# Mcp Server Builder

> >

- **Type:** Skill
- **Install:** `agentstack add skill-droodotfoo-agent-skills-mcp-server-builder`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [DROOdotFOO](https://agentstack.voostack.com/s/droodotfoo)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [DROOdotFOO](https://github.com/DROOdotFOO)
- **Source:** https://github.com/DROOdotFOO/agent-skills/tree/main/skills/mcp-server-builder
- **Website:** https://droo.foo/

## Install

```sh
agentstack add skill-droodotfoo-agent-skills-mcp-server-builder
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# MCP Server Builder

Generate Model Context Protocol servers from OpenAPI specifications. Supports
Python (FastMCP) and TypeScript targets.

## What You Get

- Working MCP server directory scaffolded from an OpenAPI spec
- Typed tool definitions, auth wrappers, confirmation gates, and test stubs

## Workflow

1. **Parse** -- Read the OpenAPI spec (JSON or YAML), extract paths, operations,
   schemas, and auth requirements.
2. **Generate** -- Map each operation to an MCP tool definition with typed input
   schemas. Apply naming conventions (verb_noun, snake_case).
3. **Secure** -- Add auth wrappers, host allowlists, confirmation gates for
   destructive operations, and structured error payloads.
4. **Validate** -- Run the manifest through lint checks: duplicate names, missing
   descriptions, invalid schemas, naming hygiene.
5. **Test** -- Unit tests for schema transforms, contract tests for manifest
   snapshots, integration tests against a staging API.

## Quality Gates (before publishing)

- [ ] Every tool has a non-empty description
- [ ] No duplicate tool names
- [ ] All destructive operations require confirmation input
- [ ] Secrets sourced from env vars only (none in schemas or defaults)
- [ ] Host allowlist is explicit (no wildcards unless justified)
- [ ] Manifest passes strict validation (`validation.md`)
- [ ] Unit + contract tests pass
- [ ] Integration test against at least one live endpoint

## Top Pitfalls

| Mistake | Fix |
| --- | --- |
| Leaking API keys in tool schemas | Use env vars; never put secrets in `inputSchema` defaults |
| Generic tool names (`get_data`) | Use API-specific prefixes (`github_list_repos`) |
| Missing error structure | Return `{error: string, code: number}`, not raw strings |
| Huge parameter objects | Flatten or split; MCP tools work best with focused inputs |
| No confirmation on DELETE | Add `confirm: true` input for destructive operations |

## Reading Guide

| Topic | File |
| --- | --- |
| OpenAPI-to-MCP mapping, scaffold templates | `scaffolding.md` |
| Auth patterns, safety, error design | `auth-and-safety.md` |
| Manifest validation and CI checks | `validation.md` |
| Testing strategy (unit/contract/integration) | `testing.md` |

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [DROOdotFOO](https://github.com/DROOdotFOO)
- **Source:** [DROOdotFOO/agent-skills](https://github.com/DROOdotFOO/agent-skills)
- **License:** MIT
- **Homepage:** https://droo.foo/

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-droodotfoo-agent-skills-mcp-server-builder
- Seller: https://agentstack.voostack.com/s/droodotfoo
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
