mcp-server
Build MCP Servers with Reusable Patterns
Teams need reliable patterns for exposing backend operations to AI agents through MCP. This skill provides reusable Python structures for tools, storage, validation, caching, and tests.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "mcp-server" from https://skillstore.io/skills/azeem-2-mcp-server.md and its manifest at https://skillstore.io/api/skills/azeem-2-mcp-server/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "mcp-server". I need an MCP server for project tasks.
Expected outcome:
A structured server design with create, get, list, update, delete, and search tools, plus validation and storage recommendations.
Using "mcp-server". Add database support to my MCP tool server.
Expected outcome:
A backend plan covering connection lifecycle, transaction boundaries, supported database choices, and safe parameter handling.
Using "mcp-server". How should I test these MCP tools?
Expected outcome:
A focused test plan with mock storage, success cases, validation failures, permission cases, and end-to-end tool calls.
Security Audit
High RiskMost static findings are false positives caused by Markdown code fences, Python import syntax, placeholder database configuration, and variable names such as db or id. The review did find high-risk semantic issues in the example patterns: raw SQL construction with dynamic identifiers and permissive authorization defaults. No prompt injection attempt was found in the reviewed SKILL.md text.
Confirmed security concerns (2)
Risk Factors
โก Contains scripts (1)
โ๏ธ External commands (11)
๐ Network access (1)
๐ Env variables (34)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/azeem-2-mcp-server/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/azeem-2-mcp-server?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/azeem-2-mcp-server?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/azeem-2-mcp-server/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/azeem-2-mcp-server.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
Azeem-2. (2026). mcp-server security audit report (audit version 8) [Author version unspecified]. Skillstore. https://skillstore.io/skills/azeem-2-mcp-server/audits/8BibTeX citation
@techreport{azeem-2-azeem-2-mcp-server-2026,
author = {Azeem-2},
title = {mcp-server security audit report (audit version 8)},
institution = {Skillstore},
year = {2026},
number = {8},
url = {https://skillstore.io/skills/azeem-2-mcp-server/audits/8},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "mcp-server security audit report (audit version 8)"
version: "unspecified"
type: report
authors:
- name: "Azeem-2"
date-released: "2026-07-05"
url: "https://skillstore.io/skills/azeem-2-mcp-server/audits/8"
identifiers:
- type: other
value: "skillstore:azeem-2-mcp-server:audit:8"
description: "Skillstore immutable audit report identifier"
Compare variants
2 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
cam10001110101-mcp-server
2026-09-09
azeem-2-mcp-server
2026-09-09
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Create Internal MCP Tools
Build a server that exposes approved internal operations to AI agents through MCP tools.
Prototype Database-backed Agents
Use the CRUD patterns to test how an agent can safely read and update domain records.
Standardize MCP Server Tests
Adapt the mock database and pytest examples to verify tool behavior before deployment.
Try These Prompts
Use the mcp-server skill to outline a simple Python MCP server for my domain. Include tools, inputs, and storage needs.
Using the mcp-server patterns, design CRUD MCP tools for this entity model: [describe fields]. Include validation and user scoping.
Apply the mcp-server database patterns to support PostgreSQL for this MCP server. Include connection setup, transactions, and safe query practices.
Review my MCP server design against the mcp-server skill. Focus on authorization, SQL safety, rate limits, caching, error handling, and tests.
Best Practices
- Replace illustrative permission checks with real authentication and authorization before deployment.
- Use allowlisted identifiers or query builders when generating database queries.
- Keep secrets in managed environment configuration and avoid hardcoded default credentials.
Avoid
- Do not expose generic CRUD tools without strict entity, field, and permission boundaries.
- Do not concatenate user-controlled table names, columns, sort fields, or limits into SQL.
- Do not treat sample rate limits and caching settings as production defaults without review.