}_mcp (lowercase with underscores)
- Examples:
slack_mcp,github_mcp,jira_mcp
Node/TypeScript: Use format {service}-mcp-server (lowercase with hyphens)
- Examples:
slack-mcp-server,github-mcp-server,jira-mcp-server
The name should be general, descriptive of the service being integrated, easy to infer from the task description, and without version numbers.
Tool Naming and Design
Tool Naming
- Use snake_case:
search_users,create_project,get_channel_info - Include service prefix: Anticipate that your MCP server may be used alongside other MCP servers
- Use
slack_send_messageinstead of justsend_message - Use
github_create_issueinstead of justcreate_issue
- Use
- Be action-oriented: Start with verbs (get, list, search, create, etc.)
- Be specific: Avoid generic names that could conflict with other servers
Tool Design
- Tool descriptions must narrowly and unambiguously describe functionality
- Descriptions must precisely match actual functionality
- Provide tool annotations (readOnlyHint, destructiveHint, idempotentHint, openWorldHint)
- Keep tool operations focused and atomic
Response Formats
All tools that return data should support multiple formats:
JSON Format (response_format="json")
- Machine-readable structured data
- Include all available fields and metadata
- Consistent field names and types
- Use for programmatic processing
Markdown Format (response_format="markdown", typically default)
- Human-readable formatted text
- Use headers, lists, and formatting for clarity
- Convert timestamps to human-readable format
- Show display names with IDs in parentheses
- Omit verbose metadata
Pagination
For tools that list resources:
- Always respect the
limitparameter - Implement pagination: Use
offsetor cursor-based pagination - Return pagination metadata: Include
has_more,next_offset/next_cursor,total_count - Never load all results into memory: Especially important for large datasets
- Default to reasonable limits: 20-50 items is typical
Example pagination response:
{
"total": 150,
"count": 20,
"offset": 0,
"items": [...],
"has_more": true,
"next_offset": 20
}
Transport Options
Streamable HTTP
Best for: Remote servers, web services, multi-client scenarios
Characteristics:
- Bidirectional communication over HTTP
- Supports multiple simultaneous clients
- Can be deployed as a web service
- Enables server-to-client notifications
Use when:
- Serving multiple clients simultaneously
- Deploying as a cloud service
- Integration with web applications
stdio
Best for: Local integrations, command-line tools
Characteristics:
- Standard input/output stream communication
- Simple setup, no network configuration needed
- Runs as a subprocess of the client
Use when:
- Building tools for local development environments
- Integrating with desktop applications
- Single-user, single-session scenarios
Note: stdio servers should NOT log to stdout (use stderr for logging)
Transport Selection
| Criterion | stdio | Streamable HTTP |
|---|---|---|
| Deployment | Local | Remote |
| Clients | Single | Multiple |
| Complexity | Low | Medium |
| Real-time | No | Yes |
Security Best Practices
Authentication and Authorization
OAuth 2.1:
- Use secure OAuth 2.1 with certificates from recognized authorities
- Validate access tokens before processing requests
- Only accept tokens specifically intended for your server
API Keys:
- Store API keys in environment variables, never in code
- Validate keys on server startup
- Provide clear error messages when authentication fails
Input Validation
- Sanitize file paths to prevent directory traversal
- Validate URLs and external identifiers
- Check parameter sizes and ranges
- Prevent command injection in system calls
- Use schema validation (Pydantic/Zod) for all inputs
Error Handling
- Don't expose internal errors to clients
- Log security-relevant errors server-side
- Provide helpful but not revealing error messages
- Clean up resources after errors
DNS Rebinding Protection
For streamable HTTP servers running locally:
- Enable DNS rebinding protection
- Validate the
Originheader on all incoming connections - Bind to
127.0.0.1rather than0.0.0.0
Tool Annotations
Provide annotations to help clients understand tool behavior:
| Annotation | Type | Default | Description |
|---|---|---|---|
readOnlyHint |
boolean | false | Tool does not modify its environment |
destructiveHint |
boolean | true | Tool may perform destructive updates |
idempotentHint |
boolean | false | Repeated calls with same args have no additional effect |
openWorldHint |
boolean | true | Tool interacts with external entities |
Important: Annotations are hints, not security guarantees. Clients should not make security-critical decisions based solely on annotations.
Error Handling
- Use standard JSON-RPC error codes
- Report tool errors within result objects (not protocol-level errors)
- Provide helpful, specific error messages with suggested next steps
- Don't expose internal implementation details
- Clean up resources properly on errors
Example error handling:
try {
const result = performOperation();
return { content: [{ type: "text", text: result }] };
} catch (error) {
return {
isError: true,
content: [{
type: "text",
text: `Error: ${error.message}. Try using filter='active_only' to reduce results.`
}]
};
}
Testing Requirements
Comprehensive testing should cover:
- Functional testing: Verify correct execution with valid/invalid inputs
- Integration testing: Test interaction with external systems
- Security testing: Validate auth, input sanitization, rate limiting
- Performance testing: Check behavior under load, timeouts
- Error handling: Ensure proper error reporting and cleanup
Documentation Requirements
- Provide clear documentation of all tools and capabilities
- Include working examples (at least 3 per major feature)
- Document security considerations
- Specify required permissions and access levels
- Document rate limits and performance characteristics
Back to anthropics/skills (Anthropic official skills) or Agent skills.