Install
$ agentstack add skill-droodotfoo-agent-skills-mcp-server-builder ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
MCP Server Builder
Generate Model Context Protocol servers from OpenAPI specifications. Supports Python (FastMCP) and TypeScript targets.
What You Get
- Working MCP server directory scaffolded from an OpenAPI spec
- Typed tool definitions, auth wrappers, confirmation gates, and test stubs
Workflow
- Parse -- Read the OpenAPI spec (JSON or YAML), extract paths, operations,
schemas, and auth requirements.
- Generate -- Map each operation to an MCP tool definition with typed input
schemas. Apply naming conventions (verbnoun, snakecase).
- Secure -- Add auth wrappers, host allowlists, confirmation gates for
destructive operations, and structured error payloads.
- Validate -- Run the manifest through lint checks: duplicate names, missing
descriptions, invalid schemas, naming hygiene.
- Test -- Unit tests for schema transforms, contract tests for manifest
snapshots, integration tests against a staging API.
Quality Gates (before publishing)
- [ ] Every tool has a non-empty description
- [ ] No duplicate tool names
- [ ] All destructive operations require confirmation input
- [ ] Secrets sourced from env vars only (none in schemas or defaults)
- [ ] Host allowlist is explicit (no wildcards unless justified)
- [ ] Manifest passes strict validation (
validation.md) - [ ] Unit + contract tests pass
- [ ] Integration test against at least one live endpoint
Top Pitfalls
| Mistake | Fix | | --- | --- | | Leaking API keys in tool schemas | Use env vars; never put secrets in inputSchema defaults | | Generic tool names (get_data) | Use API-specific prefixes (github_list_repos) | | Missing error structure | Return {error: string, code: number}, not raw strings | | Huge parameter objects | Flatten or split; MCP tools work best with focused inputs | | No confirmation on DELETE | Add confirm: true input for destructive operations |
Reading Guide
| Topic | File | | --- | --- | | OpenAPI-to-MCP mapping, scaffold templates | scaffolding.md | | Auth patterns, safety, error design | auth-and-safety.md | | Manifest validation and CI checks | validation.md | | Testing strategy (unit/contract/integration) | testing.md |
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: DROOdotFOO
- Source: DROOdotFOO/agent-skills
- License: MIT
- Homepage: https://droo.foo/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.