AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Mcp Management

skill-clearfunction-cf-devtools-mcp-management · by clearfunction

>

No reviews yet
0 installs
15 views
0.0% view→install

Install

$ agentstack add skill-clearfunction-cf-devtools-mcp-management

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-clearfunction-cf-devtools-mcp-management)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
7mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Mcp Management? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

MCP Management

Comprehensive guide for finding, configuring, securing, and building MCP servers for Claude Code and Claude Desktop.

Quick Navigation

  • Find Servers: See [Discovering MCP Servers](#discovering-mcp-servers)
  • Configure Servers: See [references/server-configs.md](references/server-configs.md)
  • Build Custom Servers: See [references/building-servers.md](references/building-servers.md)
  • Security: See [references/security-essentials.md](references/security-essentials.md)
  • Troubleshooting: See [references/troubleshooting.md](references/troubleshooting.md)
  • Enterprise: See [references/enterprise-config.md](references/enterprise-config.md)

Platform Differences

| Aspect | Claude Code | Claude Desktop | |-------------------|------------------------------|-------------------------------------------------------------------| | Config location | ~/.claude/settings.json | ~/Library/Application Support/Claude/claude_desktop_config.json | | CLI management | claude mcp add/list/remove | Manual JSON editing | | Scopes | local/project/user | Single config | | Hot reload | Supported | Requires full restart (Cmd+Q) | | Can act as server | Yes (claude mcp serve) | No |

Discovering MCP Servers

Primary Registries

| Registry | Servers | Best For | |--------------------------------------------------------------------|-----------|------------------------------------------| | Official MCP Registry | Canonical | Verified, authoritative source | | GitHub MCP Registry | Curated | GitHub-native, one-click VS Code install | | Smithery.ai | 4,600+ | Usage metrics, edge deployment | | Glama.ai | 10,000+ | Hosted option, no local setup | | PulseMCP | 7,500+ | Daily updates, streaming focus |

Specialized Directories

| Registry | Focus | |-------------------------------------------------------------------------------|--------------------------------------| | Cursor Directory | Cursor IDE optimized (1,800+) | | Mastra | Meta-aggregator across registries | | MCP.so | Quality-verified listings | | Awesome MCP Servers | Community curated GitHub list | | HiMCP.ai | Uptime & performance metrics | | MCPdb.org | Regional filtering, tech docs | | MCPMarket.com | Commercial/enterprise with pricing | | Portkey.ai | Enterprise security/compliance | | MCPServers.org | User reviews, troubleshooting guides | | Cline.bot | Cline AI one-click integration | | APITracker.io | API version tracking | | AIXploria | Editorial reviews, use-case guides |

Evaluation Criteria

When selecting an MCP server:

  1. Maintenance: Recent commits? Active issues?
  2. Security: Reviewed code? Known vulnerabilities?
  3. Token cost: How many tokens does it consume?
  4. Transport: HTTP (remote) vs stdio (local)?
  5. Trust: Official vs community vs unknown author?

Pre-Installation Workflow

CRITICAL: Before installing ANY MCP server, follow this workflow:

1. Fetch and Read the README

Always retrieve the server's README.md from GitHub or the registry:

# View README directly
gh repo view owner/repo-name

# Or fetch raw README
curl -s https://raw.githubusercontent.com/owner/repo/main/README.md

Look for:

  • Required environment variables
  • Prerequisites (Node 18+, Python 3.10+, API keys)
  • Configuration options and defaults
  • Usage examples and limitations
  • Security considerations

2. Check for Deprecations

| Deprecated | Use Instead | |---------------------------------------|------------------------------------------| | SSE transport | HTTP or stdio (June 2025 spec) | | @modelcontextprotocol/server-github | @github/github-mcp-server (April 2025) | | OAuth 2.0 for HTTP | OAuth 2.1 required (March 2025 spec) |

3. Verify Prerequisites

# Check Node version (18+ typically required)
node --version

# Check Python version (3.10+ for MCP SDK)
python3 --version

# Check if package exists
npm view @package/server-name

4. Review Security Implications

Before proceeding, confirm:

  • [ ] What filesystem paths can it access?
  • [ ] What network requests can it make?
  • [ ] What environment variables does it read?
  • [ ] Is the source code available and reviewed?

5. Install Following README Instructions

Only after completing steps 1-4, install using the README's recommended method.

Transport Types

| Transport | Use When | Example | |-----------|-----------------------------|----------------------------------------------------------------------------------| | HTTP | Cloud services, remote APIs | claude mcp add --transport http notion https://mcp.notion.com/mcp | | stdio | Local tools, system access | claude mcp add --transport stdio fs -- npx -y @anthropic/mcp-server-filesystem | | SSE | Legacy (prefer HTTP) | Deprecated for new implementations |

Quick Setup Examples

Claude Code (CLI)

# Add remote server
claude mcp add --transport http github https://api.githubcopilot.com/mcp/

# Add local server
claude mcp add --transport stdio postgres -- npx -y @modelcontextprotocol/server-postgres

# List servers
claude mcp list

# Remove server
claude mcp remove github

Claude Desktop (JSON)

{
  "mcpServers": {
    "github": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-github"],
      "env": {
        "GITHUB_PERSONAL_ACCESS_TOKEN": "ghp_xxx"
      }
    }
  }
}

MCP vs CLI Decision

| Use MCP When | Use CLI When | |----------------------------------|---------------------------| | Rich context needed in responses | Simple one-off operations | | Complex queries across resources | Quick lookups | | Ongoing session work | Infrequent access | | Want tool integration | Prefer direct control |

Token budget matters: GitHub MCP ~40k tokens. Context7 ~500 tokens. Enable sparingly.

Security Essentials

Critical risks (2025 research: 43% of servers have command injection flaws):

  1. Prompt injection: Malicious content in fetched data manipulates Claude
  2. Tool poisoning: Malicious tool descriptions trick model into unsafe actions
  3. Credential exposure: API keys in version control or logs

Mitigations:

  • Only install from trusted registries
  • Review server code before installing unknown servers
  • Use scoped tokens with minimal permissions
  • Never commit credentials to version control
  • Enable project-scope servers only after review

See [references/security-essentials.md](references/security-essentials.md) for detailed patterns.

Building MCP Servers

Language Selection

| Choose | When | |----------------|------------------------------------------------------------------| | Python | Rapid prototyping, data science tools, existing Python ecosystem | | TypeScript | Web integrations, npm ecosystem, type safety preference |

Python Quick Start (FastMCP)

from mcp.server.fastmcp import FastMCP

mcp = FastMCP("my-server")

@mcp.tool()
async def my_tool(param: str) -> str:
    """Tool description for Claude."""
    return f"Result: {param}"

if __name__ == "__main__":
    mcp.run(transport="stdio")

TypeScript Quick Start

import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
import { StdioServerTransport } from "@modelcontextprotocol/sdk/server/stdio.js";

const server = new McpServer({ name: "my-server", version: "1.0.0" });

server.registerTool("my_tool", {
  description: "Tool description for Claude",
  inputSchema: { param: z.string() }
}, async ({ param }) => ({
  content: [{ type: "text", text: `Result: ${param}` }]
}));

const transport = new StdioServerTransport();
await server.connect(transport);

Critical: For stdio transport, NEVER write to stdout (corrupts JSON-RPC). Use stderr or logging libraries.

See [references/building-servers.md](references/building-servers.md) for complete patterns.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.